arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CyberForge:用于网络安全智能体训练的、基于代码仓库级别的经验证漏洞注入框架

CyberForge: Verified Vulnerability Injection at Repository Level for Cybersecurity Agent Training

Amine Lbath, Manan Suri, Aurelien Delaitre, Vadim Okun, Massih-Reza Amini, Ram D. Sriram, Dinesh Manocha

arXiv 2608.06471首次发表:更新:

发表机构

National Institute of Standards and Technology; Université Grenoble Alpes; CNRS; University of Maryland, College Park(美国国家标准与技术研究院; 格勒诺布尔阿尔卑斯大学; 法国国家科学研究中心; 马里兰大学帕克分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出CyberForge框架,通过向真实C/C++项目注入漏洞生成经验证的代码仓库级安全训练数据,微调后可提升智能体在SEC-bench和PatchEval上的漏洞修复性能。

AI 中文摘要

尽管近期取得了进展,但前沿的大语言模型(LLM)智能体在发现和修补现实软件中的复杂漏洞方面仍存在局限。公开可用的智能体已能辅助攻击者,攻击者仅需找到一个可利用的弱点,而防御者则必须持续在快速增长的代码库中识别并修补所有漏洞。更强的防御智能体将有助于缩小这一差距,但具备可复现构建与执行环境的安全训练数据稀缺仍是瓶颈。我们提出CyberForge,这是一个通过向真实C/C++项目注入漏洞来合成可执行的代码仓库级安全训练数据的框架。它对每个实例进行动态验证:注入后的构建必须通过项目的单元测试,且生成的漏洞证明(PoV)必须在注入后的构建上触发,而在干净构建上不触发。CyberForge不受公开漏洞可用性的限制,因此相比依赖历史CVE数据的数据增强技术具备可扩展性。生成的语料库包含80个项目、63个弱点类别中的1034个经验证漏洞,其编辑局部性与真实CVE补丁处于真实对真实的噪声下限下相似。对该语料库收集的轨迹进行微调,可在SEC-bench补丁修复任务中提升3.3至14.7个百分点,覆盖三种模型规模和两种教师模型的全部六种配置,其中31B规模的学生模型达到了其GPT-5.4-mini教师的水平,准确率为72.7%,而教师的准确率为74.0%。这些提升可泛化到分布外的PatchEval(包含其他编程语言的语料库),所有配置均实现了性能提升,且31B规模的学生模型通过了其教师模型的性能。

英文摘要

Despite recent advances, frontier large language model (LLM) agents remain limited in discovering and patching complex vulnerabilities in real-world software. Generally available agents can already aid attackers, who only need to find one exploitable weakness, while defenders must continuously identify and patch all vulnerabilities across fast-growing codebases. Stronger defensive agents would help close this gap, yet the scarcity of security training data with reproducible build and execution environments remains a bottleneck. We present CyberForge, a framework that synthesizes executable, repository-level security training data by injecting vulnerabilities into real C/C++ projects. It validates each instance dynamically: the injected build must pass the project's unit tests, and generated proof-of-vulnerability (PoV) must trigger on the injected build and not on the clean one. CyberForge is not limited by the availability of disclosed vulnerabilities, therefore it can scale in comparison to data augmentation techniques which rely on historic CVE data. The resulting corpus holds 1034 validated vulnerabilities across 80 projects and 63 weakness categories, with edit locality similar to real CVE patches under a real-versus-real noise floor. Fine-tuning on trajectories collected over this corpus improves SEC-bench patch repair by +3.3 to +14.7 points, in all six configurations of three model scales and two teachers, with the 31B student reaching its GPT-5.4-mini teacher, 72.7% against 74.0%. These gains generalize out of distribution to PatchEval, a corpus containing other programming languages, where every configuration also improves and the 31B student passes its teacher.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑