LATIDIA · Ciberseguridad
Medición y explotación del sesgo contextual en la revisión del código de seguridad asistida por LLM
arXiv: 2603.18740v4Tipo de Anuncio: replace-cross Resumen: Los sistemas de Revisión Automatizada de Código (ACR) que integran Modelos de Lenguaje Grande (LLM) se adoptan cada vez más en los flujos de trabajo de desarrollo de software, que van desde
WhatsApp ↗Telegram ↗
La noticia
arXiv:2603.18740v4 Announce Type: replace-cross Abstract: Automated Code Review (ACR) systems integrating Large Language Models (LLMs) are increasingly adopted in software development workflows, ranging from interactive assistants to autonomous agents in CI/CD pipelines. In this paper, we study how LLM-based vulnerability detection in ACR is affected by the framing effect: the tendency to let the presentation of information override its semantic content in forming judgments. We examine whether adversaries can exploit this through contextual-bias injection (crafting PR metadata to bias ACR security judgments) as a supply-chain attack vector against real-world ACR pipelines. To this end, we first conduct a large-scale exploratory study across 6 LLMs under five framing conditions, establishing the