Research
Sixty-eight models agree, and none of it is the bug
sixty-eight open code models converge on a representation of vulnerable functions that does not contain the vulnerability
Maciej Cichoń
Reads the code but not the vulnerability
an unfitted reader of model activations cannot tell a vulnerable function from its own fix
Maciej Cichoń
Code written to be misread by an LLM
prompt injection, invisible unicode and adversarial rewrites aimed at the model reading your code
Maciej Cichoń
What Vulnerability Detectors Actually Learn
Testing whether code models encode vulnerabilities or just learn labels
Maciej Cichoń