arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CoGate:用于安全代码生成的置信门控协同解码

CoGate: Confidence-Gated Co-Decoding for Secure Code Generation

Minghao Hu, Lannan Luo, Allen Roush, Phillip Howard

arXiv 2607.28529首次发表:更新:

AI 中文总结

针对现有协同解码未考虑专家模型置信度的问题,提出CoGate方法,在多LLM后端和代码生成基准上优于CoSec+,在CWEval的Func-Sec@10指标最高提升12.6%。

AI 中文摘要

大型语言模型被广泛用于代码生成,但由于其从预训练数据中学习到的模式,也可能生成不安全的程序。解码时引导已成为解决该问题的重要方案:在每一步将小型专家模型与目标模型结合以生成更安全的代码,这被称为协同解码。然而,现有协同解码方法的接受规则未考虑专家模型的置信度,当安全专家因未见过的模式或分布外(OOD)上下文而置信度不足时,其指导可能具有误导性。为应对这一挑战,我们提出CoGate,一种基于专家模型置信度控制其对协同解码过程影响的置信门控协同解码方法。我们实现了该方法,并在多个LLM后端(CodeGen、DeepSeek-Coder、Qwen-Coder、StarCoder)和多个代码生成基准(HumanEval、安全套件及CWEval)上进行评估。我们的方法在多个基准上优于现有协同解码方法(CoSec+),在CWEval上实现了Func-Sec@10指标最高12.6%的提升。

英文摘要

Large language models are widely used for code generation, but they can also produce insecure programs due to patterns learned from their pretraining data. Decoding-time steering has become an important solution to this problem: a small expert model is combined with the target model at each step to generate more secure code, which is referred to as co-decoding. However, the acceptance rule for existing co-decoding approaches does not consider the expert model's confidence. When the security expert is unconfident due to unseen patterns or out-of-distribution (OOD) contexts, its guidance can therefore be misleading. To address the challenge, we propose CoGate, a confidence-gated co-decoding approach that controls the expert's influence on the co-decoding process based on its confidence. We implement our approach and evaluate it across multiple LLM backends (CodeGen, DeepSeek-Coder, Qwen-Coder, StarCoder) on several code generation benchmarks (HumanEval, security suite, and CWEval). Our approach outperforms existing co-decoding methods (CoSec+) across multiple benchmarks, achieving up to a 12.6% gain of Func-Sec@10 on CWEval.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑