arrow
返回

A Simple Adversarial Attack against Code Completion Engines Based on Large Language Models

delete2025-11-01
delete0
PRE
AI
D
Dapeng Zhao *
T
Tongcheng Geng
DOI:10.70003/160792642025112606004delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The large language model-driven code completion engines have demonstrated an significant capability to generate functionally correct code based on context. However, these code-completion engines risk being exploited through black-box attacks. We propose a simple yet practical Adversarial attack against Black-box Code Completion engines (ABCC). This novel attack method aims to steer code completion engines to generate vulnerable code. Consistent with most commercial completion engines, ABCC assumes only black-box query access to the target engine without needing knowledge of the engine's internal structure. Our attack is executed by inserting malicious attack strings as brief comments within the completion input. Firstly, we generate attack strings using large language models based on the expected malicious code. Then, using these attack strings, we guide the code completion engine to produce the desired malicious code. We validated our approach on the stateof-the-art black-box commercial service OpenAI API. In security-critical test cases covering 12 types of CWEs, ABCC significantly increased the likelihood of the targeted completion engine generating unsafe code, with an absolute increase exceeding with a success rate of 277.7%, which is significantly higher than the baseline model GPT-3.5-Turbo-Instruct when it completes code without using prompts.
Keyword:
Adversarial attack
Code completion
Large language models

期刊

J
Journal of Internet Technology
IF:
1.2
论文数:
81
被引数:
985

机构

M
ministry of public security (china)
学者数:
586
论文数: 486
被引数: 0
引用论文

引用论文

暂无论文信息