Can Open Large Language Models Catch Vulnerabilities?

强化学习 钢筋 计算机科学 认知科学 人工智能 心理学 社会心理学
作者
DeepSeek-AI,Daya Guo,Dejian Yang,Haowei Zhang,Junxiao Song,Ruoyu Zhang,Runxin Xu,Qihao Zhu,Shirong Ma,Peiyi Wang,Xiao Bi,Xiaokang Zhang,Xingkai Yu,Yu Wu,Zhenhua Wu,Zhibin Gou,Zhihong Shao,Zhuoshu Li,Ziyi Gao,Aixin Liu
出处
期刊:Cornell University - arXiv 被引量:434
标识
DOI:10.4230/oasics.icpec.2025.4
摘要

As Large Language Models (LLMs) become increasingly integrated into secure software development workflows, a critical question remains unanswered: can these models not only detect insecure code but also reliably classify vulnerabilities according to standardized taxonomies? In this work, we conduct a systematic evaluation of three state-of-the-art LLMs - Llama3, Codestral, and Deepseek R1 - using a carefully filtered subset of the Big-Vul dataset annotated with eight representative Common Weakness Enumeration categories. Adopting a closed-world classification setup, we assess each model’s performance in both identifying the presence of vulnerabilities and mapping them to the correct CWE label. Our findings reveal a sharp contrast between high detection rates and markedly poor classification accuracy, with frequent overgeneralization and misclassification. Moreover, we analyze model-specific biases and common failure modes, shedding light on the limitations of current LLMs in performing fine-grained security reasoning.These insights are especially relevant in educational contexts, where LLMs are being adopted as learning aids despite their limitations. A nuanced understanding of their behaviour is essential to prevent the propagation of misconceptions among students. Our results expose key challenges that must be addressed before LLMs can be reliably deployed in security-sensitive environments.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
领导范儿应助LL采纳,获得10
1秒前
2秒前
简单宛秋发布了新的文献求助10
3秒前
柯云发布了新的文献求助10
3秒前
Chen发布了新的文献求助10
4秒前
6秒前
番茄糊芋丝完成签到 ,获得积分10
6秒前
在水一方应助一一采纳,获得10
6秒前
神勇契发布了新的文献求助10
7秒前
小瓶子发布了新的文献求助10
7秒前
zinc发布了新的文献求助10
8秒前
8秒前
8秒前
在下想完成签到 ,获得积分10
10秒前
10秒前
CodeCraft应助耍酷的白梦采纳,获得10
10秒前
momo发布了新的文献求助30
10秒前
日暮炊烟发布了新的文献求助10
11秒前
积极的誉完成签到,获得积分10
12秒前
小南发布了新的文献求助10
12秒前
13秒前
纸飞机发布了新的文献求助10
14秒前
16秒前
珍妮完成签到,获得积分10
17秒前
小马甲应助song采纳,获得10
17秒前
MGQQbg发布了新的文献求助10
17秒前
情怀应助aa采纳,获得10
17秒前
充电宝应助阔达的水壶采纳,获得10
19秒前
韫染发布了新的文献求助10
20秒前
纸飞机完成签到,获得积分10
21秒前
zhouzhou发布了新的文献求助10
22秒前
22秒前
zzz完成签到,获得积分10
25秒前
cqh完成签到,获得积分10
25秒前
情怀应助小南采纳,获得10
25秒前
棒棒糖完成签到,获得积分10
26秒前
zinc完成签到,获得积分10
26秒前
29秒前
30秒前
30秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Molecular Biology of Cancer: Mechanisms, Targets, and Therapeutics 3000
Les Mantodea de guyane 2500
VASCULITIS(血管炎)Rheumatic Disease Clinics (Clinics Review Articles) —— 《风湿病临床》(临床综述文章) 1000
Feldspar inclusion dating of ceramics and burnt stones 1000
What is the Future of Psychotherapy in a Digital Age? 801
The Psychological Quest for Meaning 800
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 计算机科学 有机化学 物理 生物化学 纳米技术 复合材料 内科学 化学工程 人工智能 催化作用 遗传学 数学 基因 量子力学 物理化学
热门帖子
关注 科研通微信公众号,转发送积分 5971903
求助须知:如何正确求助?哪些是违规求助? 7290045
关于积分的说明 15993025
捐赠科研通 5109810
什么是DOI,文献DOI怎么找? 2744103
邀请新用户注册赠送积分活动 1709926
关于科研通互助平台的介绍 1621839