Published February 28, 2022 | Version v1

DisCERN for Code Vulnerability Detection and Correction

  • 1. Robert Gordon University

Description

Counterfactual explanations highlight “actionable knowledge” which helps the end-users to understand how a machine learning outcome could be changed to a more desirable outcome. In code vulnerability detection, understanding these “actionable” corrections can be critical to proactively mitigate security attacks that are caused by known vulnerabilities. In this paper, we present the case-based explainer DisCERN for counterfactual discovery in code vulnerability detection. DisCERN explains the outcomes of black-box vulnerability detection models by highlighting actionable corrections to guide the user. DisCERN uses feature relevance explainer knowledge as a proxy to discover potentially vulnerable code statements and then uses a novel substitution algorithm based on pattern matching to find corrections from the nearest unlike neighbour. The overall aim of DisCERN is to identify vulnerabilities and correct them with minimal changes necessary. We evaluate DisCERN for validity and sparsity using three NIST SAR datasets 1 to find that Dis- CERN suggests meaningful corrections which is further established using example counterfactuals in a qualitative evaluation.

Files

AAAI_XAI_2022 (1).pdf

Files (1.5 MB)

Name Size Download all
md5:3beec80c579b2d4694e5831059aba2bb
1.5 MB Preview Download