{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/an-llm-assisted-easy-to-trigger-backdoor","title":"An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection","arxiv_id":"2406.06822","date":"2024-06-10","proceeding":null,"authors":["Shenao Yan","Shen Wang","Yue Duan","Hanbin Hong","Kiho Lee","Doowon Kim","Yuan Hong"],"abstract":"Large Language Models (LLMs) have transformed code completion tasks, providing context-based suggestions to boost developer productivity in software engineering. As users often fine-tune these models for specific applications, poisoning and backdoor attacks can covertly alter the model outputs. To address this critical security challenge, we introduce CodeBreaker, a pioneering LLM-assisted backdoor attack framework on code completion models. Unlike recent attacks that embed malicious payloads in detectable or irrelevant sections of the code (e.g., comments), CodeBreaker leverages LLMs (e.g., GPT-4) for sophisticated payload transformation (without affecting functionalities), ensuring that both the poisoned data for fine-tuning and generated code can evade strong vulnerability detection. CodeBreaker stands out with its comprehensive coverage of vulnerabilities, making it the first to provide such an extensive set for evaluation. Our extensive experimental evaluations and user studies underline the strong attack performance of CodeBreaker across various settings, validating its superiority over existing approaches. By integrating malicious payloads directly into the source code with minimal transformation, CodeBreaker challenges current security measures, underscoring the critical need for more robust defenses for code completion.","url_abs":"https://arxiv.org/abs/2406.06822v1","url_pdf":"https://arxiv.org/pdf/2406.06822v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"an-llm-assisted-easy-to-trigger-backdoor","repo_url":"https://github.com/datasec-lab/codebreaker","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"jax","reach":null}],"tasks":[{"task_slug":"backdoor-attack","task_name":"Backdoor Attack"},{"task_slug":"code-completion","task_name":"Code Completion"},{"task_slug":"vulnerability-detection","task_name":"Vulnerability Detection"}],"methods":[{"method_slug":"set","method_name":"SET"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=2406.06822","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2406.06822"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/datasec-lab/codebreaker","reach":null}],"summary":{"ran_draft_wrong":3},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"58a861ed3065cdb3","entry":"cast","repo":"datasec-lab/codebreaker","repo_kind":"official","path":"CodeGen/codegen1/benchmark/mtpb_exec.py","file_url":"https://github.com/datasec-lab/codebreaker/blob/HEAD/CodeGen/codegen1/benchmark/mtpb_exec.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"58a861ed3065cdb3"}},{"code_sha256_prefix":"b196c82bf4ad6d4d","entry":"read_jsonl","repo":"datasec-lab/codebreaker","repo_kind":"official","path":"CodeGen/codegen1/benchmark/mtpb_exec.py","file_url":"https://github.com/datasec-lab/codebreaker/blob/HEAD/CodeGen/codegen1/benchmark/mtpb_exec.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"b196c82bf4ad6d4d"}},{"code_sha256_prefix":"364f0139371b1c4d","entry":"rewrite_ast_with_print","repo":"datasec-lab/codebreaker","repo_kind":"official","path":"CodeGen/codegen1/benchmark/mtpb_exec.py","file_url":"https://github.com/datasec-lab/codebreaker/blob/HEAD/CodeGen/codegen1/benchmark/mtpb_exec.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"364f0139371b1c4d"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}