Przeskocz do nawigacji głównej Przeskocz do wyszukiwania Przeskocz do głównej treści

Using artificial intelligence in the context of buffer overflow vulnerabilities*

  • Oleg Savenko
  • , Yevhenii Sierhieiev
  • , Piotr Gaj
  • , Jiri Balej
  • Khmelnytsky National University
  • Mendel University in Brno

Wyniki badań: Wkład do czasopismaArtykuł z konferencjirecenzja

1 Cytowanie z bazy Scopus

Abstrakt

The article investigates a method for detecting Buffer Overflow vulnerabilities based on the YOLO neural network. Buffer Overflow vulnerabilities remain a fundamental security concern for modern software systems due to their potential for catastrophic exploitation and persistent presence in both legacy and actively maintained codebases. Traditional detection methods such as static application security testing (SAST) and dynamic analysis offer partial coverage and often struggle with high false positive rates, poor scalability, or limited adaptability to novel vulnerability patterns. This paper presents a novel approach to the automated detection of Buffer Overflow vulnerabilities by leveraging graph-based code representations and the YOLO (You Only Look Once) neural network architecture, originally designed for object detection in computer vision. The study comprehensively reviews current state-of-the-art AI/ML-driven vulnerability detection methods, highlighting their advantages and limitations. The proposed method systematically transforms program code into graph structures and applies YOLO to efficiently localize high-risk code regions. We detail the mathematical risk modeling underpinning the detection process and the workflow for integrating this approach into CI/CD pipelines. A full-scale experiment, using real-world data from CVE and NVD repositories, demonstrates significant improvements in detection accuracy and efficiency compared to leading static analysis tools. The approach achieved 94.3% precision and an F1-score of 93.0% on benchmark datasets, confirming its practical utility for software security assurance. Finally, we discuss challenges, observed limitations, and perspectives for extending the model to additional vulnerability classes and industrial settings.

Język oryginałuangielski
Strony (od–do)211-220
Liczba stron10
CzasopismoCEUR Workshop Proceedings
Tom4013
Status publikacjiOpublikowano - 2025
Wydarzenie2nd International Workshop on Intelligent and CyberPhysical Systems, ICyberPhyS 2025 - Khmelnytskyi, Ukraina
Czas trwania: 4 lip 2025 → …

Obszary tematyczne ASJC Scopus

  • Informatyka ogólna

Fingerprint

Zanurz się w tematy badawcze publikacji „Using artificial intelligence in the context of buffer overflow vulnerabilities*”. Razem tworzą niepowtarzalny odcisk palca.

Cytuj to