Malicious Attack Challenges and Mitigation Strategies for Large Code Models: A Survey on Data Poisoning, Adversarial Attacks, and Backdoor Vulnerabilities

Dongqing Lin, Luwen Huangfu, Chunhua Liao, Brian Chung, Akul Gowda, Thomas Scott Brettin · Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences · 2026

The rapid proliferation of Large Code Models (LCMs), driven by Large Language Models (LLMs) advancements, has revolutionized automated code generation and completion. However, their widespread adoption introduces significant security risks like data poisoning, adversarial attacks, and backdoor vulnerabilities perspectives. This survey comprehensively reviews LCMs' security landscape with more than 200 recent papers to identify and categorize threats in code generation techniques, and summarizes five mainstream mitigation strategies: Model Hardening, Data Sanitization, Adversarial Training, Security Alignment, and Evaluation Datasets. Uniquely, this work applies Evolutionary Game Theory (EGT) to conceptualize LCMs' security as a continuous ``arms race" between attackers and defenders, where the effectiveness of specific strategies serves as a fitness indicator. Our analysis reveals that while defense techniques have advanced, balancing the robustness and functionality of LCMs remains a persistent challenge. Our findings underscore the need for standardized security benchmarks and real-time threat monitoring to ensure the safety of LCM-powered software.

Read the paper · More papers on PaperTik