Skip to main navigation Skip to search Skip to main content

Using artificial intelligence in the context of buffer overflow vulnerabilities*

  • Oleg Savenko
  • , Yevhenii Sierhieiev
  • , Piotr Gaj
  • , Jiri Balej
  • Khmelnytsky National University
  • Mendel University in Brno

Research output: Contribution to journalConference articlepeer-review

1 Citation (Scopus)

Abstract

The article investigates a method for detecting Buffer Overflow vulnerabilities based on the YOLO neural network. Buffer Overflow vulnerabilities remain a fundamental security concern for modern software systems due to their potential for catastrophic exploitation and persistent presence in both legacy and actively maintained codebases. Traditional detection methods such as static application security testing (SAST) and dynamic analysis offer partial coverage and often struggle with high false positive rates, poor scalability, or limited adaptability to novel vulnerability patterns. This paper presents a novel approach to the automated detection of Buffer Overflow vulnerabilities by leveraging graph-based code representations and the YOLO (You Only Look Once) neural network architecture, originally designed for object detection in computer vision. The study comprehensively reviews current state-of-the-art AI/ML-driven vulnerability detection methods, highlighting their advantages and limitations. The proposed method systematically transforms program code into graph structures and applies YOLO to efficiently localize high-risk code regions. We detail the mathematical risk modeling underpinning the detection process and the workflow for integrating this approach into CI/CD pipelines. A full-scale experiment, using real-world data from CVE and NVD repositories, demonstrates significant improvements in detection accuracy and efficiency compared to leading static analysis tools. The approach achieved 94.3% precision and an F1-score of 93.0% on benchmark datasets, confirming its practical utility for software security assurance. Finally, we discuss challenges, observed limitations, and perspectives for extending the model to additional vulnerability classes and industrial settings.

Original languageEnglish
Pages (from-to)211-220
Number of pages10
JournalCEUR Workshop Proceedings
Volume4013
Publication statusPublished - 2025
Event2nd International Workshop on Intelligent and CyberPhysical Systems, ICyberPhyS 2025 - Khmelnytskyi, Ukraine
Duration: 4 Jul 2025 → …

Keywords

  • Buffer overflow
  • Graphs
  • Machine Learning
  • YOLO
  • cybersecurity

ASJC Scopus subject areas

  • General Computer Science

Fingerprint

Dive into the research topics of 'Using artificial intelligence in the context of buffer overflow vulnerabilities*'. Together they form a unique fingerprint.

Cite this