跳到主要导航 跳到搜索 跳到主要内容

VulKnow: Enhancing Vulnerability Detection with Structured Knowledge and Large Language Models

  • Guixiang Liao
  • , Yanli Chen
  • , Wei Ke
  • , Hanzhou Wu
  • , Zhicheng Dong
  • Guizhou Normal University
  • Xi'an Jiaotong University
  • Shanghai University
  • Tibet University

科研成果: 期刊稿件文章同行评审

摘要

The rapid proliferation of Internet-of-Things (IoT) systems has led to increasingly heterogeneous, resource-constrained, and security-sensitive software deployments. In this context, detecting vulnerabilities in embedded and system-level IoT code has become particularly critical, as even a single exploitable flaw may compromise entire networks or devices. Vulnerability detection in real-world software continues to pose significant challenges due to the intricate nature of program semantics, the diversity of vulnerability patterns, and the limited explainability offered by current machine learning models. Although Large Language Models (LLMs) have exhibited remarkable capabilities in comprehending and reasoning about source code, their effectiveness is frequently compromised by inadequate domain knowledge and instances of hallucinated outputs. To address these limitations, we propose VulKnow, a retrieval-augmented framework for vulnerability detection that harnesses structured vulnerability knowledge alongside multi-stage prompt-based reasoning. Specifically, VulKnow first constructs a structured knowledge base derived from authoritative sources such as CWE/CVE reports and standard library specifications. Sub-sequently, it conducts context-aware knowledge retrieval and integrates the retrieved items into an LLM-based initial filtering module. To ensure high-confidence and verifiable results, we design a multi-stage reasoning pipeline that progressively validates vulnerabilities through semantic prompts and consistency checks. Experiments conducted on multiple real-world datasets (Linux, Qemu, Big-Vul) demonstrate that VulKnow significantly enhances precision, recall, and explainability compared to existing static analysis tools as well as LLM-only baselines. This positions VulKnow as a reliable solution for practical vulnerability auditing scenarios.

源语言英语
期刊IEEE Internet of Things Journal
DOI
出版状态已接受/待刊 - 2026
已对外发布

学术指纹

探究 'VulKnow: Enhancing Vulnerability Detection with Structured Knowledge and Large Language Models' 的科研主题。它们共同构成独一无二的学术指纹。

引用此