Vollständiger Abstract
Worum geht es in dieser Arbeit?
Software vulnerabilities are an increasing and critical threat to the security of modern digital infrastructure. The National Vulnerability Database NVD recorded more than 33,000 new vulnerabilities in 2021–2022 alone. As traditional detection approaches such as manual code review and dynamic testing are insufficient to cope with the scale and complexity of today’s software systems, automated, intelligent and proactive solutions are required. This paper follows the PRISMA guidelines for a systematic literature review . The structured search of the Scopus index was performed on 14 August 2026, and 916 records were obtained for the period 2020–2025. After screening titles and abstracts against six exclusion criteria, 663 records remained, a paradigm specific eligibility criterion requiring a dataset appropriate to each study’s methodological paradigm reduced these to 178 eligible studies, 127 of which evaluate on a named, standardized code level benchmark. These were purposively sampled for in depth synthesis, leading to 14 studies 8 primary, 6 supplementary selected to maximize coverage of 7 methodological paradigms including Abstract Syntax Tree (AST) based source code analysis, graph based deep learning using Code Property Graphs (CPGs), NLP driven severity classification, temporal forecasting, runtime behavioral monitoring, corpus level evolutionary analysis and information retrieval driven feature engineering. Key datasets used in these studies are Draper VDISC dataset with SATE IV Juliet Test Suite, MVFSC benchmark (396,130 function level samples), NVD corpus (110,000+ reports), Java open source systems. The synthesis reveals that in all studies directly comparing them, structural code representations like ASTs and CPGs outperform metric-based or text-only features, and that graph-based models like GraphSAGE are superior to sequence-based models. Three research gaps are quantified against the systematic corpus. First, of 61 records evaluated on the Juliet Test Suite or SARD, only three compare three or more distinct algorithm families and none compare all four under a single controlled protocol. Second, of the 127 pre release, code level eligible studies, only 4 mention the Common Vulnerability Scoring System (CVSS) or severity at all. No identified study combines pre release source code prediction with CVSS compatible severity estimation. Third, artifact availability is reported in only 42 of 178 eligible studies (23.6%) and the mean reproducibility score across the primary studies is 2.1 of 4. This review provides the empirical basis for the proposed framework to overcome these shortcomings via multi algorithm comparison, integrated severity prediction, and reproducible evaluation on standardized benchmark datasets.
Bibliografischer Nachweis
Publikationsdaten
- Autor:innen
- Ahmad Fathi, Ibrahim Saleh
- Quelle
- Al-Noor Journal of Engineering Management and Computer Science
- Publikation
- 2026-01-01
- Band / Ausgabe
- Nicht angegeben
- Seiten
- Nicht angegeben
- ISSN / ISBN
- 3079-0689
- Zitationen
- 0 laut Crossref
- Referenzen
- 0 hinterlegt
Zitieren
Zitierfähiger Nachweis
Ahmad Fathi, Ibrahim Saleh (2026). Predicting Software Vulnerabilities Using Artificial Intelligence Models: A Systematic Literature Review. Al-Noor Journal of Engineering Management and Computer Science. https://doi.org/10.71229/vh28zt77
Kontext
Themen, Förderung und Nutzung
Lizenzhinweise: Lizenz 1