PulseAugur
实时 14:20:23

研究评估LLM辅助的软件漏洞修复

arXiv上发表的一项新研究调查了大型语言模型(LLM)在协助开发人员进行软件漏洞修复方面的有效性。研究假设,虽然LLM可能会加快修复过程,但它们也可能引入不安全的代码或表面化的修复,这些修复可以通过功能测试但无法通过安全验证。该研究概述了一个使用带有隐藏测试的Web应用程序进行的受控实验,以将LLM辅助修复与手动调试进行比较。 AI

影响 调查使用LLM进行软件安全的潜在风险和收益,为开发人员的最佳实践提供信息。

排序理由 该集群包含一篇详细介绍LLM能力实证研究的研究论文。

在 arXiv cs.AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

研究评估LLM辅助的软件漏洞修复

报道来源 [2]

  1. arXiv cs.AI TIER_1 English(EN) · Fabio Massacci ·

    有用还是有害?通过一项人类研究评估LLM辅助漏洞修复

    Software vulnerability remediation is a cognitively demanding task that requires specialized security expertise often lacking in general developers. In the meantime, Large Language Models (LLMs) assisted tools show potential in vulnerability detection, location, and repair tasks.…

  2. Hugging Face Daily Papers TIER_1 English(EN) ·

    有益还是有害?通过人类研究评估LLM辅助漏洞修复

    Software vulnerability remediation is a cognitively demanding task that requires specialized security expertise often lacking in general developers. In the meantime, Large Language Models (LLMs) assisted tools show potential in vulnerability detection, location, and repair tasks.…