Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

On-Premise CodeBERT-Driven Model for Vulnerability Detection in Source Code

Sako, D.J.S., Hart, B.S., Bennett, E.O. , Deedam, F.B.

Abstract

Security vulnerabilities in software systems remain a major concern in modern computing, especially as applications grow in complexity and are increasingly integrated into critical infrastructures. Traditional vulnerability detection methods such as static code analysis tools and manual inspection face limitations in accuracy, scalability, and privacy preservation, since they often rely on cloud-based solutions that expose sensitive source code. This paper presents an on- premise Artificial Intelligence (AI)-based model for vulnerability detection in source code, designed to ensure there is efficiency in identifying potential weaknesses. The system employs a fine-tuned CodeBERT model, which leverages transformer-based natural language processing techniques to learn semantic patterns in source code. By deploying the model locally within a Dockerized environment, the solution ensures that source code remains entirely under organizational control, eliminating reliance on external servers. The methodology integrates real- time scanning for multiple programming languages (Python, Java, and JavaScript), a web-based upload interface, and a core detection algorithm capable of classifying vulnerabilities based on learned patterns. Evaluation results demonstrate strong detection performance, with an average score of 92% for accuracy, precision, recall and F1-score respectively. The findings highlight the potential of on-premise AI-based systems to revolutionize vulnerability detection by combining accuracy and scalability.

Keywords

Vulnerability DetectionOn-Premise AISource Code AnalysisCodeBERTDockerSonarQube

References

Bahaa, S., Zeng, J., Zhou, T., & Choo, K. K. R. (2022). Explainable AI and privacy-preserving techniques in cybersecurity. Computers & Security, 119, 102769. Begolli, I., Aksoy, M. & Neider, N. (2025). Fine-Tuning Multilingual Language Models for Code Review: An Empirical Study on Industrial C# Projects. https://arxiv.org/html/2507.19271v1 Cheng, L., Zou, Y., & Gu, H. (2024). VULEXPLAINER: Locating vulnerability-critical code lines. ACM Transactions on Software Engineering, 33(2), 12–20. https://arxiv.org/abs/2401.02737 Doshi-Velez, F., & Kim, B. (2017). Towards a rigorous science of interpretable machine learning. arXiv preprint arXiv:1702.08608. Feng, Z., Guo, D., Tang, D., Duan, N., Feng, X., Gong, M., ... & Zhou, M. (2020). CodeBERT: A Pre-Trained Model for Programming and Natural Languages. arXiv preprint arXiv:2002.08155. GitHub. (2023). CodeQL documentation. GitHub Docs. https://codeql.github.com/docs/ Hanif, K., & Maffeis, S. (2022). VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection, https://arxiv.org/abs/2205.12424 Merkel, D. (2014). Docker: Lightweight Linux Containers for Consistent Development and Deployment. Linux Journal, 2014(239), 2. Kim, J. (2022). Code representation learning for vulnerability detection. Journal of Software Security, 45(2), 33–47. Nath, R. (2023). Decentralized AI-based system for multiparty software vulnerability detection. International Journal of Cybersecurity, 15(1), 55–72. Nguyen, D., & Choo, K. K. R. (2021). AI approaches to vulnerability detection: A survey. Cybersecurity Advances, 10(3), 98–120.https://doi.org/10.1109/access.2022.3191115 OWASP. (2023). OWASP Top 10 Vulnerabilities. https://owasp.org/www-project-top-ten/ Pakalapati, K., Rajapaksha, L., & Nguyen, K. (2023). On-premise AI for secure software development. International Journal of Privacy and Security, 12(3), 243–260. Shen, M., Pillai, A.A. Yuan, B.A. Davis, J.C. and Machiry, A. (2025). Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software, https://arxiv.org/pdf/2310.00205 Shimmi, S., Okhravi, H, & Rahimi, M. (2025). AI-Based Software Vulnerability Detection: A Systematic Literature Review. https://arxiv.org/html/2506.10280v1 Rajapaksha, P. (2023). AI-powered classification models for vulnerability detection in C/C++ applications. Journal of Secure Computing, 18(1), 76–91. Rajapaksha, L., Nath, A., & Smith, J. (2022). Decentralized systems combining AI and blockchain for vulnerability detection. Cryptography and Security Journal, 9(4), 345–370. Sonar Source. (2023). SonarQube official documentation. https://docs.sonarsource.com/ sonarqube/ Wang, L., Chen, C., Zhu, J., Zhan, R. and Han, W. (2026). CQLLM: A Framework for Generating CodeQL Security Vulnerability Detection Code Based on Large Language Model, Appl. Sci., 16(1), 517; https://doi.org/10.3390/app16010517 Wu, Y., Zou, D., Dou, S., Yang, W., Xu, D. and Jin, H. (2022). VulCNN: An Image-inspired Scalable Vulnerability Detection System. In 44th International Conference on Software Engineering (ICSE ’22) , https: //doi.org/10.1145/3510003.3510229 Zhang, Y., & Xin, H. (2023). VulCNN and VulGAI: Image-inspired and graph-enhanced deep learning for code vulnerability detection. ACM Transactions on Software Engineering and Methodology, 32(2), 1–27.

More Articles from INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND MATHEMATICAL THEORY

Advances in Algorithmic Contract Scoring for Pre-Negotiation Yield Optimization and Risk Retention

Author: Ngozi Samuel Uzougbo, Michael Ominyi, Cyril Chimelie Anichukwueze, Blessing, Chika Jones

DevTest flow: Designing a Scalable Continuous Testing Pipeline for High-Velocity Software Delivery

Author: Lawal Ahmed Oladimeji, Achori Busayo, Akeju BusayoZainab, Saka Samson, Damilare, Mbah Demian Chidi, Runsewe Similoluwa Mayowa, Oladiti Luqman, Abiodun