Aligning vulnerabilities across various security repositories remains a vital yet difficult task, primarily due to absent or inconsistent vulnerability attributes, which can lead to false negatives and shared generic descriptors that may trigger false positives. Existing alignment frameworks, such as GNN-based methods, either focus solely on intra-graph structures without leveraging cross-repository dependencies or fail to integrate both fine-grained local feature learning and global structural differentiation. To address these limitations, we propose DARA (Dual-Attention-based Reconstruction vulnerability Alignment), a novel framework that jointly models intra- and inter-graph relationships through dual-attention mechanisms while integrating mask-based reconstruction with global contrastive alignment. Specifically, the Adaptive Reconstruction Branch mitigates false negatives by learning invariant representations through masked feature reconstruction, while the Dual-Attention-Based Contrast Branch refines embeddings by incorporating both local contextual dependencies and global structural reasoning, further enhancing discrimination via contrastive loss. Extensive experiments on real-world alignment benchmarks [22] (CERT-NVD and SF-NVD) demonstrate that DARA outperforms state-of-the-art methods CEAM [22], improving Pre@Rec = 0.95, F1, and PRAUC scores. By jointly optimizing fine- and coarse-grained representations with structured alignment reasoning, DARA establishes a new benchmark for accurate and scalable vulnerability intelligence consolidation.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DARA: Enhancing Vulnerability Alignment via Adaptive Reconstruction and Dual-Level Attention

  • Lihua Wang,
  • Jiaojiao Jiang,
  • Salil S. Kanhere,
  • Jiamou Sun,
  • Sanjay Jha,
  • Zhenchang Xing

摘要

Aligning vulnerabilities across various security repositories remains a vital yet difficult task, primarily due to absent or inconsistent vulnerability attributes, which can lead to false negatives and shared generic descriptors that may trigger false positives. Existing alignment frameworks, such as GNN-based methods, either focus solely on intra-graph structures without leveraging cross-repository dependencies or fail to integrate both fine-grained local feature learning and global structural differentiation. To address these limitations, we propose DARA (Dual-Attention-based Reconstruction vulnerability Alignment), a novel framework that jointly models intra- and inter-graph relationships through dual-attention mechanisms while integrating mask-based reconstruction with global contrastive alignment. Specifically, the Adaptive Reconstruction Branch mitigates false negatives by learning invariant representations through masked feature reconstruction, while the Dual-Attention-Based Contrast Branch refines embeddings by incorporating both local contextual dependencies and global structural reasoning, further enhancing discrimination via contrastive loss. Extensive experiments on real-world alignment benchmarks [22] (CERT-NVD and SF-NVD) demonstrate that DARA outperforms state-of-the-art methods CEAM [22], improving Pre@Rec = 0.95, F1, and PRAUC scores. By jointly optimizing fine- and coarse-grained representations with structured alignment reasoning, DARA establishes a new benchmark for accurate and scalable vulnerability intelligence consolidation.