arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

路由上限与领域无关:代码安全漏洞检测中的结构先验注入

Routing Ceilings Are Domain-Independent: Structural Prior Injection in Code Security Vulnerability Detection

Manuel Israel Cázares

arXiv 2607.14628首次发表:更新:

发表机构

Bytepro AI(字节专业人工智能公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究在代码安全漏洞检测中测试路由器假设是否跨领域,通过重现SAIR设计评估三个大语言模型。结果表明结构先验能提升语义漏洞召回率,零样本性能随语义复杂度下降,备忘单在真实数据上效果不佳,迭代重新校准也有问题,证实了SAIR的跨分布权衡及路由器假设的跨领域性。

AI 中文摘要

大语言模型(LLMs)在潜在能力和一致激活之间存在差距:路由器假设认为模型具备解决任务的知识,但缺乏可靠的内部路由来激活它。形式数学推理方面的先前工作表明,结构先验(备忘单)能显著提高分布内性能,但在分布外(OOD)会降至零样本基线以下,且迭代重新校准会加剧而非纠正这种崩溃。我们通过在源代码安全漏洞检测中重现SAIR设计来测试此现象是否跨领域,评估了三个大语言模型在三种漏洞类别上的表现,然后将增强备忘单的提示转移到来自VUDENC的真实世界CVE数据上。我们的发现复制并扩展了SAIR:结构先验将所有模型的语义漏洞召回率从20.0%提高到100.0%;零样本性能沿语义复杂度梯度下降;相同的备忘单在合成性能上饱和,但在真实CVE数据上会放大分布转移崩溃;迭代重新校准产生的v2备忘单在真实数据上比v1更差。这些结果表明SAIR中记录的跨分布权衡表面可推广到代码安全,且路由器假设是跨领域的。我们认为崩溃的结构性质促使进行分布感知训练而非提示校准。代码和评估脚本:此https URL

英文摘要

Large language models (LLMs) exhibit a well-documented gap between latent capability and consistent activation: the router hypothesis posits that models possess the knowledge to solve a task but lack reliable internal routing to activate it. Prior work in formal mathematical reasoning (SAIR, Cázares 2026) reports that structural priors (cheatsheets) raise in-distribution performance dramatically, yet collapse below the zero-shot baseline out-of-distribution (OOD) -- and that iterative recalibration amplifies rather than corrects the collapse. We test whether this phenomenon is cross-domain by reproducing the SAIR design in source-code security vulnerability detection, evaluating three LLMs (GPT-OSS-120B, Llama-3.3-70B, Gemma-4-31B) across three vulnerability categories (CWE-798, CWE-284, and the non-CWE N+1 anti-pattern) spanning syntactic, contextual, and semantic complexity, then transferring cheatsheet-augmented prompts to real-world CVE data from VUDENC (CWE-89, CWE-22). Our findings replicate and extend SAIR: (F1) structural priors lift semantic-vulnerability recall from 20.0% to 100.0% across all models; (F2) zero-shot performance degrades along a semantic complexity gradient; (F3) the same cheatsheets that saturate synthetic performance amplify distribution-shift collapse on real CVE data (CWE-89: 100% synthetic F1 to 48.9% on VUDENC, -51.1pp); (F5) iterative recalibration produces a v2 cheatsheet that performs worse than v1 on real data, mirroring SAIR's AN45c-vs-AN38 finding. These results provide evidence that the cross-distribution trade-off surface documented in SAIR generalises to code security, and that the router hypothesis is cross-domain. We argue the structural nature of the collapse motivates distribution-aware training over prompt calibration. Code and evaluation scripts: https://github.com/bytepro-ai/bitcoder-v2-research

Comments12 pages, 5 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑