TOSSS: a CVE-based Software Security Benchmark for Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Damie, Marc, Ertan, Murat Bilgehan, Essoussi, Domenico, Makhanu, Angela, Peter, Gaëtan, Wensveen, Roos
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914395063320576
author Damie, Marc
Ertan, Murat Bilgehan
Essoussi, Domenico
Makhanu, Angela
Peter, Gaëtan
Wensveen, Roos
author_facet Damie, Marc
Ertan, Murat Bilgehan
Essoussi, Domenico
Makhanu, Angela
Peter, Gaëtan
Wensveen, Roos
contents With their increasing capabilities, Large Language Models (LLMs) are now used across many industries. They have become useful tools for software engineers and support a wide range of development tasks. As LLMs are increasingly used in software development workflows, a critical question arises: are LLMs good at software security? At the same time, organizations worldwide invest heavily in cybersecurity to reduce exposure to disruptive attacks. The integration of LLMs into software engineering workflows may introduce new vulnerabilities and weaken existing security efforts. We introduce TOSSS (Two-Option Secure Snippet Selection), a benchmark that measures the ability of LLMs to choose between secure and vulnerable code snippets. Existing security benchmarks for LLMs cover only a limited range of vulnerabilities. In contrast, TOSSS relies on the CVE database and provides an extensible framework that can integrate newly disclosed vulnerabilities over time. Our benchmark gives each model a security score between 0 and 1 based on its behavior; a score of 1 indicates that the model always selects the secure snippet, while a score of 0 indicates that it always selects the vulnerable one. We evaluate 14 widely used open-source and closed-source models on C/C++ and Java code and observe scores ranging from 0.48 to 0.89. LLM providers already publish many benchmark scores for their models, and TOSSS could become a complementary security-focused score to include in these reports.
format Preprint
id arxiv_https___arxiv_org_abs_2603_10969
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle TOSSS: a CVE-based Software Security Benchmark for Large Language Models
Damie, Marc
Ertan, Murat Bilgehan
Essoussi, Domenico
Makhanu, Angela
Peter, Gaëtan
Wensveen, Roos
Machine Learning
Computation and Language
Cryptography and Security
Software Engineering
With their increasing capabilities, Large Language Models (LLMs) are now used across many industries. They have become useful tools for software engineers and support a wide range of development tasks. As LLMs are increasingly used in software development workflows, a critical question arises: are LLMs good at software security? At the same time, organizations worldwide invest heavily in cybersecurity to reduce exposure to disruptive attacks. The integration of LLMs into software engineering workflows may introduce new vulnerabilities and weaken existing security efforts. We introduce TOSSS (Two-Option Secure Snippet Selection), a benchmark that measures the ability of LLMs to choose between secure and vulnerable code snippets. Existing security benchmarks for LLMs cover only a limited range of vulnerabilities. In contrast, TOSSS relies on the CVE database and provides an extensible framework that can integrate newly disclosed vulnerabilities over time. Our benchmark gives each model a security score between 0 and 1 based on its behavior; a score of 1 indicates that the model always selects the secure snippet, while a score of 0 indicates that it always selects the vulnerable one. We evaluate 14 widely used open-source and closed-source models on C/C++ and Java code and observe scores ranging from 0.48 to 0.89. LLM providers already publish many benchmark scores for their models, and TOSSS could become a complementary security-focused score to include in these reports.
title TOSSS: a CVE-based Software Security Benchmark for Large Language Models
topic Machine Learning
Computation and Language
Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2603.10969