Transformer-Based Secure Code Generation and Vulnerability Repair Using Fine-Tuned CodeLlama and Retrieval-Augmented Generation
编号:48 访问权限:仅限参会人 更新:2026-07-22 19:43:00 浏览:3次 Online

报告开始:2026年07月30日 17:50(Asia/Kolkata)

报告时间:15min

所在会场:[S4] Computer Vision and Pattern Recognition [S4-3] Computer Vision and Pattern Recognition

暂无文件

摘要
Abstract—Today's software systems are becoming more complex, and automatic detection and code remediation of software vulnerabilities becomes increasingly important for ensuring secure and functionally correct software code. Detecting security flaws is currently fairly effective, but creating secure alternative is not very effective. To fill this gap, here is an integrated framework that, on the test set of 262 examples, achieves a BLEU score of 30.65 and a CodeBERT embedding similarity score of 0.9643 that is impressively high in terms of semantic similarity to reference secure code. Qualitative results also illustrate the system's ability to successfully mitigate against various types of vulnerability within several programming languages such as SQL Injection, XSS, Path Traversal, ServerSide Request Forgery (SSRF) and Command Injection. We call our method a hybrid fine-tuning and RAG approach by adding a fine-tuning step to the pre-trained CodeLlama-13b model.To obtain these results, we propose a hybrid method consisting of fine-tuning a pre-trained CodeLlama-13b and a RetrievalAugmented Generation (RAG) pipeline. Fine-tuning was performed through Quantized Low-Rank Adaptation (QLoRA) on a multilingual vulnerable and corrected code snippet dataset by quantizing to 4 bits.Fine-tuning is done using Quantized Low-Rank Adaptation (QLoRA) with a multilingual dataset of vulnerable code snippets and corrected code snippets in 4 bits quantization. The RAG pipeline uses cross-encoder reranking along with the BGE encoder, which is a feature of ChromaDB, to fetch relevant contextual knowledge from large CVE and CWE databases to prevent hallucinations and induce generation.
关键词
Parameter-Efficient Fine-Tuning,QLoRA,Large Language Models,CodeLlama,RAG,Secure Code Generation,Vulnerability Detection
报告人
Younis Alshibli
student Muscat college

稿件作者
Younis Alshibli Muscat college
Ferddie Quiroz Canlas Muscat College
发表评论
验证码 看不清楚,更换一张
全部评论
重要日期
  • 会议日期

    07月30日

    2026

    08月01日

    2026

  • 06月30日 2026

    初稿截稿日期

  • 07月30日 2026

    注册截止日期

主办单位
The United Societies of Science
承办单位
Kongunadu College of Engineering and Technology
协办单位
IEEE Section
IEEE Madras Section
历届会议
移动端
在手机上打开
小程序
打开微信小程序
客服
扫码或点此咨询