Clint Gibler’s Post

View profile for Clint Gibler

Sharing the latest cybersecurity research at tldrsec.com | Head of Security Research at Semgrep

📖 LLM4Vuln: How good are LLMs at reasoning about vulnerabilities? 9 zero-days in smart contracts, and how much function calling, prompting, knowledge retrieval, etc. matter. The paper aims to decouple LLMs' vulnerability reasoning capability from their other capabilities (e.g. seeking additional info via function calling, retrieving vulnerability knowledge like via RAG, etc.). and proposes a unified evaluation framework named LLM4Vuln. They had GPT-4, Mixtral, and Code Llama analyze 75 ground-truth smart contract vulnerabilities as well as 4,950 different scenarios, and identified 9 zero-day vulnerabilities in two pilot bug bounty programs, earning >$1,000. The paper also examines the varying effects of knowledge enhancement, context supplementation, prompt schemes, and models. #cybersecurity #security #ai CC Caleb Sima, Daniel Miessler, Jason Haddix, Chris Hughes

Clint Gibler

Sharing the latest cybersecurity research at tldrsec.com | Head of Security Research at Semgrep

7mo
Marcel Velica

Senior Security Program Manager | Leading Cybersecurity Initiatives | Driving Strategic Security Solutions | Cybersecurity Excellence | Cloud Security

7mo

 As AI continues to integrate into cybersecurity, understanding the strengths and limitations of these models is crucial.  Clint Gibler

See more comments

To view or add a comment, sign in

Explore topics