• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
  • HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    Ziyu Yao Announces EMNLP Paper on LLM Code Security

    Assistant professor Ziyu Yao announces EMNLP paper with student Hao Yan examining LLM code security mitigations.

    AA
    ZY
    2 Sources, 27d ago, first seen 27d ago

    TLDR

    Ziyu Yao posted about a new main paper at EMNLP written with student Hao Yan. The work focuses on code security concerns with current large language models. Yao states that existing mitigation approaches mostly treat the LLM as a blackbox. Their inspection shows these approaches often present a security-correctness tradeoff. The methods improve code security by removing its fun. The post from the GMU assistant professor highlights the tradeoff finding from the analysis of mitigation techniques for LLM generated code.

    Combined views

    1.7K

    2 Sources, first seen 27d ago

    Combined views

    1.7K

    2 Sources, first seen 27d ago

    19 likes
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet

    19 likes
    1 saves
    7 reposts

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    1 saves
    7 reposts

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    2 Sources

    @ZiyuYaoNew #EMNLP main paper with my student Hao Yan @Haaao_Y : Code security is a prevalent concern with current LLMs, while existing mitigations mostly treat the LLM as a blackbox. In our inspection, these mitigation approaches often present a security-correctness tradeoff --- they improve code security by removing its function, which makes the code more secure but also less useful. In this work, we mechanistically interpret how an LLM encodes safety vs. vulnerability in code generation and propose DuoSteer, a double-activation steering approach for mitigating code vulnerability while addressing the security-correctness tradeoff. Following the principle of actionable interpretability, we evaluate DuoSteer against practical mitigation approaches (SFT and hint prompting, a strong baseline by us as well) and found that DuoSteer gave better joint performance on code security and correctness. Our contrastive pair dataset, CODESEC-PAIRS, derived from Llama3.1-8B-Instruct and Qwen-2.5-Coder-7B-Instruct, is also released: https://huggingface.co/datasets/haaao821/CodeSec-Pairs More coming along this line to make interpretability grounded and useful in the application of code generation! Paper: https://arxiv.org/pdf/2608.30025 (And our earlier hint prompting paper just accepted to ACM TOSEM: https://arxiv.org/pdf/2506.23034)
    @anas_antRT @ZiyuYao: New #EMNLP main paper with my student Hao Yan @Haaao_Y : Code security is a prevalent concern with current LLMs, while existin…

    2 Sources

    @ZiyuYaoNew #EMNLP main paper with my student Hao Yan @Haaao_Y : Code security is a prevalent concern with current LLMs, while existing mitigations mostly treat the LLM as a blackbox. In our inspection, these mitigation approaches often present a security-correctness tradeoff --- they improve code security by removing its function, which makes the code more secure but also less useful. In this work, we mechanistically interpret how an LLM encodes safety vs. vulnerability in code generation and propose DuoSteer, a double-activation steering approach for mitigating code vulnerability while addressing the security-correctness tradeoff. Following the principle of actionable interpretability, we evaluate DuoSteer against practical mitigation approaches (SFT and hint prompting, a strong baseline by us as well) and found that DuoSteer gave better joint performance on code security and correctness. Our contrastive pair dataset, CODESEC-PAIRS, derived from Llama3.1-8B-Instruct and Qwen-2.5-Coder-7B-Instruct, is also released: https://huggingface.co/datasets/haaao821/CodeSec-Pairs More coming along this line to make interpretability grounded and useful in the application of code generation! Paper: https://arxiv.org/pdf/2608.30025 (And our earlier hint prompting paper just accepted to ACM TOSEM: https://arxiv.org/pdf/2506.23034)
    @anas_antRT @ZiyuYao: New #EMNLP main paper with my student Hao Yan @Haaao_Y : Code security is a prevalent concern with current LLMs, while existin…