<p>As AI technology advances, early detection of code vulnerabilities becomes increasingly critical for preventing exploitation, reducing remediation costs, enhancing user trust, and improving system performance. Recently, Large language Models (LLMs) have shown remarkable performance across various tasks using few-shot learning. This study aims to adopt LLM-based agents in a multi-turn discussion framework enhanced with a Retrieval-Augmented Generation (RAG) strategy to improve response quality. Our multi-agent approach transforms a single LLM into a highly collaborative intelligence through multi-turn self-collaboration with diverse personas. By leveraging their combined expertise, this approach enhances the accuracy of code vulnerability detection and improves inference capabilities. To effectively utilize few-shot learning samples, we employ intra-references to extract a small number of similar samples from the training data, and inter-references to obtain samples from external data. The experimental studies are conducted on the TreeVul_Ext dataset, and our model achieves promising results across different evaluation criteria. Furthermore, we apply our model to detect code vulnerabilities in low-resource languages and exhibit competitive performance as well.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Leveraging Intra- and Inter-References in vulnerability detection using Multi-Agent collaboration based on LLMs

  • Chung-Nan Tsai,
  • Jingnan Xie,
  • Chun-Ming Lai,
  • Ching-Sheng Lin

摘要

As AI technology advances, early detection of code vulnerabilities becomes increasingly critical for preventing exploitation, reducing remediation costs, enhancing user trust, and improving system performance. Recently, Large language Models (LLMs) have shown remarkable performance across various tasks using few-shot learning. This study aims to adopt LLM-based agents in a multi-turn discussion framework enhanced with a Retrieval-Augmented Generation (RAG) strategy to improve response quality. Our multi-agent approach transforms a single LLM into a highly collaborative intelligence through multi-turn self-collaboration with diverse personas. By leveraging their combined expertise, this approach enhances the accuracy of code vulnerability detection and improves inference capabilities. To effectively utilize few-shot learning samples, we employ intra-references to extract a small number of similar samples from the training data, and inter-references to obtain samples from external data. The experimental studies are conducted on the TreeVul_Ext dataset, and our model achieves promising results across different evaluation criteria. Furthermore, we apply our model to detect code vulnerabilities in low-resource languages and exhibit competitive performance as well.