ニュース
Vulnerability Localization Benchmark: Measuring Agentic Security Analysis at Repository Scale
arXiv cs.AI · 公開日 · 読了3分
30秒で要点
- 何が起きたか
- Researchers released VLoc Bench, a benchmark with 500 real vulnerabilities across 290 repositories, measuring how well AI agents locate vulnerable code files given only CWE descriptions.
- なぜ重要か
- Security engineers and AI researchers evaluating agentic code analysis tools need this to understand current localization capabilities and limitations at repository scale.
- 注意点
- Best system achieved only 0.229 File F1 score; 38% of tasks received no correct localization from any model, indicating the task remains substantially unsolved.
- agent
- agentic
- eval
- benchmark
この話題の背景にあるパターン
各ページで、技術の仕組み、コストに見合う場面、そして破綻する条件を解説しています。
The Agent Architect
1つのパターン、1つのトレードオフ、1つの本番障害事例。エージェントシステムを構築する人のための短い週刊ブリーフィング。
週1回のメール、ワンクリックで購読解除できます。アドレスはブリーフィングの送信のみに使用します。