SecureVibe:让Vibe Coding更安全
SecureVibe: Making Vibe Coding More Secure
- Carnegie Mellon University(卡内基梅隆大学)
- Microsoft Research(微软研究院)
- University of Virginia, Charlottesville(弗吉尼亚大学夏洛茨维尔分校)
- University of California, San Diego(加利福尼亚大学圣迭戈分校)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对vibe coding中功能正确但存在安全漏洞的问题,提出SECUREVIBE训练方案,通过监督微调及两种后训练方法强化安全规划与测试,在多个基准上显著提升安全与功能通过率。
AI中文摘要:
随着vibe coding能力日益增强并广泛普及,即使是功能正确的解决方案中的安全漏洞也日益令人担忧。在调查功能正确但不安全的解决方案时,我们发现不安全的智能体进行有效规划与测试以发现功能需求背后隐藏安全风险的可能性,不到安全智能体的一半。受此启发,我们开发了SECUREVIBE,一种明确针对代码安全规划与测试的训练方案。SECUREVIBE围绕这些安全行为构建训练信号,包括在包含4项安全任务的安全套件上进行监督微调,以及后训练方法SECUREVIBE_rl和SECUREVIBE_hg,分别通过可验证的执行反馈和基于提示的自监督来增强安全能力。我们的SECUREVIBE在4个基准上的两类安全编码任务中均优于基线。具体而言,SECUREVIBE在BaxBench上将安全pass@1提高了6.9个百分点。这些提升还扩展到未见过的CWE类别,在SusVibes上提高了11.5个百分点。同时,它还将安全编码任务SusVibes上的功能pass@1提高了13.6个百分点,并将通用编码任务SWE-bench Verified上的功能pass@1提高了4.1个百分点。进一步分析提供了两个实用见解:(i)在安全规划、编码和测试之间多样化监督,比仅增加编码轨迹更能有效强化安全行为;(ii)当智能体现有的安全能力不足以从结果反馈中有效学习时,基于提示的监督尤其有价值。
英文摘要:
As vibe coding becomes increasingly capable and widespread, security vulnerabilities in even functionally correct solutions are a growing concern. When investigating functionally correct but insecure solutions, we find that the insecure agent is less than half as likely to conduct effective planning and testing for the hidden security risks behind the functional requirements. Motivated by this, we develop SECUREVIBE, a training recipe that explicitly targets planning and testing for code security. SECUREVIBE constructs training signals around these security behaviors. It includes supervised fine-tuning on the security suite with 4 security tasks, and post-training methods, SECUREVIBE_rl and SECUREVIBE_hg, to enhance security capabilities from verifiable execution feedback and hint-based self-supervision. Our SECUREVIBE outperforms the baseline on two types of security coding tasks across 4 benchmarks. Specifically, SECUREVIBE improves the security pass@1 by 6.9 points on BaxBench. The gains extend to unseen CWE categories, with improvements of 11.5 points on SusVibes. Meanwhile, it also improves functionality pass@1 by 13.6 points on the security coding task SusVibes and 4.1 points on the generic coding task SWE-bench Verified. Further analysis offers two practical insights: (i) diversifying supervision across security planning, coding, and testing strengthens security behaviors more effectively than adding coding trajectories alone, and (ii) hint-guided supervision is particularly valuable when the agent's existing security capabilities are insufficient to learn effectively from outcome feedback.