6 papers
Beyond Single Reports: Evaluating Automated ATT&CK Technique Extraction in Multi-Report Campaign Settings
Md Nazmul Haque, Sivana Hamer, Brandon Wroblewski +2
Large-scale cyberattacks, referred to as campaigns, are documented across multiple CTI reports from diverse sources, with some providing a high-level overview of attack techniques…
How Do Semantically Equivalent Code Transformations Impact Membership Inference on LLMs for Code?
Hua Yang, Alejandro Velasco, Thanh Le-Cong +3
The success of large language models for code relies on vast amounts of code data, including public open-source repositories, such as GitHub, and private, confidential code from co…
Secure or Suspect? Investigating Package Hallucinations of Shell Command in Original and Quantized LLMs
Md Nazmul Haque, Elizabeth Lin, Lawrence Arkoh +2
Large Language Models for code (LLMs4Code) are increasingly used to generate software artifacts, including library and package recommendations in languages such as Go. However, rec…
How Quantization Impacts Privacy Risk on LLMs for Code?
Md Nazmul Haque, Hua Yang, Zhou Yang +1
Large language models for code (LLMs4Code) rely heavily on massive training data, including sensitive data, such as cloud service credentials of the projects and personal identifia…
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
Sivana Hamer, Jacob Bowen, Md Nazmul Haque +3
The MITRE Adversarial Tactics, Techniques and Common Knowledge (MITRE ATT&CK) Attack Technique to Proactive Software Supply Chain Risk Management Framework (P-SSCRM) Task mapping d…
Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
Sivana Hamer, Jacob Bowen, Md Nazmul Haque +3
Software supply chain frameworks, such as the US NIST Secure Software Development Framework (SSDF), detail what tasks software development organizations are recommended or mandated…