arXiv AI By Lin Cui, Vincenzo Scotti, Raffaela Mirandola

CVE2AP: Automated Generation of PDDL-Encoded Attack Paths via Large Language Models

Read the original on arXiv AI →

CVE2AP is an LLM-based system that automatically converts natural language CVE descriptions into PDDL-encoded attack paths. It uses structured prompting and an error‑feedback loop that refines outputs based on planner‑reported syntactic and solvability errors. Empirical tests across various LLMs show high quality results, with up to 86.9% syntax correctness, 78.6% solvability, and 93.1% semantic correctness, and GPT‑5.5 providing the best quality‑cost balance.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Sep 25

Detecting Data Poisoning in Code Generation LLMs via Black-Box, Vulnerability-Oriented Scanning

The paper introduces CodeScan, a black-box, vulnerability-oriented scanning framework designed to detect data poisoning and backdoor attacks in code generation large language models (LLMs). CodeScan operates by analyzing structural similarities across multiple code generations, normalizing them with abstract syntax tree (AST) techniques, and then applying LLM-based vulnerability analysis to identify recurring insecure patterns. Evaluations on 117 models across three architectures and multiple sizes show over 97% detection accuracy with fewer false positives compared to prior methods.

By Shenao Yan, Shan Jin, Shimaa Ahmed, Sunpreet Singh Arora, Yiwei Cai, Yizhen Wang, Yuan Hong