Logo PTI Logo FedCSIS

Proceedings of the 21st Conference on Computer Science and Intelligence Systems (FedCSIS)

Annals of Computer Science and Information Systems, Volume 47

Embedding-Level Pretraining for Assembly-Level Vulnerability Detection Using Transformer Models

, ,

DOI: http://dx.doi.org/10.15439/2026F7378

Citation: Dominik Ciesiołkiewicz, ,

Full text

Abstract. This paper presents a deep learning framework for assembly-level vulnerability detection that operates directly on disassembled binary code, addressing scenarios where source code is unavailable. The approach combines pretrained PalmTree instruction embeddings with a RoBERTa-based transformer adapted to process continuous inputs. We introduce an embedding-level masked language modeling strategy that masks in the continuous embedding space using Gaussian noise. This enables the model to capture contextual relationships between assembly instructions without relying on discrete token representations. The method is evaluated on the ROMEO dataset across multiple Common Weakness Enumeration (CWE) classes and demonstrates strong performance on accuracy, precision, recall, F1-score and PR-AUCs. Ablation studies further confirm the effectiveness of embedding-level pretraining and PalmTree embeddings. These results suggest that embedding-aware transformer architectures are a promising direction for vulnerability detection in binary code.

References

  1. P. Marwedel, Embedded system design: Embedded systems foundations of cyber-physical systems. Dordrecht: Springer Netherlands, 2011. https: //dx.doi.org/10.1007/978-94-007-0257-8
  2. M. Eceiza, J. L. Flores, and M. Iturbe, “Fuzzing the Internet of Things: A review on the techniques and challenges for efficient vulnerability discovery in embedded systems,” IEEE Internet Things J., vol. 8, no. 13, pp. 10390–10411, Jul. 2021. https://dx.doi.org/10.1109/JIOT.2021.3056179
  3. S. Taviss, S. H. H. Ding, M. Zulkernine, P. Charland, and S. Acharya, “Asm2Seq: Explainable assembly code functional summary generation for reverse engineering and vulnerability analysis,” Digital Threats, vol. 5, no. 1, Art. no. 6, pp. 1–25, Mar. 2024. https://dx.doi.org/10.1145/3592623
  4. D. Liu, Y. Tang, B. Wang, W. Xie, and B. Yu, “Automated vulnerability detection in embedded devices,” in Advances in Digital Forensics XIV, G. Peterson and S. Shenoi, Eds. Cham: Springer International Publishing, 2018, pp. 313–329. https://dx.doi.org/10.1007/978-3-319-99277-8 17
  5. A. Aumpansub and Z. Huang, “Learning-based vulnerability detection in binary code,” in Proc. 14th Int. Conf. Machine Learning and Computing (ICMLC), 2022. https://dx.doi.org/10.1145/3529836.3529926
  6. H. Hanif and S. Maffeis, “VulBERTa: Simplified source code pre-training for vulnerability detection,” in Proc. Int. Joint Conf. Neural Networks (IJCNN), 2022. https://dx.doi.org/10.1109/IJCNN55064.2022.9892280
  7. X. Li, Y. Qu, and H. Yin, “PalmTree: Learning an assembly language model for instruction embedding,” in Proc. 2021 ACM SIGSAC Conf. Computer and Communications Security (CCS), Nov. 2021, pp. 3236– 3251. https://dx.doi.org/10.1145/3460120.3484587
  8. A. Diwan, M. Q. Li, and B. C. M. Fung, “VDGraph2Vec: Vulnerability detection in assembly code using message passing neural networks,” in 2022 21st IEEE Int. Conf. Machine Learning and Applications (ICMLA), Nassau, Bahamas, Dec. 2022, pp. 1039–1046. https://dx.doi.org/10.1109/ ICMLA55696.2022.00173
  9. A. Qasem, P. Shirani, M. Debbabi, L. Wang, B. Lebel, and B. L. Agba, “Automatic vulnerability detection in embedded devices and firmware: Survey and layered taxonomies,” ACM Comput. Surv., vol. 54, no. 2, pp. 1–42, Mar. 2022. https://dx.doi.org/10.1145/3432893
  10. W. Charoenwet, P. Thongtanunam, V.-T. Pham, and C. Treude, “An empirical study of static analysis tools for secure code review,” in Proc. ACM SIGSOFT Int. Symp. Software Testing and Analysis (ISSTA), 2024.
  11. R. Venkitaraman and G. Gupta, “Static program analysis of embedded executable assembly code,” in Proc. 2004 Int. Conf. Compilers, Architecture, and Synthesis for Embedded Systems, Washington, DC, USA, Sep. 2004, pp. 157–166. https://dx.doi.org/10.1145/1023833.1023857
  12. R. Bagnara, A. Bagnara, and P. M. Hill, “The MISRA C coding standard and its role in the development and analysis of safety- and securitycritical embedded software,” unpublished, Sep. 4, 2018. https://dx.doi. org/10.48550/arXiv.1809.00821
  13. S. Rawat, D. Ceara, L. Mounier, and M.-L. Potet, “Combining static and dynamic analysis for vulnerability detection,” unpublished, May 16, 2013. https://dx.doi.org/10.48550/arXiv.1305.3883
  14. Z. Qian, F. Zhong, Q. Hu, Y. Jiang, J. Huang, M. Ren, and J. Yu, “Software vulnerability analysis across programming language and program representation landscapes: A survey,” unpublished, Mar. 26, 2025. https://dx.doi.org/10.48550/arXiv.2503.20244
  15. Z. Shen and S. Chen, “A survey of automatic software vulnerability detection, program repair, and defect prediction techniques,” Security and Communication Networks, vol. 2020, pp. 1–16, Sep. 2020. https://dx.doi. org/10.1155/2020/8858010
  16. S. Kim, R. Y. C. Kim, and Y. B. Park, “Software vulnerability detection methodology combined with static and dynamic analysis,” Wireless Pers. Commun., vol. 89, no. 3, pp. 777–793, Aug. 2016. https://dx.doi.org/10. 1007/s11277-015-3152-1
  17. A. Guzman and OWASP Contributors, “Firmware security testing methodology,” OWASP. [Online]. Available: https://scriptingxss.gitbook. io/firmware-security-testing-methodology. [Accessed: Aug. 27, 2025].
  18. M. Messner and P. Eckmann, “Firmware security analyzer EMBA,” presented at TROOPERS22, Heidelberg, Germany, 2022. [Online]. Available: https://troopers.de/downloads/troopers22/TR22 EMBA.pdf. [Accessed: Aug. 27, 2025].
  19. Z. Li, D. Zou, S. Xu, H. Jin, Y. Zhu, Z. Chen, S. Wang, and J. Wang, “VulDeePecker: A deep learning-based system for vulnerability detection,” in Proc. 2018 Network and Distributed System Security Symp., 2018. https://dx.doi.org/10.14722/ndss.2018.23158
  20. R. L. Russell, L. Y. Kim, L. H. Hamilton, T. Lazovich, J. A. Harer, O. Ozdemir, P. M. Ellingwood, and M. W. McConley, “Automated vulnerability detection in source code using deep representation learning,” unpublished, Nov. 28, 2018. https://dx.doi.org/10.48550/arXiv.1807.04320
  21. X.-C. Wen, Y. Chen, C. Gao, H. Zhang, J. M. Zhang, and Q. Liao, “Vulnerability detection with graph simplification and enhanced graph representation learning,” unpublished, Feb. 9, 2023. https://dx.doi.org/10. 48550/arXiv.2302.04675
  22. Y. Chen, Z. Lin, and Z. Guo, “Application of hierarchical attention network in vulnerability detection model,” in 2024 2nd Int. Conf. Big Data and Privacy Computing (BDPC), Macau, China, Jan. 2024, pp. 43– 48. https://dx.doi.org/10.1109/BDPC59998.2024.10649344
  23. “The Common Vulnerabilities and Exposures (CVE) program,” The MITRE Corporation. [Online]. Available: https://www.cve.org/. [Accessed: Aug. 19, 2025].
  24. National Institute of Standards and Technology, “Juliet C/C++ 1.3 test suite,” Software Assurance Reference Dataset (SARD). [Online]. Available: https://samate.nist.gov/SARD/test-suites/112. [Accessed: Aug. 19, 2025].
  25. C.-A. Brust, T. Sonnekalb, and B. Gruner, “ROMEO: A binary vulnerability detection dataset for exploring Juliet through the lens of assembly language,” Computers & Security, vol. 128, Art. no. 103165, May 2023. https://dx.doi.org/10.1016/j.cose.2023.103165
  26. “objdump(1) — Linux manual page,” man7.org. [Online]. Available: https://man7.org/linux/man-pages/man1/objdump.1.html. [Accessed: Aug. 19, 2025].
  27. Hugging Face, “RoBERTa model documentation,” Hugging Face Transformers, 2024. [Online]. Available: https://huggingface.co/docs/ transformers/model doc/roberta. [Accessed: Sep. 1, 2025].