Skip to main content

A Multimodal Framework for Source Code Vulnerability Detection, Explanation, and Mitigation

Submitted by Anonymous on
PhD Thesis📅 30.07.2026 — 13:30
👤 Speaker:
IBRAHIM TARAKCI
🎓 Supervisor(s):
PROF.DR.HALIT OGUZTUZUN, ASST.PROF.DR.SELMA SULOGLU
📍 Location:
A105
⏲ Duration:
120 min.
📝 Abstract:

This thesis develops a multimodal approach to source code vulnerability detection, explanation, and mitigation. It investigates complementary software representations, including source code, general-purpose, security-aware, and taint-based metrics, together with functional and security-oriented summaries generated by large language models (LLMs). These representations are evaluated independently and through multimodal fusion using machine learning, deep learning, pretrained code models, and LLMs. The study also examines dataset quality, duplicate and near-duplicate samples, class imbalance, cross-dataset generalization, and robustness under semantic-preserving code transformations. Robustness is treated as a separate evaluation dimension rather than an operational component of the final framework. The later stages extend vulnerability detection toward structured explanation and LLM-assisted mitigation. Multimodal evidence is used to generate explanations describing the likely root cause, vulnerability mechanism, supporting code evidence, predicted Common Weakness Enumeration (CWE) category, and potential impact. These explanations then guide candidate repair generation, while independent validation evaluates structural integrity, semantic alignment with the identified weakness, repair intent, and consistency with the available security evidence. The selected components are integrated into VulAREL—Vulnerability Assessment, Repair, and Explanation across Learning Models—a traceable, function-level framework that connects multimodal detection, structured explanation, and candidate repair while separating generation from hidden reference-based evaluation. The findings show that the value of multimodal evidence varies across tasks, datasets, and model families; explanation-guided mitigation is more effective than code-only mitigation; and generated repairs require independent validation and human oversight. Overall, the thesis provides a practical, auditable, and comprehensive framework for source code vulnerability analysis.

Time - Location
2026-07-30 13:30:00