Quarterly journal published in SPbPU
and edited by prof. Dmitry Zegzhda
Peter the Great St. Petersburg Polytechnic University
Institute of computer sciences and technologies
information security of computer systems
Information Security Problems. Computer Systems
Published since 1999.
ISSN 2071-8217
AN APPROACH TO IDENTIFYING SOFTWARE CODE VULNERABILITIES BASED ON ADAPTATION WITH REINFORCEMENT LEARNING OF MACHINE LEARNING MODELS
A. G. Lomako, N. E. Isaev, A. B. Menisov, T. R. Sabirov
Annotation: The article is devoted to the development of an approach to identifying vulnerable code using adaptation methods for pre-trained reinforcement machine learning models. A training methodology is presented that includes stages of model adaptation using data from various domains, which ensures high generalization ability of the algorithms. Experimental results have shown the effectiveness of the proposed approach on the popular CWEFix code analysis dataset. The developed approach helps to improve the quality of vulnerability detection and reduce the level of false positives, which makes it a useful tool for ensuring software security.
Keywords: code vulnerabilities, machine learning, reinforcement learning, software analysis, information security
Pages 83–96