Rosmaël Zidane Lekeufack Foulefack

dblp:385/5463 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
8since 2021 · last 2026
0009-0005-7701-1634ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Modeling function-level relationships for vulnerability detection in graph neural networks
abstract
Context: Deep learning, and in particular graph-based models, has advanced software vulnerability detection by effectively capturing structural code features. Nonetheless, most existing approaches treat source code as independent components, overlooking inter-function relationships and thereby missing potential vulnerability propagation across function boundaries. Objective: To address this limitation, we propose SCVdet , a Graph Attention Network (GAT) based method that integrates inter-function dependencies into the vulnerability detection process. Method: These dependencies are approximated by using a clustering technique over learned code functions’ embeddings. This enables scalable and dynamic modeling of function relationships without incurring the high computational cost of the static code analysis required to recover the full set of real and complete inter-function dependencies. We enhance representation learning by complementing the analysis of the functions’ code, local code semantics, with the inter-function dependency analysis, global project-level analysis. We then adopt two strategies: concatenation and attention, to fuse such local and global types of information. Results: Extensive experiments on multi-language datasets ( FFmpeg+QEMU , ProjectKB , Big-Vul , and CVEFixes ) demonstrate that SCVdet consistently outperforms both sequence-based and graph-based baselines, achieving up to a 16% improvement in F1-score at the function level and 7% at the statement level. Conclusion: The results indicate that SCVdet improves vulnerability detection by combining both local and global information. This approach increases detection accuracy and outperforms the capabilities of state-of-the-art tools while maintaining scalability.
Rosmaël Zidane Lekeufack Foulefack, Elisabetta Provvedini, Alessandro Marchetto 0001
Eng. Appl. Artif. Intell.1
2026 Domain-aware graph neural networks for source code vulnerability detection
abstract
Deep learning, in particular, graph-based models, has advanced software vulnerability detection by capturing structural code features. However, existing approaches often rely solely on source code and focus mainly on C/C++ at the function level, limiting their ability to detect fine-grained vulnerabilities in diverse languages like Java and Python. To overcome these limitations, we propose VVulDet , an enhanced Graph Neural Network model. VVulDet enriches code representations with complex graph representations through random walks feature update and incorporates domain knowledge from CVE and CWE descriptions, along with expert-provided reference code fragments. This integration enhances the model’s understanding of vulnerabilities beyond pure code structure. We evaluate VVulDet on four datasets covering Java, Python, and C/C++, demonstrating consistent improvements at both statement and function level detection. Notably, VVulDet achieves, on average, the highest overall performance across all datasets, demonstrating F1-score improvements of up to 8.6% and 9.6% at the statement and function levels on ProjectKB, 6.8% and 15.5% on MegaVul, 1.4% and 4.5% on CVEFixes, and 2.4% and 23.7% on BigVul, respectively, compared to the model version that does not incorporate domain knowledge. These results confirm that integrating domain knowledge into graph-based models significantly boosts vulnerability detection performance across multiple programming languages and granularity levels.
Rosmaël Zidane Lekeufack Foulefack, Alessandro Marchetto 0001
Inf. Softw. Technol.1
2025 Incorporating Domain Knowledge into GNNs for Advanced Vulnerability Detection in Java
abstract
In recent years, security testing and vulnerability detection in source code have experienced a significant transformation with the adoption of data-driven techniques. This shift has reduced reliance on manual analysis, addressed the high false-positive rates of static analyzers, and accelerated the early detection of software bugs, ultimately mitigating the risk of cyberattacks. Among these advancements, graph-based approaches have shown promising results by capturing structural and contextual patterns within source code. However, such methods often rely solely on the code under analysis, limiting their ability to comprehensively learn vulnerable patterns.This study explores the integration of domain-specific knowledge into a Graph Neural Network (GNN)–based model to enhance its understanding and detection of vulnerabilities. By incorporating resources such as Common Vulnerability Exposure (CVE) descriptions, Common Weakness Enumeration (CWE) definitions, and sample functions provided by security experts at the MITRE Corporation, we aim to enrich the model’s knowledge base. Our approach demonstrates significant improvements on a Java vulnerability dataset across all considerable metrics. This finding underscores the value of domain-specific augmentation in advancing vulnerability detection capabilities.
Rosmaël Zidane Lekeufack Foulefack, Alessandro Marchetto 0001
AST1
2025 On the Use of Imbalanced Datasets for Learning-Based Vulnerability Detection
Rosmaël Zidane Lekeufack Foulefack, Alessandro Marchetto 0001
ICTSS1
2024 Malaria Parasite Detection in Microscopic Blood Smear Images Using Deep Learning Techniques
abstract
Malaria remains a curable illness causing a significant number of deaths globally. Timely and accurate detection is crucial for prompt patient management. This research proposes a highly effective and precise Convolutional Neural Network (CNN) model designed specifically for detecting malaria parasites (MPD). Furthermore, two cutting-edge deep learning (DL) models, DenseNet121 and VGG16, were fine-tuned for MPD. The developed CNN model was trained using blood smear images and achieved notable performance: a classification accuracy of 96.66%, precision of 97.09%, F1-score of 96.56%, and sensitivity of 96.03%. A comprehensive analysis demonstrates that the proposed CNN model yields comparable accuracy to DenseNet121 and VGG16 while possessing notably fewer trainable parameters. This suggests that the proposed CNN model is more efficient and less complex than the pre-trained DenseNet121 and VGG16 models. Additionally, the proposed CNN technique surpasses the performance of three earlier investigations in MPD. Moreover, this paper presents heat maps as an explainable AI technique, highlighting significant regions and image patterns that significantly influence DL model decisions. Overall, the findings underscore the potential of DL algorithms in detecting malaria parasites, potentially aiding medical practitioners in administering timely treatments to millions affected by the disease.
Rosmaël Zidane Lekeufack Foulefack, Andronicus Ayobami Akinyelu, Dinna Ranirina, Berthine Nyunga Mpinda
IJCNN1
2024 Enhanced Graph Neural Networks for Vulnerability Detection in Java via Advanced Subgraph Construction
Rosmaël Zidane Lekeufack Foulefack, Alessandro Marchetto 0001
ICTSS1
2024 Enhancing Vulnerability Detection with Domain Knowledge: A Comparison of Different Mechanisms
Alessandro Marchetto 0001, Rosmaël Zidane Lekeufack Foulefack
ICTSS2
2024 Towards a Knowledge Graph Based Approach for Vulnerable Code Weaknesses Identification
Martina Vecellio Reane, Daniele Dall'Anese, Rosmaël Zidane Lekeufack Foulefack, Alessandro Marchetto 0001
ICTSS3