Abstract
Abstract
Vulnerability localization aims to identify the specific lines of code that contain vulnerabilities, thereby enabling developers to address security issues more efficiently and promptly. While recent methods have employed attention weights (e.g., LineVul) or feature attribution techniques (e.g., Line-DP) to guide vulnerability localization based on detection outcomes, these methods may rely on signals that are not faithfully reflective of the model's decision process. In this paper, we propose VulProbe, a novel method that probes the hidden representations of a vulnerability detection model to achieve line-level vulnerability localization. The hidden representations that are input to discriminate vulnerabilities encode rich information about the source code. By probing these representations, VulProbe identifies syntactic structures that are highly associated with the model's predictive decisions and subsequently localizes the vulnerable lines. Specifically, we first fine-tune CodeBERT on a vulnerability detection task to ensure that the model learns vulnerability-related features. Next, we probe the syntactic information embedded in the hidden representations using a mask-based weighting mechanism that emphasizes vulnerability-related token pairs during probe training, and transform the probed information into Abstract Syntax Trees (ASTs). By comparing the predicted AST (P-AST) with the original AST (O-AST) derived from the input source code, we identify key syntactic structures associated with vulnerabilities and leverage these insights to localize vulnerable lines. To evaluate the performance of our VulProbe, we compare it with eight baseline methods using six evaluation metrics. VulProbe, at the median value, achieves Top-1 Accuracy of 0.2586, Top-3 Accuracy of 0.4224, Top-5 Accuracy of 0.4914, IFA of 6.03, Recall@1\%Effort of 0.422414, and Effort@20\%Recall of 0.003951. It improves the baselines by 108.21\% -- 660.03\%, 52.47\% -- 888.07\%, 25.76\% -- 723.47\%, 17.15\% -- 57.59\%, 62.58\% -- 9950.26\%, and 51.28\% -- 96.78\%, respectively. Statistical analysis further confirms that the improvements achieved by VulProbe over the baseline methods are significant.