发表机构
Zhejiang University(浙江大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究推出WeSCE基准,针对仅指定功能目标的弱安全约束下的代码编辑,提出连续风险表示与漂移度量,以量化代码编辑中的安全漂移,为安全评估提供多尺度视角。
AI 中文摘要
在本研究中,我们推出WeSCE,这是一个用于量化弱安全约束下代码编辑中安全漂移的基准,其中任务仅指定功能目标,无明确安全要求。WeSCE包含400个源自真实代码的可执行程序,涵盖功能添加、功能移除、漏洞修复和重构。为量化安全漂移,我们提出一种连续风险表示,通过统一公式聚合异构漏洞信号,并定义漂移度量以捕捉代码转换下整体风险、最坏情况严重程度和漏洞分布的变化,提供从平均情况行为到最坏情况重点的多尺度安全视图。
英文摘要
In this work, we introduce WeSCE, a benchmark for quantifying security drift in code editing under weak-security constraints, where tasks specify only functional objectives without explicit security requirements. WeSCE consists of 400 executable programs derived from real-world code, covering feature addition, feature removal, bug fixing, and refactoring. To quantify security drift, we propose a continuous risk representation that aggregates heterogeneous vulnerability signals through a unified formulation, and define drift measures capturing changes in overall risk, worst-case severity, and vulnerability distribution under code transformations, providing a multi-scale view of security spanning average-case behavior to worst-case emphasis.