Skip to main content

Showing 1–3 of 3 results for author: Parra, G D L T

Searching in archive cs. Search in all archives.
.
  1. arXiv:2401.07035  [pdf, other

    cs.SE

    Causative Insights into Open Source Software Security using Large Language Code Embeddings and Semantic Vulnerability Graph

    Authors: Nafis Tanveer Islam, Gonzalo De La Torre Parra, Dylan Manual, Murtuza Jadliwala, Peyman Najafirad

    Abstract: Open Source Software (OSS) security and resilience are worldwide phenomena hampering economic and technological innovation. OSS vulnerabilities can cause unauthorized access, data breaches, network disruptions, and privacy violations, rendering any benefits worthless. While recent deep-learning techniques have shown great promise in identifying and localizing vulnerabilities in source code, it is… ▽ More

    Submitted 13 January, 2024; originally announced January 2024.

  2. arXiv:2401.03374  [pdf, other

    cs.SE cs.AI

    LLM-Powered Code Vulnerability Repair with Reinforcement Learning and Semantic Reward

    Authors: Nafis Tanveer Islam, Joseph Khoury, Andrew Seong, Mohammad Bahrami Karkevandi, Gonzalo De La Torre Parra, Elias Bou-Harb, Peyman Najafirad

    Abstract: In software development, the predominant emphasis on functionality often supersedes security concerns, a trend gaining momentum with AI-driven automation tools like GitHub Copilot. These tools significantly improve developers' efficiency in functional code development. Nevertheless, it remains a notable concern that such tools are also responsible for creating insecure code, predominantly because… ▽ More

    Submitted 21 February, 2024; v1 submitted 6 January, 2024; originally announced January 2024.

  3. An Unbiased Transformer Source Code Learning with Semantic Vulnerability Graph

    Authors: Nafis Tanveer Islam, Gonzalo De La Torre Parra, Dylan Manuel, Elias Bou-Harb, Peyman Najafirad

    Abstract: Over the years, open-source software systems have become prey to threat actors. Even as open-source communities act quickly to patch the breach, code vulnerability screening should be an integral part of agile software development from the beginning. Unfortunately, current vulnerability screening techniques are ineffective at identifying novel vulnerabilities or providing developers with code vuln… ▽ More

    Submitted 17 April, 2023; originally announced April 2023.