Pith. sign in

REVIEW 5 cited by

Security of Language Models for Code: A Systematic Literature Review

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2410.15631 v2 pith:W7TZLDCD submitted 2024-10-21 cs.SE cs.CR

classification cs.SEcs.CR
keywords modelscodelmslanguageresearchsecuritycodereviewtools
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Language models for code (CodeLMs) have emerged as powerful tools for code-related tasks, outperforming traditional methods and standard machine learning approaches. However, these models are susceptible to security vulnerabilities, drawing increasing research attention from domains such as software engineering, artificial intelligence, and cybersecurity. Despite the growing body of research focused on the security of CodeLMs, a comprehensive survey in this area remains absent. To address this gap, we systematically review 67 relevant papers, organizing them based on attack and defense strategies. Furthermore, we provide an overview of commonly used language models, datasets, and evaluation metrics, and highlight open-source tools and promising directions for future research in securing CodeLMs.

Discussion (0). Sign in to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation

    cs.CR 2026-07 conditional novelty 7.0 of 10

    Injected insecure coding preferences in LLM long-term memory raise vulnerability rates by 2.7-50.3 pp and suppress warnings; memory-level filtering restores safe behavior in the tested set.

  2. Unified Communication Compression Beyond Global Error Bounds for Distributed Nonconvex Optimization

    math.OC 2026-04 unverdicted novelty 7.0 of 10

    A unified compression algorithm for distributed nonconvex optimization achieves O(1/sqrt(T)) convergence for locally-bounded compressors, matching centralized 1-bit methods, with an improved O(1/T^{2/3}) rate after on...

  3. LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems

    cs.CR 2025-09 conditional novelty 6.0 of 10

    A systematic review that categorizes LLM threats, severity scores, and mitigations across development and operation life cycles and multiple deployment scenarios.

  4. MT4DP: Data Poisoning Attack Detection for DL-based Code Search Models via Metamorphic Testing

    cs.SE 2025-07 reject novelty 5.0 of 10

    MT4DP flags a code search query as poisoned when rewriting it changes the ranking of code more than a threshold, but the main evaluation is weakened by synthetic trigger insertion and threshold tuning on the test set.

  5. An Empirical Study of Vulnerable Package Dependencies in LLM Repositories

    cs.CR 2025-08 conditional novelty 4.0 of 10

    In 52 open-source LLM projects, 75.8% of those with dependency configs use at least one vulnerable package, and half of supply chain vulnerabilities stay undisclosed for over 56 months.

Pith tools