Rethinking Mixture-of-Experts for Vulnerability Detection: An Empirical Study and Improved Design
Deep learning–based vulnerability detection (DLVD) has recently adopted the Mixture-of-Experts (MoE) paradigm to address vulnerability heterogeneity and the long-tailed distribution of Common Weakness Enumeration (CWE) categories. A representative framework, MoEVD, builds CWE-specific experts and a router for expert selection, but its assumptions about expert specialization and routing reliability remain underexplored. We reproduce MoEVD under the same dataset, splits, backbone, and evaluation protocol, and conduct a fine-grained empirical study of expert behavior and routing decisions. We find that CWE-based experts do not consistently develop stable or exclusive specialization, and their effectiveness is highly sensitive to non-target vulnerabilities. More importantly, an idealized-router baseline shows that routing mismatch measurably limits what the original experts can achieve under idealized routing, while learned routing disproportionately sends non-vulnerable samples to a few experts. Guided by these findings, we explore targeted changes that relax strict CWE-based expert binding and replace fixed top-k routing with probability-mass-based top-p selection under a controlled OR-style voting rule. Under a controlled OR-style comparison on BigVul, the combined design shifts the precision--recall trade-off, improving F1 from 0.38 to 0.42 and recall from 0.32 to 0.39 while slightly increasing FPR. Repeated runs and zero-shot checks on two external datasets suggest that the trend is stable in the evaluated settings, while the improvements remain modest.
Authors
- Chaofeng Sha (ORCID: https://orcid.org/0009-0004-4195-0122)
- Xin Peng (ORCID: https://orcid.org/0000-0003-3376-2581)
- Rongze Jiang
Institutions
- Fudan University (CN)
Publication Details
- Journal
- Proceedings of the ACM on software engineering.
- Published
- 2026-10-01
- DOI
- https://doi.org/10.1145/3832223
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00