LLM vs. SAST: A Technical Analysis on Detecting Coding Bugs of GPT4-Advanced Data Analysis

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tehrani, Madjid G., Sultanow, Eldar, Buchanan, William J., Houmani, Mahkame, Fodja, Christel H. Djaha
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908412643639296
author Tehrani, Madjid G.
Sultanow, Eldar
Buchanan, William J.
Houmani, Mahkame
Fodja, Christel H. Djaha
author_facet Tehrani, Madjid G.
Sultanow, Eldar
Buchanan, William J.
Houmani, Mahkame
Fodja, Christel H. Djaha
contents With the rapid advancements in Natural Language Processing (NLP), large language models (LLMs) like GPT-4 have gained significant traction in diverse applications, including security vulnerability scanning. This paper investigates the efficacy of GPT-4 in identifying software vulnerabilities compared to traditional Static Application Security Testing (SAST) tools. Drawing from an array of security mistakes, our analysis underscores the potent capabilities of GPT-4 in LLM-enhanced vulnerability scanning. We unveiled that GPT-4 (Advanced Data Analysis) outperforms SAST by an accuracy of 94% in detecting 32 types of exploitable vulnerabilities. This study also addresses the potential security concerns surrounding LLMs, emphasising the imperative of security by design/default and other security best practices for AI.
format Preprint
id arxiv_https___arxiv_org_abs_2506_15212
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LLM vs. SAST: A Technical Analysis on Detecting Coding Bugs of GPT4-Advanced Data Analysis
Tehrani, Madjid G.
Sultanow, Eldar
Buchanan, William J.
Houmani, Mahkame
Fodja, Christel H. Djaha
Cryptography and Security
With the rapid advancements in Natural Language Processing (NLP), large language models (LLMs) like GPT-4 have gained significant traction in diverse applications, including security vulnerability scanning. This paper investigates the efficacy of GPT-4 in identifying software vulnerabilities compared to traditional Static Application Security Testing (SAST) tools. Drawing from an array of security mistakes, our analysis underscores the potent capabilities of GPT-4 in LLM-enhanced vulnerability scanning. We unveiled that GPT-4 (Advanced Data Analysis) outperforms SAST by an accuracy of 94% in detecting 32 types of exploitable vulnerabilities. This study also addresses the potential security concerns surrounding LLMs, emphasising the imperative of security by design/default and other security best practices for AI.
title LLM vs. SAST: A Technical Analysis on Detecting Coding Bugs of GPT4-Advanced Data Analysis
topic Cryptography and Security
url https://arxiv.org/abs/2506.15212