Research
Code written to be misread by an LLM
prompt injection, invisible unicode and adversarial rewrites aimed at the model reading your code
Maciej Cichoń
What Vulnerability Detectors Actually Learn
Testing whether code models encode vulnerabilities or just learn labels
Maciej Cichoń
LLMs Write Insecure Code by Default
When a prompt asks for a feature and never mentions security, what do language models write? A benchmark of eleven models on 1,007 sink-forcing tasks.
Bartłomiej Dmitruk
change the code, keep the bug
building a scalable benchmark measuring LLM capabilities for vulnerability detection
Maciej Cichoń