After some incredibly annoying stalled research, I am close to empirically demonstrating that the #neuralnets used for machine learning-assisted software vulnerability detection #mlavd are *only* recognizing code patterns and not able to perform the calculations and code-flow required to test for vulnerability.
#warning These are early, tentative results. Still working on testing the graph and transformer-based models. I do expect graph models to perform somewhat better, but we'll see.