新闻
Vulnerability Localization Benchmark: Measuring Agentic Security Analysis at Repository Scale
arXiv cs.AI · 发布于 · 阅读约3分钟
30秒读懂
- 发生了什么
- Researchers released VLoc Bench, a benchmark with 500 real vulnerabilities across 290 repositories, measuring how well AI agents locate vulnerable code files given only CWE descriptions.
- 为何重要
- Security engineers and AI researchers evaluating agentic code analysis tools need this to understand current localization capabilities and limitations at repository scale.
- 注意
- Best system achieved only 0.229 File F1 score; 38% of tasks received no correct localization from any model, indicating the task remains substantially unsolved.
- agent
- agentic
- eval
- benchmark
这条新闻背后的模式
每个模式都讲清楚技术如何运作、何时值得投入,以及在哪里会失效。
The Agent Architect
每周一个模式、一个权衡、一个生产事故案例。为构建智能体系统的人准备的每周简报。
每周一封邮件,一键退订。您的地址仅用于发送简报。