OpenSSF Finding and Fixing Vulnerabilities Using AI

2.2 Strengths and weaknesses

Most current AI systems build on LLMs or similar technologies, so they inherit the strengths and weaknesses of those technologies. Their strengths are what make this material possible: they can read and reason about large amounts of code quickly, use tools, and work tirelessly and in parallel. As a result, they can find many vulnerabilities humans and other tools have missed.

However, they also have key weaknesses that impact finding and fixing software vulnerabilities:

Quiz

Q1. Why does the material describe an LLM as “unsound”?

  1. It always produces code that fails to compile
  2. It requires more memory than any traditional static analysis tool, causing crashes if there’s insufficient memory
  3. It can’t guarantee a program is free of some vulnerability just because it found none
  4. It can only process one source file per session
Show answer Answer: C
Quiz

Q1. Why does an LLM’s limited context window matter when analyzing a large codebase?

  1. It restricts how much input the LLM can effectively focus on, with attention favoring the beginning and end of that input
  2. It prevents the LLM from ever being trained on security-related data
  3. It means the LLM can analyze only one programming language per session, since it must load each language’s definitions into its context window
  4. It forces the LLM to run exclusively on local infrastructure
Show answer Answer: A