martynattakit/CodeSentinel-CWE_Classification
1
1---2title: CodeSentinel3emoji: ๐ก๏ธ4colorFrom: green5colorTo: gray6sdk: docker7app_port: 78608pinned: false9---10 11# CodeSentinel12 13Vulnerability classification tool combining fine-tuned ML models with MITRE framework coverage.14 15Paste a **code snippet**, **CVE description**, or **bug report** โ CodeSentinel identifies the vulnerability type, severity, and (for AI/ML inputs) the relevant ATLAS attack technique.16 17## What it does18 19- **Code input** โ Qwen2.5-Coder 7B analyzes the code โ RoBERTa classifies the CWE20- **Text input** โ RoBERTa classifies directly from the description21- **AI/ML input** โ ATLAS pattern matcher identifies the relevant attack technique22 23## Models24 25| Model | Purpose | Accuracy |26|-------|---------|----------|27| [`martynattakit/vuln-classifier-roberta`](https://huggingface.co/martynattakit/vuln-classifier-roberta) | CWE classification from text | Macro F1: 0.850 |28| [`martynattakit/vuln-analyzer-qwen-lora`](https://huggingface.co/martynattakit/vuln-analyzer-qwen-lora) | Code โ vulnerability description | Eval loss: โ |29 30## Coverage31 32**CWE Top 25** (MITRE 2024):33CWE-787, CWE-79, CWE-89, CWE-416, CWE-78, CWE-20, CWE-125, CWE-22, CWE-352, CWE-434, CWE-862, CWE-476, CWE-287, CWE-190, CWE-502, CWE-77, CWE-119, CWE-798, CWE-918, CWE-306, CWE-362, CWE-269, CWE-94, CWE-863, CWE-27634 35**MITRE ATLAS** (25 techniques):36Prompt injection, data poisoning, model extraction, membership inference, adversarial examples, jailbreaking, and more.37 38## Known limitations39 40- **CWE-77**: 0 F1 โ insufficient training samples. Predictions for this class are unreliable.41- **CWE-863**: F1 0.60 โ semantic overlap with CWE-862 makes these hard to distinguish.42- **ATLAS matching** uses keyword signals + retrieval, not a fine-tuned classifier. Confidence scores reflect signal overlap, not ground-truth accuracy. No labeled ATLAS dataset exists yet.43- **Code analysis** training data is primarily C/C++ (BigVul). Python/JS/Go descriptions may be less precise.44 45## Stack46 47```48RoBERTa-base fine-tuned on 165k CVEโCWE pairs (xamxte/cve-to-cwe)49Qwen2.5-Coder-7B QLoRA fine-tuned on BigVul (1,596 samples)50ATLAS matcher keyword RAG over 25 hand-crafted MITRE case studies51FastAPI REST API backend52```53 54## Local development55 56```bash57pip install -r requirements.txt58python app.py59# โ http://localhost:786060```61 62## Project structure63 64```65pipeline/66 classifier.py RoBERTa inference wrapper67 code_analyzer.py Qwen inference wrapper 68 atlas_matcher.py ATLAS pattern matcher69 router.py Input routing + output card70api/71 main.py FastAPI endpoints72frontend/73 index.html Web UI74data/75 atlas_cases.json 25 MITRE ATLAS techniques (hand-crafted)76notebooks/77 01_roberta_finetune.ipynb78 02_qwen_qlora.ipynb79```80 81## Links82- [Try the application here!](https://huggingface.co/spaces/martynattakit/CodeSentinel-CWE_Classification)83- [Medium Blog](https://medium.com/@martyxc2018/codesentinel-ai-cwe-classification-a3ed88f2be28)84 85## Acknowledgements86 87- **My mentor and TA from AI Builders 2025**88 For making this project possible by giving me guidances, feedbacks throughout the development of this project.89 