Exploring AI for Vulnerability Detection and Repair
Onyeka Ezenwoye, Eduard Pinconschi, Earl Roberts · 2024
As modern applications become more complex, enhancing tools and techniques for detecting and addressing vulnerabilities is crucial. AI and ML are increasingly valuable in this domain. Large Language Models like ChatGPT, Gemini, and Phind are emerging as promising solutions for code analysis and repair. This study evaluates these models’ effectiveness in identifying and fixing vulnerabilities in small C-language code samples, focusing on various CWE categories. The evaluation reveals that while ChatGPT performs with the highest accuracy in detecting vulnerabilities, all models effectively repair known flaws, though with varying proficiency. The findings aim to provide insights for improving automated vulnerability detection and remediation tools in cybersecurity.