Integrating Artificial Open Generative Artificial Intelligence into Software Supply Chain Security
arXiv:2412.19088 · doi:10.1109/ICDABI63787.2024.10800301
Abstract
While new technologies emerge, human errors always looming. Software supply chain is increasingly complex and intertwined, the security of a service has become paramount to ensuring the integrity of products, safeguarding data privacy, and maintaining operational continuity. In this work, we conducted experiments on the promising open Large Language Models (LLMs) into two main software security challenges: source code language errors and deprecated code, with a focus on their potential to replace conventional static and dynamic security scanners that rely on predefined rules and patterns. Our findings suggest that while LLMs present some unexpected results, they also encounter significant limitations, particularly in memory complexity and the management of new and unfamiliar data patterns. Despite these challenges, the proactive application of LLMs, coupled with extensive security databases and continuous updates, holds the potential to fortify Software Supply Chain (SSC) processes against emerging threats.
References in corpus (8)
- LLaMA: Open and Efficient Foundation Language Models
- A Survey on Large Language Model (LLM) Security and Privacy: The Good, the Bad, and the Ugly
- Phi-3 Technical Report: A Highly Capable Language Model Locally on Your Phone
- Large Language Models for Supply Chain Optimization
- Revolutionizing Cyber Threat Detection with Large Language Models: A privacy-preserving BERT-based Lightweight Model for IoT/IIoT Devices
- How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
- LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and Benchmarks
- What is Software Supply Chain Security?