Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Zhao, Jian, Wang, Shenao, Zhao, Yanjie, Hou, Xinyi, Wang, Kailong, Gao, Peiming, Zhang, Yuanchao, Wei, Chen, Wang, Haoyu |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2024
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
von: Zheng, Xinyi, et al.
Veröffentlicht: (2024)
von: Zheng, Xinyi, et al.
Veröffentlicht: (2024)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
von: Wang, Shenao, et al.
Veröffentlicht: (2026)
von: Wang, Shenao, et al.
Veröffentlicht: (2026)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
von: Liu, Yue, et al.
Veröffentlicht: (2025)
von: Liu, Yue, et al.
Veröffentlicht: (2025)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
von: Hou, Xinyi, et al.
Veröffentlicht: (2025)
von: Hou, Xinyi, et al.
Veröffentlicht: (2025)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
von: Nie, Yuqing, et al.
Veröffentlicht: (2024)
von: Nie, Yuqing, et al.
Veröffentlicht: (2024)
Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study
von: Hou, Xinyi, et al.
Veröffentlicht: (2025)
von: Hou, Xinyi, et al.
Veröffentlicht: (2025)
How Agentic AI Coding Assistants Become the Attacker's Shell
von: Liu, Yue, et al.
Veröffentlicht: (2026)
von: Liu, Yue, et al.
Veröffentlicht: (2026)
MiniScope: Automated UI Exploration and Privacy Inconsistency Detection of MiniApps via Two-phase Iterative Hybrid Analysis
von: Wang, Shenao, et al.
Veröffentlicht: (2024)
von: Wang, Shenao, et al.
Veröffentlicht: (2024)
Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
von: Wang, Shenao, et al.
Veröffentlicht: (2026)
von: Wang, Shenao, et al.
Veröffentlicht: (2026)
Detecting Data Poisoning in Code Generation LLMs via Black-Box, Vulnerability-Oriented Scanning
von: Yan, Shenao, et al.
Veröffentlicht: (2026)
von: Yan, Shenao, et al.
Veröffentlicht: (2026)
CKGFuzzer: LLM-Based Fuzz Driver Generation Enhanced By Code Knowledge Graph
von: Xu, Hanxiang, et al.
Veröffentlicht: (2024)
von: Xu, Hanxiang, et al.
Veröffentlicht: (2024)
Detecting Stealthy Data Poisoning Attacks in AI Code Generators
von: Improta, Cristina
Veröffentlicht: (2025)
von: Improta, Cristina
Veröffentlicht: (2025)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
von: Huang, Youwei, et al.
Veröffentlicht: (2025)
von: Huang, Youwei, et al.
Veröffentlicht: (2025)
StagedVulBERT: Multi-Granular Vulnerability Detection with a Novel Pre-trained Code Model
von: Jiang, Yuan, et al.
Veröffentlicht: (2024)
von: Jiang, Yuan, et al.
Veröffentlicht: (2024)
SMCP: Secure Model Context Protocol
von: Hou, Xinyi, et al.
Veröffentlicht: (2026)
von: Hou, Xinyi, et al.
Veröffentlicht: (2026)
YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group
von: Wang, Yayi, et al.
Veröffentlicht: (2026)
von: Wang, Yayi, et al.
Veröffentlicht: (2026)
An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection
von: Yan, Shenao, et al.
Veröffentlicht: (2024)
von: Yan, Shenao, et al.
Veröffentlicht: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
von: Liu, Bin, et al.
Veröffentlicht: (2025)
von: Liu, Bin, et al.
Veröffentlicht: (2025)
Gotcha! This Model Uses My Code! Evaluating Membership Leakage Risks in Code Models
von: Yang, Zhou, et al.
Veröffentlicht: (2023)
von: Yang, Zhou, et al.
Veröffentlicht: (2023)
SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain
von: Wang, Shenao, et al.
Veröffentlicht: (2025)
von: Wang, Shenao, et al.
Veröffentlicht: (2025)
Seeing is (Not) Believing: Practical Phishing Attacks Targeting Social Media Sharing Cards
von: Huang, Wangchenlu, et al.
Veröffentlicht: (2024)
von: Huang, Wangchenlu, et al.
Veröffentlicht: (2024)
MalModel: Hiding Malicious Payload in Mobile Deep Learning Models with Black-box Backdoor Attack
von: Hua, Jiayi, et al.
Veröffentlicht: (2024)
von: Hua, Jiayi, et al.
Veröffentlicht: (2024)
Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation
von: Lin, Bo, et al.
Veröffentlicht: (2025)
von: Lin, Bo, et al.
Veröffentlicht: (2025)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
von: Ning, Kaiwen, et al.
Veröffentlicht: (2024)
von: Ning, Kaiwen, et al.
Veröffentlicht: (2024)
Train in Vain: Functionality-Preserving Poisoning to Prevent Unauthorized Use of Code Datasets
von: Xiao, Yuan, et al.
Veröffentlicht: (2026)
von: Xiao, Yuan, et al.
Veröffentlicht: (2026)
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
von: Asare, Owura, et al.
Veröffentlicht: (2022)
von: Asare, Owura, et al.
Veröffentlicht: (2022)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
von: Masud, Md Rayhanul, et al.
Veröffentlicht: (2024)
von: Masud, Md Rayhanul, et al.
Veröffentlicht: (2024)
KVerus: Scalable and Resilient Formal Verification Proof Generation for Rust Code
von: Liu, Yuwei, et al.
Veröffentlicht: (2026)
von: Liu, Yuwei, et al.
Veröffentlicht: (2026)
Demonstration Attack against In-Context Learning for Code Intelligence
von: Ge, Yifei, et al.
Veröffentlicht: (2024)
von: Ge, Yifei, et al.
Veröffentlicht: (2024)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
von: Zhang, Junan, et al.
Veröffentlicht: (2023)
von: Zhang, Junan, et al.
Veröffentlicht: (2023)
MALSIGHT: Exploring Malicious Source Code and Benign Pseudocode for Iterative Binary Malware Summarization
von: Lu, Haolang, et al.
Veröffentlicht: (2024)
von: Lu, Haolang, et al.
Veröffentlicht: (2024)
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
von: Štorek, Adam, et al.
Veröffentlicht: (2025)
von: Štorek, Adam, et al.
Veröffentlicht: (2025)
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
von: Fu, Yujia, et al.
Veröffentlicht: (2023)
von: Fu, Yujia, et al.
Veröffentlicht: (2023)
Transferable Backdoor Attacks for Code Models via Sharpness-Aware Adversarial Perturbation
von: Chang, Shuyu, et al.
Veröffentlicht: (2026)
von: Chang, Shuyu, et al.
Veröffentlicht: (2026)
On the (In)Security of LLM App Stores
von: Hou, Xinyi, et al.
Veröffentlicht: (2024)
von: Hou, Xinyi, et al.
Veröffentlicht: (2024)
RealSec-bench: A Benchmark for Evaluating Secure Code Generation in Real-World Repositories
von: Wang, Yanlin, et al.
Veröffentlicht: (2026)
von: Wang, Yanlin, et al.
Veröffentlicht: (2026)
Large Language Models for Cyber Security: A Systematic Literature Review
von: Xu, Hanxiang, et al.
Veröffentlicht: (2024)
von: Xu, Hanxiang, et al.
Veröffentlicht: (2024)
Defending Code Language Models against Backdoor Attacks with Deceptive Cross-Entropy Loss
von: Yang, Guang, et al.
Veröffentlicht: (2024)
von: Yang, Guang, et al.
Veröffentlicht: (2024)
Poisoning Programs by Un-Repairing Code: Security Concerns of AI-generated Code
von: Improta, Cristina
Veröffentlicht: (2024)
von: Improta, Cristina
Veröffentlicht: (2024)
Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app Ecosystems
von: Zhang, Miao, et al.
Veröffentlicht: (2025)
von: Zhang, Miao, et al.
Veröffentlicht: (2025)
Ähnliche Einträge
-
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
von: Zheng, Xinyi, et al.
Veröffentlicht: (2024) -
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
von: Wang, Shenao, et al.
Veröffentlicht: (2026) -
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
von: Liu, Yue, et al.
Veröffentlicht: (2025) -
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
von: Hou, Xinyi, et al.
Veröffentlicht: (2025) -
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
von: Nie, Yuqing, et al.
Veröffentlicht: (2024)