Memory Safety in Kernel Development: An AI-Assisted Comparative Study of Rust- and C-Based Approaches to Preventing Memory Corruption

Authors

  • Asma Mustafa Alhadi Department of Computer Engineering and Sciences, Faculty of Science, University of Zawia, Libya Author
  • Nuha Omran Abokhdair Department of Computer Sciences, Faculty of Science, University of Zawia, Libya Author

DOI:

https://doi.org/10.65405/zhcpaq10

Keywords:

Memory Safety, Rust, C Programming, Kernel Development, Memory Corruption, Vulnerability Detection, Artificial Intelligence, Ownership, Buffer Overflow, Use-After-Free.

Abstract

Memory corruption remains a major source of security vulnerabilities in low-level and kernel-oriented software, particularly in systems implemented in C, where manual memory management exposes developers to errors such as buffer overflows, use-after-free, double-free, null-pointer dereferences, and memory leaks. This paper presents KernelMemSafe-AI, an AI-assisted comparative framework for evaluating memory-safety behavior in C- and Rust-based approaches within a kernel-development context. The proposed framework integrates two complementary components: an AI-assisted vulnerability-pattern classifier and a practical experimental comparison of C and Rust implementations.

A controlled and balanced dataset of 520 C/C++ and kernel-style code snippets was constructed and labeled as vulnerable or safe across multiple memory-corruption categories. The final hybrid classifier combines token and bigram analysis, Naive Bayes learning, rule-based memory-safety indicators, confidence scoring, and five-fold cross-validation. The classifier achieved 95.58% accuracy, 96.11% precision, 95.00% recall, and a 95.55% F1-score. In addition, five representative memory-safety experiments were implemented to compare language behavior in buffer-overflow, use-after-free, double-free, null-pointer-dereference, and memory-leak scenarios.

The experimental results show that C code often compiles successfully yet exhibits runtime failures, undefined behavior, allocator-level aborts, garbage values, or unreleased memory. In contrast, Rust prevents or mitigates several unsafe memory operations through ownership and move semantics, bounds checking, Option<T>, and automatic cleanup using Drop. The findings indicate that Rust provides stronger language-level protection against common memory-corruption patterns, while AI-assisted analysis can support the early identification of unsafe C code patterns. Overall, the study shows that combining memory-safe programming mechanisms with AI-assisted vulnerability analysis can improve the reliability and security of kernel-oriented software.

Downloads

Download data is not yet available.

References

[1] National Security Agency, “Software Memory Safety,” Cybersecurity Information Sheet, Nov. 2022.

[2] Microsoft Security Response Center, “We Need a Safer Systems Programming Language,” Microsoft Security Blog, Jul. 2019.

[3] H. Li, L. Guo, Y. Yang, S. Wang, and M. Xu, “An Empirical Study of Rust-for-Linux: The Success, Dissatisfaction, and Compromise,” in Proc. 2024 USENIX Annual Technical Conference (USENIX ATC), Santa Clara, CA, USA, 2024.

[4] Z. Li, A. Narayanan, M. M. Swift, and S. Jha, “Understanding the Security Impact of Rust in the Linux Kernel,” in Proc. Annual Computer Security Applications Conference (ACSAC), 2024.

[5] S. K. Panter and N. U. Eisty, “Rusty Linux: Advances in Rust for Linux Kernel Development,” in Proc. 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), 2024, pp. 496–502.

[6] H. Li, L. Guo, Y. Yang, S. Wang, and M. Xu, “Rust Meets Linux: Lessons from an Evolving Experiment,” ACM Transactions on Computer Systems, 2026.

[7] F. Garber, “Rust in the Linux Kernel: Analyzing Rust Implementations of Virtual General Purpose Input Output Drivers,” M.S. thesis, Technische Universität Wien, Vienna, Austria, 2025.

[8] A. Syalim and D. P. Sheradhien, “C vs Rust: Manual vs Automatic Spatial and Temporal Memory Safety,” The Indonesian Journal of Computer Science, vol. 14, no. 2, pp. 2197–2213, 2025.

[9] J. Fan, Y. Li, S. Wang, and T. N. Nguyen, “A C/C++ Code Vulnerability Dataset with Code Changes and CVE Summaries,” in Proc. 17th International Conference on Mining Software Repositories (MSR), Seoul, South Korea, 2020, pp. 508–512.

[10] S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep Learning Based Vulnerability Detection: Are We There Yet?,” IEEE Transactions on Software Engineering, vol. 48, no. 9, pp. 3280–3296, 2022.

[11] M. Fu and C. Tantithamthavorn, “LineVul: A Transformer-Based Line-Level Vulnerability Prediction,” in Proc. 19th International Conference on Mining Software Repositories (MSR), Pittsburgh, PA, USA, 2022, pp. 608–620.

[12] Y. Chen, Z. Ding, L. Alowain, X. Chen, and D. Wagner, “DiverseVul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection,” in Proc. 26th International Symposium on Research in Attacks, Intrusions and Defenses (RAID), Hong Kong, China, 2023, pp. 654–668.

[13] H. Hanif and S. Maffeis, “VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection,” in Proc. International Joint Conference on Neural Networks (IJCNN), 2022.

[14] Y. Li, S. Wang, and T. N. Nguyen, “Vulnerability Detection with Fine-Grained Interpretations,” in Proc. 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE), 2021.

[15] S. Cao, X. Sun, L. Bo, Y. Wei, and B. Li, “BGNN4VD: Constructing Bidirectional Graph Neural-Network for Vulnerability Detection,” Information and Software Technology, vol. 136, 2021.

[16] G. Lin, J. Zhang, W. Luo, L. Pan, O. De Vel, P. Montague, and Y. Xiang, “Software Vulnerability Discovery via Learning Multi-Domain Knowledge Bases,” IEEE Transactions on Dependable and Secure Computing, vol. 18, no. 5, pp. 2469–2485, 2021.

[17] C. Liang, L. Wang, Y. Zhang, and Z. Jin, “Survey of Source Code Vulnerability Analysis Based on Deep Learning,” Computers & Security, vol. 146, 2025.

[18] H. Su, X. Li, Y. Zhang, and J. Wang, “Source Code Vulnerability Detection Based on Deep Learning: A Review,” Discover Computing, 2026.

[19] X. He, Y. Wang, and L. Zhang, “An Improved Software Source Code Vulnerability Detection Model Based on Multi-Feature Screening and Integrated Sampling,” Sensors, vol. 25, no. 6, 2025.

[20] Z. Sheng, K. Tian, and D. Lo, “LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights,” ACM Computing Surveys, 2025.

Downloads

Published

2026-09-22

How to Cite

Memory Safety in Kernel Development: An AI-Assisted Comparative Study of Rust- and C-Based Approaches to Preventing Memory Corruption. (2026). Comprehensive Journal of Science, 11(42), 719-738. https://doi.org/10.65405/zhcpaq10

Most read articles by the same author(s)