paper-with-me

홈 › Papers

Security-by-Design for LLM-Based Code Generation: Leveraging Internal Representations for Concept-Driven Steering Mechanisms

2026-03-11 · Maximilian Wendlinger, Daniel Kowatsch, Konstantin Böttinger, Philip Sperl arxiv

Large Language Models (LLMs) show remarkable capabilities in understanding natural language and generating complex code. However, as practitioners adopt CodeLLMs for increasingly critical development tasks, research reveals that these models frequently generate functionally correct yet insecure code, posing significant security risks. While multiple approaches have been proposed to improve security in AI-based code generation, combined benchmarks show these methods remain insufficient for practical use, achieving only limited improvements in both functional correctness and security. This stems from a fundamental gap in understanding the internal mechanisms of code generation and the root causes of security vulnerabilities, forcing researchers to rely on heuristics and empirical observations. In this work, we investigate the internal representation of security concepts in CodeLLMs, revealing that models are often aware of vulnerabilities as they generate insecure code. Through systematic evaluation, we demonstrate that CodeLLMs can distinguish between security subconcepts, enabling a more fine-grained analysis than prior black-box approaches. Leveraging these insights, we propose Secure Concept Steering for CodeLLMs (SCS-Code). During token generation, SCS-Code steers LLMs' internal representations toward secure and functional code output, enabling a lightweight and modular mechanism that can be integrated into existing code models. Our approach achieves superior performance compared to state-of-the-art methods across multiple secure coding benchmarks.

📄 PDF Abstract BibTeX arXiv:2603.11212

Code (0)

등록된 구현이 없습니다.

Tasks

Code Generation

Similar Papers 제목 키워드 기반

A Mixture of Linear Corrections Generates Secure Code

2025-07-13 · Weichen Yu, Ravi Mangal, Terry Zhuo, Matt Fredrikson 외 arxiv

Large language models (LLMs) have become proficient at sophisticated code-generation tasks, yet remain ineffective at reliably detecting or avoiding code vulnerabilities. Does this deficiency stem from insufficient learn…

SecPI: Secure Code Generation with Reasoning Models via Security Reasoning Internalization

2026-04-04 · Hao Wang, Niels Mündler, Mark Vero, Jingxuan He 외 arxiv

Reasoning language models (RLMs) are increasingly used in programming. Yet, even state-of-the-art RLMs frequently introduce critical security vulnerabilities in generated code. Prior training-based approaches for secure …

Code Generation

TypePilot: Leveraging the Scala Type System for Secure LLM-generated Code

2025-10-13 · Alexander Sternfeld, Andrei Kucharavy, Ljiljana Dolamic arxiv

Large language Models (LLMs) have shown remarkable proficiency in code generation tasks across various programming languages. However, their outputs often contain subtle but critical vulnerabilities, posing significant r…

Code Generation

Enhancing Security Control Production With Generative AI

2024-11-06 · Chen Ling, Mina Ghashami, Vianne Gao, Ali Torkamani 외

Security controls are mechanisms or policies designed for cloud based services to reduce risk, protect information, and ensure compliance with security regulations. The development of security controls is traditionally a…

In-Context LearningRetrieval-augmented Generation

LMSM: LLM Security Framework Inspired by Linux Security Modules

2026-08-26 · XiuYu Zhang, Bonan Ruan, Junfeng Fang, An Zhang 외 hf

Large language models (LLMs) are increasingly deployed with layered defenses, yet malicious prompts can still bypass them. Interpretability methods can expose model-internal signals along the generation path that could i…