Embedding-Level Pretraining for Assembly-Level Vulnerability Detection Using Transformer Models
Dominik Ciesiołkiewicz, Mirosław Łazoryszczak, Piotr Dziurzański
DOI: http://dx.doi.org/10.15439/2026F7378
Citation: Dominik Ciesiołkiewicz, Mirosław Łazoryszczak, Piotr Dziurzański (2026). Embedding-Level Pretraining for Assembly-Level Vulnerability Detection Using Transformer Models. In M. Bolanowski, M. Ganzha, M. Grzegorowski, L. Maciaszek, M. Paprzycki, A. Paszkiewicz, D. Ślęzak (eds), Proceedings of the 21st Conference on Computer Science and Intelligence Systems (FedCSIS). ACSIS, Vol. 47, pages 251–261.
Abstract. This paper presents a deep learning framework for assembly-level vulnerability detection that operates directly on disassembled binary code, addressing scenarios where source code is unavailable. The approach combines pretrained PalmTree instruction embeddings with a RoBERTa-based transformer adapted to process continuous inputs. We introduce an embedding-level masked language modeling strategy that masks in the continuous embedding space using Gaussian noise. This enables the model to capture contextual relationships between assembly instructions without relying on discrete token representations. The method is evaluated on the ROMEO dataset across multiple Common Weakness Enumeration (CWE) classes and demonstrates strong performance on accuracy, precision, recall, F1-score and PR-AUCs. Ablation studies further confirm the effectiveness of embedding-level pretraining and PalmTree embeddings. These results suggest that embedding-aware transformer architectures are a promising direction for vulnerability detection in binary code.
References
- P. Marwedel, Embedded system design: Embedded systems foundations of cyber-physical systems. Dordrecht: Springer Netherlands, 2011. https: //dx.doi.org/10.1007/978-94-007-0257-8
- M. Eceiza, J. L. Flores, and M. Iturbe, “Fuzzing the Internet of Things: A review on the techniques and challenges for efficient vulnerability discovery in embedded systems,” IEEE Internet Things J., vol. 8, no. 13, pp. 10390–10411, Jul. 2021. https://dx.doi.org/10.1109/JIOT.2021.3056179
- S. Taviss, S. H. H. Ding, M. Zulkernine, P. Charland, and S. Acharya, “Asm2Seq: Explainable assembly code functional summary generation for reverse engineering and vulnerability analysis,” Digital Threats, vol. 5, no. 1, Art. no. 6, pp. 1–25, Mar. 2024. https://dx.doi.org/10.1145/3592623
- D. Liu, Y. Tang, B. Wang, W. Xie, and B. Yu, “Automated vulnerability detection in embedded devices,” in Advances in Digital Forensics XIV, G. Peterson and S. Shenoi, Eds. Cham: Springer International Publishing, 2018, pp. 313–329. https://dx.doi.org/10.1007/978-3-319-99277-8 17
- A. Aumpansub and Z. Huang, “Learning-based vulnerability detection in binary code,” in Proc. 14th Int. Conf. Machine Learning and Computing (ICMLC), 2022. https://dx.doi.org/10.1145/3529836.3529926
- H. Hanif and S. Maffeis, “VulBERTa: Simplified source code pre-training for vulnerability detection,” in Proc. Int. Joint Conf. Neural Networks (IJCNN), 2022. https://dx.doi.org/10.1109/IJCNN55064.2022.9892280
- X. Li, Y. Qu, and H. Yin, “PalmTree: Learning an assembly language model for instruction embedding,” in Proc. 2021 ACM SIGSAC Conf. Computer and Communications Security (CCS), Nov. 2021, pp. 3236– 3251. https://dx.doi.org/10.1145/3460120.3484587
- A. Diwan, M. Q. Li, and B. C. M. Fung, “VDGraph2Vec: Vulnerability detection in assembly code using message passing neural networks,” in 2022 21st IEEE Int. Conf. Machine Learning and Applications (ICMLA), Nassau, Bahamas, Dec. 2022, pp. 1039–1046. https://dx.doi.org/10.1109/ ICMLA55696.2022.00173
- A. Qasem, P. Shirani, M. Debbabi, L. Wang, B. Lebel, and B. L. Agba, “Automatic vulnerability detection in embedded devices and firmware: Survey and layered taxonomies,” ACM Comput. Surv., vol. 54, no. 2, pp. 1–42, Mar. 2022. https://dx.doi.org/10.1145/3432893
- W. Charoenwet, P. Thongtanunam, V.-T. Pham, and C. Treude, “An empirical study of static analysis tools for secure code review,” in Proc. ACM SIGSOFT Int. Symp. Software Testing and Analysis (ISSTA), 2024.
- R. Venkitaraman and G. Gupta, “Static program analysis of embedded executable assembly code,” in Proc. 2004 Int. Conf. Compilers, Architecture, and Synthesis for Embedded Systems, Washington, DC, USA, Sep. 2004, pp. 157–166. https://dx.doi.org/10.1145/1023833.1023857
- R. Bagnara, A. Bagnara, and P. M. Hill, “The MISRA C coding standard and its role in the development and analysis of safety- and securitycritical embedded software,” unpublished, Sep. 4, 2018. https://dx.doi. org/10.48550/arXiv.1809.00821
- S. Rawat, D. Ceara, L. Mounier, and M.-L. Potet, “Combining static and dynamic analysis for vulnerability detection,” unpublished, May 16, 2013. https://dx.doi.org/10.48550/arXiv.1305.3883
- Z. Qian, F. Zhong, Q. Hu, Y. Jiang, J. Huang, M. Ren, and J. Yu, “Software vulnerability analysis across programming language and program representation landscapes: A survey,” unpublished, Mar. 26, 2025. https://dx.doi.org/10.48550/arXiv.2503.20244
- Z. Shen and S. Chen, “A survey of automatic software vulnerability detection, program repair, and defect prediction techniques,” Security and Communication Networks, vol. 2020, pp. 1–16, Sep. 2020. https://dx.doi. org/10.1155/2020/8858010
- S. Kim, R. Y. C. Kim, and Y. B. Park, “Software vulnerability detection methodology combined with static and dynamic analysis,” Wireless Pers. Commun., vol. 89, no. 3, pp. 777–793, Aug. 2016. https://dx.doi.org/10. 1007/s11277-015-3152-1
- A. Guzman and OWASP Contributors, “Firmware security testing methodology,” OWASP. [Online]. Available: https://scriptingxss.gitbook. io/firmware-security-testing-methodology. [Accessed: Aug. 27, 2025].
- M. Messner and P. Eckmann, “Firmware security analyzer EMBA,” presented at TROOPERS22, Heidelberg, Germany, 2022. [Online]. Available: https://troopers.de/downloads/troopers22/TR22 EMBA.pdf. [Accessed: Aug. 27, 2025].
- Z. Li, D. Zou, S. Xu, H. Jin, Y. Zhu, Z. Chen, S. Wang, and J. Wang, “VulDeePecker: A deep learning-based system for vulnerability detection,” in Proc. 2018 Network and Distributed System Security Symp., 2018. https://dx.doi.org/10.14722/ndss.2018.23158
- R. L. Russell, L. Y. Kim, L. H. Hamilton, T. Lazovich, J. A. Harer, O. Ozdemir, P. M. Ellingwood, and M. W. McConley, “Automated vulnerability detection in source code using deep representation learning,” unpublished, Nov. 28, 2018. https://dx.doi.org/10.48550/arXiv.1807.04320
- X.-C. Wen, Y. Chen, C. Gao, H. Zhang, J. M. Zhang, and Q. Liao, “Vulnerability detection with graph simplification and enhanced graph representation learning,” unpublished, Feb. 9, 2023. https://dx.doi.org/10. 48550/arXiv.2302.04675
- Y. Chen, Z. Lin, and Z. Guo, “Application of hierarchical attention network in vulnerability detection model,” in 2024 2nd Int. Conf. Big Data and Privacy Computing (BDPC), Macau, China, Jan. 2024, pp. 43– 48. https://dx.doi.org/10.1109/BDPC59998.2024.10649344
- “The Common Vulnerabilities and Exposures (CVE) program,” The MITRE Corporation. [Online]. Available: https://www.cve.org/. [Accessed: Aug. 19, 2025].
- National Institute of Standards and Technology, “Juliet C/C++ 1.3 test suite,” Software Assurance Reference Dataset (SARD). [Online]. Available: https://samate.nist.gov/SARD/test-suites/112. [Accessed: Aug. 19, 2025].
- C.-A. Brust, T. Sonnekalb, and B. Gruner, “ROMEO: A binary vulnerability detection dataset for exploring Juliet through the lens of assembly language,” Computers & Security, vol. 128, Art. no. 103165, May 2023. https://dx.doi.org/10.1016/j.cose.2023.103165
- “objdump(1) — Linux manual page,” man7.org. [Online]. Available: https://man7.org/linux/man-pages/man1/objdump.1.html. [Accessed: Aug. 19, 2025].
- Hugging Face, “RoBERTa model documentation,” Hugging Face Transformers, 2024. [Online]. Available: https://huggingface.co/docs/ transformers/model doc/roberta. [Accessed: Sep. 1, 2025].