Team Ai
Apppublic

Lahiru-LK/codebert-vulnerability-api

sourceHugging Faceupdated 10mo agoView on Hugging Face
0likes
App README

CodeBERT Vulnerability Detection API

FastAPI-based code vulnerability detection using CodeBERT model trained for identifying SQL Injection and Certificate Validation vulnerabilities.

๐Ÿš€ API Endpoints

  • โ€”GET / - API information
  • โ€”GET /health - Health check status
  • โ€”GET /docs - Interactive API documentation (Swagger UI)
  • โ€”POST /detect - Detect vulnerabilities in code

๐Ÿ“ Example Usage

Python

python
import requests

url = "https://your-username-codebert-vulnerability-api.hf.space/detect"

response = requests.post(url, json={
    "code": """
    String query = "SELECT * FROM users WHERE id = '" + userId + "'";
    Statement stmt = connection.createStatement();
    ResultSet rs = stmt.executeQuery(query);
    """,
    "max_length": 512
})

result = response.json()
print(f"Vulnerable: {result['is_vulnerable']}")
print(f"Type: {result['vulnerability_type']}")
print(f"Confidence: {result['confidence']:.2%}")

cURL

bash
curl -X POST "https://your-username-codebert-vulnerability-api.hf.space/detect" \
  -H "Content-Type: application/json" \
  -d '{
    "code": "SELECT * FROM users WHERE id = " + user_input,
    "max_length": 512
  }'

๐Ÿ” Response Format

json
{
  "vulnerability_type": "SQL Injection",
  "confidence": 0.95,
  "is_vulnerable": true,
  "label": "s0"
}

๐Ÿท๏ธ Vulnerability Labels

  • โ€”s0 / s1 - SQL Injection vulnerabilities
  • โ€”v0 / v1 - Certificate Validation vulnerabilities

๐Ÿง  Model Details

  • โ€”Base Model: microsoft/codebert-base
  • โ€”Architecture: RoBERTa with custom classification head
  • โ€”Model Size: 487 MB
  • โ€”Task: Binary classification for vulnerability detection
  • โ€”Categories: SQL Injection, Certificate Validation

โšก Performance

The model uses CPU inference on Hugging Face Spaces free tier. For faster inference, consider upgrading to GPU hardware.

๐Ÿ“„ License

Apache 2.0