Researchers have developed a new framework called CodePoisonRAG that can inject specific vulnerabilities into code generated by Retrieval-Augmented Code Generation (RACG) systems. This framework works by transforming benign code into poisoned artifacts that align with attacker-selected weaknesses, even when the attacker has no access to the victim's internal systems. The poisoned artifacts are designed to be semantically mislabeled, appearing safe while actually containing vulnerabilities. Experiments showed high success rates in propagating these targeted weaknesses across different code generation models and even against security-focused systems like CodeGuarder. AI
IMPACT Highlights a new attack vector for AI code generation, potentially impacting the security of software developed with these tools.
RANK_REASON Academic paper detailing a new attack framework on AI code generation. [lever_c_demoted from research: ic=1 ai=1.0]
- arXiv
- CodeGuarder
- CodePoisonRAG
- Common Weakness Enumeration
- C programming language
- Java
- Retrieval-Augmented Code Generation
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →