PulseAugur
实时 06:17:39
English(EN) Direction for Detection: A Survey of Automated Vulnerability Detection and all of its Pain Points

调查揭示人工智能驱动的软件漏洞检测中存在的持续性缺陷

一篇新发表在arXiv上的调查论文详细介绍了使用机器学习进行自动化漏洞检测(ML4AVD)领域中持续存在的挑战和痛点。该论文调查了87项有影响力的工作,确定了十二个相互关联的问题,这些问题阻碍了进展,例如存在缺陷的问题表述、数据集和指标。这些问题产生了自我强化的反馈循环,导致该领域狭隘地专注于函数级别的C/C++漏洞的二元分类,而忽略了漏洞类型预测和对更多编程语言的支持等更广泛的领域。作者提出了具体的建议来解决这些问题,并评估了ML4AVD在agentic AI背景下的相关性。 AI

影响 强调了人工智能在软件安全方面的关键局限性,表明需要新的方法来提高有效性。

排序理由 该条目是一篇发表在arXiv上的调查论文,详细介绍了研究发现和分析。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

调查揭示人工智能驱动的软件漏洞检测中存在的持续性缺陷

本文如何被排名

Signal score
32 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该条目是一篇发表在arXiv上的调查论文,详细介绍了研究发现和分析。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
paper, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. arXiv cs.AI TIER_1 English(EN) · Dan Ristea, Shae McFadden, Ezzeldin Shereen, Madeleine Dwyer, Sanyam Vyas, Chris Hicks, Vasilios Mavroudis ·

    检测方向:自动化漏洞检测及其所有痛点的调查

    arXiv:2412.11194v3 Announce Type: replace-cross Abstract: Security vulnerabilities in software can have severe consequences; however, manual vulnerability detection is costly and does not scale, especially as agentic coding frameworks increase the rate of code production. Over th…