כתבה
arXiv cs.AI ·
מדידה וניצולת הטיה תחבירית בביקורת קוד תקינה עם עזרת LLM
Measuring and Exploiting Contextual Bias in LLM-Assisted Security Code Review
מערכות ביקורת קוד שמשתמשות ב-LLM עשויות להיות חשופות להתקפי טיה תחבירית. חוקרים גילו שהטיה זו יכולה להיות ניצולה על ידי תוקפים כדי להכניס חולשות בקוד. זה חשוב להקפיד על תפקוד של אנשי מקצוע בתהליך הפיתוח.
תקציר מקורי באנגליתarXiv:2603.18740v3 Announce Type: replace-cross Abstract: Automated Code Review (ACR) systems integrating Large Language Models (LLMs) are increasingly adopted in software development workflows, ranging from interactive assistants to autonomous agents in CI/CD pipelines. In this paper, we study how LLM-based vulnerability detection in ACR is affected by the framing effect: the tendency to let the presentation of information override its semantic content in forming judgments. We examine whether adversaries can exploit this through contextual-bias injection (crafting PR metadata to bias ACR security judgments) as a supply-chain attack vector against real-world ACR pipelines. To this end, we first conduct a large-scale exploratory study across 6 LLMs under five framing conditions, establishin
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית