Information-theoretical security budget for code generation using language models: identifying hidden vulnerability drift using mutual information monitoring tools

Гаипназаров , Рустам, Кузнецова , Виктория, Рахимов , Гиёс

Al-Farg'oniy avlodlari · 2026-yil

Annotatsiya

LLMs accelerate software development but often generate insecure code. This study proposes the Security Information Budget (SIB), a real-time metric measuring mutual information between model hidden representations and security context. Research suggests that a decrease in SIB precedes the generation of vulnerabilities. Tested on DeepSeek-Coder-33B and Qwen2.5-Coder-32B using CWE-Bench and HumanEval-Security, SIB monitoring achieved an F1 score of 0.81. It detected risks an average of 23 tokens before a vulnerability appeared, effectively complementing existing static analysis tools.

Maqola ma’lumotlari
MualliflarГаипназаров , Рустам, Кузнецова , Виктория, Рахимов , Гиёс
JurnalAl-Farg'oniy avlodlari
Nashr sanasi2026-04-28
Son2
Betlar37-45
TilRus

Kalit so‘zlar

large language models, code security, mutual information, information bottleneck, vulnerability detection, CWE., большие языковые модели, безопасность кода, взаимная информация, информационное узкое место, обнаружение уязвимостей, CWE., katta til modellari, kod xavfsizligi, o‘zaro axborot, axborot torayishi (information bottleneck), zaifliklarni aniqlash, CWE.

Ilmiy soha

Al-Farg'oniy avlodlari jurnalidan boshqa maqolalar

Al-Farg'oniy avlodlari — barcha maqolalar