arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

针对AI拉取请求审查者的自适应代码修订攻击

Adaptive Code Revision Attacks on AI Pull Request Reviewers

Jingzhi Gong, Jie M. Zhang, Gunel Jahangirova, Meng Wang

arXiv 2610.05399首次发表:更新:

发表机构

King’s College London; University of Bristol(伦敦国王学院; 布里斯托大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出AFCRA攻击,利用AI PR审查者的反馈修复报告问题同时保留代码漏洞,实验显示成功率远超现有攻击,揭示反馈引导代码修订对自动化审查的严重威胁。

AI 中文摘要

拉取请求审查在代码到达用户之前保护软件,有助于防止可能使用户遭受攻击的漏洞。AI代理越来越多地执行这些审查并解释需要修复哪些问题。然而,对于提交易受攻击代码的攻击者来说,这些反馈也揭示了哪些更改可能获得批准。现有的PR攻击通过说服性文本和评论寻求此类批准,同时保持可执行代码不变。这尚不清楚攻击者是否可以利用反馈来修复报告的问题,同时在修订后的代码中保留漏洞。因此,我们使用AFCRA(自适应反馈引导的代码修订攻击)对该威胁进行了实证研究。为了区分成功的攻击与真正的修复,我们从159个已披露的漏洞构建了AFCRA-Bench,并带有可执行的漏洞利用程序来验证代码中的漏洞。在与Sonnet 5和GPT-5.5审查者的五轮交互中,AFCRA的成功率分别达到最强的评估文本或评论攻击的2.5倍和12.5倍。这些成功的案例研究表明,审查者接受对报告问题的修复,同时忽视幸存的漏洞。这些发现确立了反馈引导的代码修订对自动化PR审查构成威胁。为了解决这一威胁,我们为研究人员、AI提供商、PR审查者和PR作者提供了关于保护AI辅助开发的可操作启示。

英文摘要

Pull-request review protects software before new code reaches users, helping prevent vulnerabilities that could expose users to attacks. AI agents increasingly perform these reviews and explain which problems need fixing. However, for an attacker submitting vulnerable code, this feedback also reveals what changes may secure approval. Existing PR attacks seek such approval through persuasive text and comments while keeping executable code fixed. This leaves unclear whether an attacker can use the feedback to repair the reported problem while preserving a vulnerability in the revised code. We therefore conduct an empirical study of this threat using AFCRA (Adaptive Feedback-guided Code Revision Attack). To distinguish successful attacks from genuine repairs, we construct AFCRA-Bench from 159 disclosed vulnerabilities, with executable exploits to verify vulnerabilities in code. Across five-round interactions with Sonnet 5 and GPT-5.5 reviewers, AFCRA reaches success rates 2.5x and 12.5x those of the strongest evaluated text- or comment-based attack. Case studies of these successes show how reviewers accept repairs of reported problems while overlooking surviving vulnerabilities. These findings establish feedback-guided code revision as a threat to automated PR review. To address this threat, we derive actionable implications for researchers, AI providers, PR reviewers, and PR authors on securing AI-assisted development.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑