Uppsats
Enhancing Software Security with AI: Detecting Vulnerabilities in High-Level Programming Languages
Master-uppsats
Lunds universitet/Institutionen för elektro- och informationsteknik
Publicerad: 2024
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
With the rapid growth of software dependencies in critical systems, detecting vulnerabilities early in the development cycle has become a necessity. While extensive research exists on vulnerability detection in low-level languages like C/C++, there is a significant gap in addressing vulnerabilities in higher-level languages, including JavaScript, Python, and PHP. This thesis explores the feasibility of using fine-tuned large language models (LLMs) to detect vulnerabilities in these higher level languages, leveraging data-driven approaches to bridge the existing research gap. In this thesis we work with fine-tuning LLMs on a curated dataset derived from CVEFixes, implementing the model in an API format to facilitate integration into CI/CD pipelines. Key performance metrics, including accuracy, precision, and F1 score, reveal that the model achieved varying effectiveness across different languages, with strong results in JavaScript and Java but weaker results in PHP, highlighting the nuanced challenges of vulnerability detection in diverse programming contexts. To demonstrate real-world applicability, the models proposed in this thesis were deployed through a user-friendly web interface, with API accessibility allowing seamless integration for developers. In our discussion, we address the ethical and security implications of using AIdriven vulnerability detection, including potential misuse by malicious actors and over-reliance on automated findings. The findings suggest that while LLMs are promising for certain languages, further refinement is needed to improve accuracy and reliability across diverse high-level languages. Future work should explore hybrid models that combine traditional and AI-based detection to mitigate current limitations and enhance practical use in software security, and CWE-specific training for higher-level languages.
Information
- Författare
- Dahlén, Kevin
- Lärosäte / institution
- Lunds universitet/Institutionen för elektro- och informationsteknik
- Publiceringsdatum
- 2024
- Uppsatstyp
- Master-uppsats
- Språk
- Engelska
- Nyckelord
- ⌕Technology and Engineering
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Weidemann, Eivind Aksel
Publicerad: 2026
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Li, Hongyan
Publicerad: 2026
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Du, Mingtong
Publicerad: 2026
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Müller, Arvid, Flynn Rosenberg, Elias
Publicerad: 2026
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Ekstrand, Julius, Truong, Victor
Publicerad: 2026
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Fu, Zhongwang
Publicerad: 2026