4 papers
From Data Leak to Secret Misses: The Impact of Data Leakage on Secret Detection Models
Farnaz Soltaniani, Mohammad Ghafari
Machine learning models are increasingly used for software security tasks. These models are commonly trained and evaluated on large Internet-derived datasets, which often contain d…
Evaluating Large Language Models for Security Bug Report Prediction
Farnaz Soltaniani, Shoaib Razzaq, Mohammad Ghafari
Early detection of security bug reports (SBRs) is critical for timely vulnerability mitigation. We present an evaluation of prompt-based engineering and fine-tuning approaches for…
Think Broad, Act Narrow: CWE Identification with Multi-Agent Large Language Models
Mohammed Sayagh, Mohammad Ghafari
Machine learning and Large language models (LLMs) for vulnerability detection has received significant attention in recent years. Unfortunately, state-of-the-art techniques show th…
Poisoned Source Code Detection in Code Models
Ehab Ghannoum, Mohammad Ghafari
Deep learning models have gained popularity for conducting various tasks involving source code. However, their black-box nature raises concerns about potential risks. One such risk…