SecLLM4SVD

Secured Large Language Models in Reliable Software Vulnerability Detection

Inspiration

Large language models (LLMs) are increasingly used to detect software vulnerabilities, offering a level of code understanding that traditional rule-based and signature-based methods can't match. However, LLMs are vulnerable to adversarial attacks — subtle code modifications like variable renaming or control-flow changes that can silently mislead their detection output. Because LLMs operate as black boxes, it's difficult to know whether they truly understand code semantics or are simply recognizing superficial patterns, making it hard to trust, diagnose, or secure their use in real-world software security. SecLLM4SVD is motivated by this gap: the need to understand why LLMs make the decisions they do, and to make them reliably robust before they're deployed in security-critical settings.

Innovation

SecLLM4SVD is a fundamental research project that investigates the reliability and robustness of LLM-based software vulnerability detection. The project will:

  • Develop mechanistic interpretability methods to explain how LLMs identify vulnerabilities in code.
  • Build a unified framework to systematically assess and generate adversarial attacks against LLM-based detectors.
  • Design human-in-the-loop countermeasures that align LLM reasoning with expert knowledge to improve resilience.
  • Launch a dynamic leaderboard ranking state-of-the-art LLMs by robustness against real-world adversarial attacks.

By combining mechanistic interpretability, adversarial robustness, and human-AI alignment, SecLLM4SVD moves beyond simply improving detection accuracy — it aims to make LLM-based security tools provably trustworthy, a dimension largely overlooked in current AI-for-security research.

Impact

The project's outcomes will provide:

  • A mechanistically interpretable detection pipeline, revealing how LLMs reason about vulnerabilities in code.
  • A quantifiable framework for assessing adversarial risk in LLM-based security tools.
  • Human-in-the-loop defense strategies that improve the reliability of LLM-based detection.
  • A public leaderboard and open tools/datasets to benchmark LLM robustness in vulnerability detection.

By exposing and mitigating adversarial vulnerabilities in LLM-based security tools, SecLLM4SVD will help organizations deploy AI-driven vulnerability detection with confidence — with applications spanning secure software development, automated code auditing, and safer adoption of AI in security-critical industries.

Project Profile

Start date
 
1.4.2026
End date
 
30.9.2029
Duration
 
42 Months
Keywords
 
vulnerability detection and remediation; programming languages; sciences and software engineering; large language models (LLM)

Funding

Funding Framework
 
FNR INTER, ANR
Call
 
INTER/ANR/25

 
This project has received funding from the French National Research Agency (ANR) under Grant Agreement nº ANR-25-CE25-5615 and the Fonds National de la Recherche Luxembourg (FNR) under Grant Agreement nº INTER/ANR/25/19582186/SecLLM4SVD.

Partners

People

How can we help you?

By content type (optional)