Secret Breach Detection in Source Code with Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Rahman, Md Nafiu, Ahmed, Sadif, Wahab, Zahin, Sohan, S M, Shahriyar, Rifat
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908469001453568
author Rahman, Md Nafiu
Ahmed, Sadif
Wahab, Zahin
Sohan, S M
Shahriyar, Rifat
author_facet Rahman, Md Nafiu
Ahmed, Sadif
Wahab, Zahin
Sohan, S M
Shahriyar, Rifat
contents Background: Leaking sensitive information - such as API keys, tokens, and credentials - in source code remains a persistent security threat. Traditional regex and entropy-based tools often generate high false positives due to limited contextual understanding. Aims: This work aims to enhance secret detection in source code using large language models (LLMs), reducing false positives while maintaining high recall. We also evaluate the feasibility of using fine-tuned, smaller models for local deployment. Method: We propose a hybrid approach combining regex-based candidate extraction with LLM-based classification. We evaluate pre-trained and fine-tuned variants of various Large Language Models on a benchmark dataset from 818 GitHub repositories. Various prompting strategies and efficient fine-tuning methods are employed for both binary and multiclass classification. Results: The fine-tuned LLaMA-3.1 8B model achieved an F1-score of 0.9852 in binary classification, outperforming regex-only baselines. For multiclass classification, Mistral-7B reached 0.982 accuracy. Fine-tuning significantly improved performance across all models. Conclusions: Fine-tuned LLMs offer an effective and scalable solution for secret detection, greatly reducing false positives. Open-source models provide a practical alternative to commercial APIs, enabling secure and cost-efficient deployment in development workflows.
format Preprint
id arxiv_https___arxiv_org_abs_2504_18784
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Secret Breach Detection in Source Code with Large Language Models
Rahman, Md Nafiu
Ahmed, Sadif
Wahab, Zahin
Sohan, S M
Shahriyar, Rifat
Software Engineering
Background: Leaking sensitive information - such as API keys, tokens, and credentials - in source code remains a persistent security threat. Traditional regex and entropy-based tools often generate high false positives due to limited contextual understanding. Aims: This work aims to enhance secret detection in source code using large language models (LLMs), reducing false positives while maintaining high recall. We also evaluate the feasibility of using fine-tuned, smaller models for local deployment. Method: We propose a hybrid approach combining regex-based candidate extraction with LLM-based classification. We evaluate pre-trained and fine-tuned variants of various Large Language Models on a benchmark dataset from 818 GitHub repositories. Various prompting strategies and efficient fine-tuning methods are employed for both binary and multiclass classification. Results: The fine-tuned LLaMA-3.1 8B model achieved an F1-score of 0.9852 in binary classification, outperforming regex-only baselines. For multiclass classification, Mistral-7B reached 0.982 accuracy. Fine-tuning significantly improved performance across all models. Conclusions: Fine-tuned LLMs offer an effective and scalable solution for secret detection, greatly reducing false positives. Open-source models provide a practical alternative to commercial APIs, enabling secure and cost-efficient deployment in development workflows.
title Secret Breach Detection in Source Code with Large Language Models
topic Software Engineering
url https://arxiv.org/abs/2504.18784