Extracting Recurring Vulnerabilities from Black-Box LLM-Generated Software

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Kordonsky, Tomer, Yamin, Maayan, Benzimra, Noam, LeVi, Amit, Mendelson, Avi
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918377452208128
author Kordonsky, Tomer
Yamin, Maayan
Benzimra, Noam
LeVi, Amit
Mendelson, Avi
author_facet Kordonsky, Tomer
Yamin, Maayan
Benzimra, Noam
LeVi, Amit
Mendelson, Avi
contents LLMs are increasingly used for code generation, but their outputs often follow recurring templates that can induce predictable vulnerabilities. We study vulnerability persistence in LLM-generated software and introduce Feature--Security Table (FSTab) with two components. First, FSTab enables a black-box attack that predicts likely backend vulnerabilities from observable frontend features and knowledge of the source LLM, without access to the backend or source code. Second, FSTab provides a model-centric evaluation that quantifies how consistently a model reproduces the same vulnerabilities across programs, semantics-preserving rephrasings, and application domains. We evaluate FSTab on state-of-the-art code LLMs, including GPT-5.2, Claude-4.5 Opus, and Gemini-3 Pro, across diverse application domains. Our results show strong cross-domain transfer: even when the target domain is excluded from training, FSTab achieves up to 94% attack success and 93% vulnerability coverage on Internal Tools (Claude-4.5 Opus). These findings expose an underexplored attack surface in LLM-generated software and highlight the security risks of code generation. Our code is available at https://github.com/fstabicml2026/FSTab
format Preprint
id arxiv_https___arxiv_org_abs_2602_04894
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Extracting Recurring Vulnerabilities from Black-Box LLM-Generated Software
Kordonsky, Tomer
Yamin, Maayan
Benzimra, Noam
LeVi, Amit
Mendelson, Avi
Cryptography and Security
Artificial Intelligence
LLMs are increasingly used for code generation, but their outputs often follow recurring templates that can induce predictable vulnerabilities. We study vulnerability persistence in LLM-generated software and introduce Feature--Security Table (FSTab) with two components. First, FSTab enables a black-box attack that predicts likely backend vulnerabilities from observable frontend features and knowledge of the source LLM, without access to the backend or source code. Second, FSTab provides a model-centric evaluation that quantifies how consistently a model reproduces the same vulnerabilities across programs, semantics-preserving rephrasings, and application domains. We evaluate FSTab on state-of-the-art code LLMs, including GPT-5.2, Claude-4.5 Opus, and Gemini-3 Pro, across diverse application domains. Our results show strong cross-domain transfer: even when the target domain is excluded from training, FSTab achieves up to 94% attack success and 93% vulnerability coverage on Internal Tools (Claude-4.5 Opus). These findings expose an underexplored attack surface in LLM-generated software and highlight the security risks of code generation. Our code is available at https://github.com/fstabicml2026/FSTab
title Extracting Recurring Vulnerabilities from Black-Box LLM-Generated Software
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2602.04894