Predicting Software Vulnerabilities Using Artificial Intelligence Models: A Systematic Literature Review

Authors

  • Ahmad Raad Fathi Software Department, College of Computer Sciences & Mathematics, University of Mosul, Mosul, Iraq
  • Ibrahim Ahmed Saleh Software Department, College of Computer Sciences & Mathematics, University of Mosul, Mosul, Iraq

DOI:

https://doi.org/10.71229/vh28zt77

Keywords:

Software Vulnerability Prediction, Machine Learning, Deep Learning, NLP Transformers

Abstract

Software vulnerabilities are an increasing and critical threat to the security of modern digital infrastructure. The National Vulnerability Database NVD recorded more than 33,000 new vulnerabilities in 2021–2022 alone. As traditional detection approaches such as manual code review and dynamic testing are insufficient to cope with the scale and complexity of today’s software systems, automated, intelligent and proactive solutions are required. This paper follows the PRISMA guidelines for a systematic literature review . The structured search of the Scopus index was performed on 14 August 2026, and 916 records were obtained for the period 2020–2025. After screening titles and abstracts against six exclusion criteria, 663 records remained, a paradigm specific eligibility criterion requiring a dataset appropriate to each study’s methodological paradigm reduced these to 178 eligible studies, 127 of which evaluate on a named, standardized code level benchmark. These were purposively sampled for in depth synthesis, leading to 14 studies 8 primary, 6 supplementary selected to maximize coverage of 7 methodological paradigms including Abstract Syntax Tree (AST) based source code analysis, graph based deep learning using Code Property Graphs (CPGs), NLP driven severity classification, temporal forecasting, runtime behavioral monitoring, corpus level evolutionary analysis and information retrieval driven feature engineering. Key datasets used in these studies are Draper VDISC dataset with SATE IV Juliet Test Suite, MVFSC benchmark (396,130 function level samples), NVD corpus (110,000+ reports), Java open source systems. The synthesis reveals that in all studies directly comparing them, structural code representations like ASTs and CPGs outperform metric-based or text-only features, and that graph-based models like GraphSAGE are superior to sequence-based models. Three research gaps are quantified against the systematic corpus. First, of 61 records evaluated on the Juliet Test Suite or SARD, only three compare three or more distinct algorithm families and none compare all four under a single controlled protocol. Second, of the 127 pre release, code level eligible studies, only 4 mention the Common Vulnerability Scoring System (CVSS) or severity at all. No identified study combines pre release source code prediction with CVSS compatible severity estimation. Third, artifact availability is reported in only 42 of 178 eligible studies (23.6%) and the mean reproducibility score across the primary studies is 2.1 of 4. This review provides the empirical basis for the proposed framework to overcome these shortcomings via multi algorithm comparison, integrated severity prediction, and reproducible evaluation on standardized benchmark datasets.

References

[1] Sheng, Z. et al.: Large Language Models in Software Security: A Survey of Vulnerability Detection Techniques. arXiv:2502.07049 [cs.CR] (2025).

[2] Zhou, Y., Liu, S., Siow, J., Du, X., Liu, Y.: Devign: Effective Vulnerability Identification by Learning Comprehensive Program Semantics via Graph Neural Networks. In: Advances in Neural Information Processing Systems (NeurIPS) 32 (2019).

[3] B. Mweu and J. Ndia, “Static Analysis Techniques for Secure Software: A Systematic Review,” Computers, Materials & Continua, vol. 79, no. 3, pp. —, 2025, doi: 10.32604/cmc.2025.071765.

[4] NIST National Vulnerability Database NVD. Available: https://nvd.nist.gov/ (2024).

[5] MITRE Corporation. Common Weakness Enumeration (CWE). Available: https://cwe.mitre.org/ (2024).

[6] Yamaguchi, F., Golde, N., Arp, D., Rieck, K.: Modeling and Discovering Vulnerabilities with Code Property Graphs. In: Proc. IEEE Symposium on Security and Privacy (S&P), pp. 590–604 (2014).

[7] Li Y, Huang CL, Wang ZF, Yuan L, Wang XC. Survey of software vulnerability mining methods based on machine learning. Ruan Jian Xue Bao/Journal of Software, 2020, 31(7): 2040 –2061 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/6055.htm [doi: 10.13328/j.cnki.jos.006055].

[8] Bichsel, P., Ferrara, P., Gross, T., Vechev, M.: Statistical Deobfuscation of Android Applications. In: Proc. ACM CCS, pp. 343–355 (2016).

[9] Cao SC, Sun XB, Bo LL, Wu RX, Li B, Tao CQ. MVD: Memory related vulnerability detection based on flow sensitive graph neural networks. In: Proc. of the 44th IEEE/ACM Int ’l Conf. on Software Engineering. Pittsburgh: IEEE, 2022. 1456 –1468. doi: 10.1145/3510003.3510219

[10] W. Zheng, X. Wu, A. O. A. Semasaba, S. A. Agyemang, T. Liu, and Y. Ge, “Representation vs. Model: What Matters Most for Source Code Vulnerability Detection,” in Proc. IEEE Int. Conf. on Software Analysis, Evolution and Reengineering (SANER), 2021, pp. 647–653.

[11] Bilgin, Z., Ersoy, M.A., Soykan, E.U., Tomur, E., Comak, P., Karacay, L.: Vulnerability Prediction From Source Code Using Machine Learning. IEEE Access 8, 150672–150684 (2020).

[12] Williams, M.A., Barranco, R.C., Naim, S.M., Dey, S., Hossain, M.S., Akbar, M.: A Vulnerability Analysis and Prediction Framework. Computers & Security 92, 101751 (2020). https://doi.org/10.1016/j.cose.2020.101751

[13] Carletti, V., Foggia, P., Saggese, A., Vento, M.: Predicting Source Code Vulnerabilities Using Deep Learning: A Fair Comparison on Real Data. In: ITASEC 2024, CEUR-WS, vol. 3731 (2024).

[14] Orojo, A.K., Elumelu, W.C., Orojo, O.O., Donnahoo, M., Hutton, S.: Predicting Software Vulnerability Trends with Multi Recurrent Neural Networks. In: Proc. 1st Int. Conf. NLP & AI for Cyber Security, pp. 42–47 (2024).

[15] Sierhieiev, Y., Paiuk, V., Nicheporuk, A., Kwiecien, A., Huralnyk, O.: Detection and Prediction of Vulnerabilities Based on Behavioral Analysis with ML. In: ICyberPhyS-2024, CEUR-WS, vol. 3736 (2024).

[16] Bonhomme, C., Dulaunoy, A.: VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification. arXiv:2507.03607 [cs.CR] (2025).

[17] Meka, C.G.: Information Retrieval Driven Software Vulnerability Prediction. Ph.D. thesis, University College London (2025).

[18] Chakraborty, S., Krishna, R., Ding, Y., Ray, B.: Deep Learning Based Vulnerability Detection: Are We There Yet? IEEE Transactions on Software Engineering 48(9), 3280–3296 (2022). https://doi.org/10.1109/TSE.2021.3087402

fig 1

Downloads

Published

2026-08-28

Issue

Section

Review Papers

How to Cite

Predicting Software Vulnerabilities Using Artificial Intelligence Models: A Systematic Literature Review. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(3), 549-563. https://doi.org/10.71229/vh28zt77

Similar Articles

11-20 of 36

You may also start an advanced similarity search for this article.