PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 31, 2026Information and Software Technology1 citationsOpen Access

A responsible AI–driven framework for robust and transparent software vulnerability detection

View Full Paper
NBNihala BasheerSISheikh Shareeful IslamPKPrabhat Kumar

Key Points

  • The central aim is to develop a Responsible AI-driven framework to enhance software vulnerability detection while maintaining fairness and interpretability.
  • Developed a model-agnostic vulnerability detection framework.
  • Implemented fairness-aware data preprocessing and multi-model evaluation.
  • Used SHAP, LIME, and attention-based approaches for interpretability.
  • Conducted white-box adversarial attacks to evaluate security and reliability.
  • Validated framework on three public datasets: CWE-119, CWE-399, and DiverseVul.
  • Achieved competitive detection performance across multiple datasets.
  • Provided structured explanations and demonstrated adversarial evaluation stability.
  • Identified dataset-specific vulnerability cues through interpretability analyses.
  • Showed consistent confidence shifts in perturbation studies under controlled conditions.
  • Illustrated stable performance trends during adversarial attacks.

Abstract

Software vulnerability detection (SVD) is increasingly challenged by the scale and complexity of modern software systems. Although deep learning–based approaches demonstrate strong detection performance, their adoption in security-critical settings is limited by insufficient interpretability, adversarial resilience, and systematic Responsible AI integration. This paper aims to design and evaluate a Responsible AI–driven framework for SVD that operationalizes fairness, interpretability, security, reliability, and transparency without compromising detection effectiveness. We propose a model-agnostic vulnerability detection framework that incorporates fairness-aware data preprocessing, multi-model evaluation, and structured verification mechanisms. Interpretability is achieved through multi-view explanations combining global and local SHAP, LIME, and attention-based attribution. Explanation consistency is examined using attention-guided token occlusion, while security is evaluated via multiple white-box adversarial attacks on correctly classified test samples. The framework is validated on three public datasets—CWE-119, CWE-399, and DiverseVul—using deep learning and pre-trained code models. Experimental results demonstrate competitive detection performance across datasets while providing structured explanation and adversarial evaluation evidence. Interpretability analyses reveal dataset-specific vulnerability cues aligned with domain knowledge, and perturbation studies show consistent confidence shifts under controlled token masking. Adversarial experiments further illustrate stable performance trends under attack conditions. The findings indicate that Responsible AI principles can be systematically operationalized within deep learning–based SVD pipelines. By integrating fairness, interpretability, security evaluation, reliability assessment, and transparency mechanisms, the proposed framework supports trustworthy and security-aware deployment of AI-driven vulnerability detection systems.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Basheer et al. (2026) studied this question.

synapsesocial.com/papers/69cb645fe6a8c024954b89c6https://doi.org/10.1016/j.infsof.2026.108126
Ask AI
Helpful
Bookmark
Share
View Full Paper