CoTDeceptor:Adversarial Code Obfuscation Against CoT-Enhanced LLM Code Agents

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Li, Haoyang, Li, Mingjin, Zuo, Jinxin, Li, Siqi, Li, Xiao, Wu, Hao, Lu, Yueming, He, Xiaochuan
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909975475912704
author Li, Haoyang
Li, Mingjin
Zuo, Jinxin
Li, Siqi
Li, Xiao
Wu, Hao
Lu, Yueming
He, Xiaochuan
author_facet Li, Haoyang
Li, Mingjin
Zuo, Jinxin
Li, Siqi
Li, Xiao
Wu, Hao
Lu, Yueming
He, Xiaochuan
contents LLM-based code agents(e.g., ChatGPT Codex) are increasingly deployed as detector for code review and security auditing tasks. Although CoT-enhanced LLM vulnerability detectors are believed to provide improved robustness against obfuscated malicious code, we find that their reasoning chains and semantic abstraction processes exhibit exploitable systematic weaknesses.This allows attackers to covertly embed malicious logic, bypass code review, and propagate backdoored components throughout real-world software supply chains.To investigate this issue, we present CoTDeceptor, the first adversarial code obfuscation framework targeting CoT-enhanced LLM detectors. CoTDeceptor autonomously constructs evolving, hard-to-reverse multi-stage obfuscation strategy chains that effectively disrupt CoT-driven detection logic.We obtained malicious code provided by security enterprise, experimental results demonstrate that CoTDeceptor achieves stable and transferable evasion performance against state-of-the-art LLMs and vulnerability detection agents. CoTDeceptor bypasses 14 out of 15 vulnerability categories, compared to only 2 bypassed by prior methods. Our findings highlight potential risks in real-world software supply chains and underscore the need for more robust and interpretable LLM-powered security analysis systems.
format Preprint
id arxiv_https___arxiv_org_abs_2512_21250
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle CoTDeceptor:Adversarial Code Obfuscation Against CoT-Enhanced LLM Code Agents
Li, Haoyang
Li, Mingjin
Zuo, Jinxin
Li, Siqi
Li, Xiao
Wu, Hao
Lu, Yueming
He, Xiaochuan
Cryptography and Security
Multiagent Systems
LLM-based code agents(e.g., ChatGPT Codex) are increasingly deployed as detector for code review and security auditing tasks. Although CoT-enhanced LLM vulnerability detectors are believed to provide improved robustness against obfuscated malicious code, we find that their reasoning chains and semantic abstraction processes exhibit exploitable systematic weaknesses.This allows attackers to covertly embed malicious logic, bypass code review, and propagate backdoored components throughout real-world software supply chains.To investigate this issue, we present CoTDeceptor, the first adversarial code obfuscation framework targeting CoT-enhanced LLM detectors. CoTDeceptor autonomously constructs evolving, hard-to-reverse multi-stage obfuscation strategy chains that effectively disrupt CoT-driven detection logic.We obtained malicious code provided by security enterprise, experimental results demonstrate that CoTDeceptor achieves stable and transferable evasion performance against state-of-the-art LLMs and vulnerability detection agents. CoTDeceptor bypasses 14 out of 15 vulnerability categories, compared to only 2 bypassed by prior methods. Our findings highlight potential risks in real-world software supply chains and underscore the need for more robust and interpretable LLM-powered security analysis systems.
title CoTDeceptor:Adversarial Code Obfuscation Against CoT-Enhanced LLM Code Agents
topic Cryptography and Security
Multiagent Systems
url https://arxiv.org/abs/2512.21250