Team Ai
Apppublic

kid25/code-security-analyzer

sourceHugging Faceapache-2.0updated 4mo agoView on Hugging Face
0likes
App README

๐Ÿ”’ Code Security Risk Analyzer v2

AI-powered multi-label vulnerability detection across 30 CWE categories mapped to OWASP Top 10 2021. Supports Python, JavaScript, Java, C, C++, PHP, and Go.

v2 Improvements

  • โ€”Per-class threshold optimization โ€” each CWE has its own optimal detection threshold (not global 0.3)
  • โ€”Temperature-calibrated probabilities โ€” confidence scores are meaningful (0.8 โ‰ˆ 80% true positive rate)
  • โ€”CWE-aware fix generation โ€” fixer model knows what vulnerability to fix
  • โ€”3.7x larger fixer model โ€” CodeT5+ 220M (was flan-t5-small 60M)
  • โ€”Asymmetric Loss training โ€” handles 90% safe class imbalance

Model Performance

ModelMetricScore
Classifier (GraphCodeBERT 125M)Macro F10.476 (+311% vs baseline)
Weighted F10.945
Safe Detection F10.982
Fixer (CodeT5+ 220M)BLEU81.0
ROUGE-L0.788
Eval Loss0.175 (3.1x better than v1)

Features

  • โ€”Detection Model: GraphCodeBERT classifier โ€” 125M params, two-phase training with ASL loss
  • โ€”Fix Generator: CodeT5+ 220M โ€” CWE-aware input format, beam search generation
  • โ€”Structured Reports: CWE ID, OWASP category, severity score, exploit likelihood, plain English explanation
  • โ€”Attack Chain Analysis: Multi-vulnerability chaining analysis
  • โ€”REST API: JSON endpoint for integration into CI/CD pipelines

API Usage

python
from gradio_client import Client

client = Client("ayshajavd/code-security-analyzer")

# Get markdown report
report = client.predict(code="your code here", api_name="/analyze")

# Get structured JSON report
json_report = client.predict(code="your code here", api_name="/get_json_report")

Models & Dataset

Training Notebooks

All training code: vuln-classifier-training-notebooks