LATIDIA · Ciberseguridad
¿En qué se equivocó la primera reparación? Localización de los orígenes de las fallas silenciosas en la reparación de vulnerabilidades genéticas
arXiv:2610.06163v1 Announce Type: new Abstract: Localizing where a LLM-based agent first fail to keep security during a repair can show which stage of its workflow needs a additional safeguard. Esto es difícil para
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.06163v1 Announce Type: new Abstract: Localizing where an LLM-based agent first fails to uphold security during a repair can show which stage of its workflow needs an additional safeguard. This is difficult for silent failures, which are patches that pass syntactic and functional checks but still contain a security vulnerability. Because such patches give no observable failure signal, existing failure attribution methods, which rely on observed task failures and labelled failure steps, are less suited to them. We propose Security Awareness Gap Evaluation (SAGE), a trace-based method that combines an assessment of the security reasoning recorded at each turn with the reconstructed code history to identify the earliest turn at