Team Ai
Apppublic

martynattakit/CodeSentinel-CWE_Classification

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes
README.md89 linesDownload Raw Back to root
1---2title: CodeSentinel3emoji: ๐Ÿ›ก๏ธ4colorFrom: green5colorTo: gray6sdk: docker7app_port: 78608pinned: false9---10 11# CodeSentinel12 13Vulnerability classification tool combining fine-tuned ML models with MITRE framework coverage.14 15Paste a **code snippet**, **CVE description**, or **bug report** โ€” CodeSentinel identifies the vulnerability type, severity, and (for AI/ML inputs) the relevant ATLAS attack technique.16 17## What it does18 19- **Code input** โ†’ Qwen2.5-Coder 7B analyzes the code โ†’ RoBERTa classifies the CWE20- **Text input** โ†’ RoBERTa classifies directly from the description21- **AI/ML input** โ†’ ATLAS pattern matcher identifies the relevant attack technique22 23## Models24 25| Model | Purpose | Accuracy |26|-------|---------|----------|27| [`martynattakit/vuln-classifier-roberta`](https://huggingface.co/martynattakit/vuln-classifier-roberta) | CWE classification from text | Macro F1: 0.850 |28| [`martynattakit/vuln-analyzer-qwen-lora`](https://huggingface.co/martynattakit/vuln-analyzer-qwen-lora) | Code โ†’ vulnerability description | Eval loss: โ€” |29 30## Coverage31 32**CWE Top 25** (MITRE 2024):33CWE-787, CWE-79, CWE-89, CWE-416, CWE-78, CWE-20, CWE-125, CWE-22, CWE-352, CWE-434, CWE-862, CWE-476, CWE-287, CWE-190, CWE-502, CWE-77, CWE-119, CWE-798, CWE-918, CWE-306, CWE-362, CWE-269, CWE-94, CWE-863, CWE-27634 35**MITRE ATLAS** (25 techniques):36Prompt injection, data poisoning, model extraction, membership inference, adversarial examples, jailbreaking, and more.37 38## Known limitations39 40- **CWE-77**: 0 F1 โ€” insufficient training samples. Predictions for this class are unreliable.41- **CWE-863**: F1 0.60 โ€” semantic overlap with CWE-862 makes these hard to distinguish.42- **ATLAS matching** uses keyword signals + retrieval, not a fine-tuned classifier. Confidence scores reflect signal overlap, not ground-truth accuracy. No labeled ATLAS dataset exists yet.43- **Code analysis** training data is primarily C/C++ (BigVul). Python/JS/Go descriptions may be less precise.44 45## Stack46 47```48RoBERTa-base        fine-tuned on 165k CVEโ†’CWE pairs (xamxte/cve-to-cwe)49Qwen2.5-Coder-7B    QLoRA fine-tuned on BigVul (1,596 samples)50ATLAS matcher       keyword RAG over 25 hand-crafted MITRE case studies51FastAPI             REST API backend52```53 54## Local development55 56```bash57pip install -r requirements.txt58python app.py59# โ†’ http://localhost:786060```61 62## Project structure63 64```65pipeline/66    classifier.py      RoBERTa inference wrapper67    code_analyzer.py   Qwen inference wrapper  68    atlas_matcher.py   ATLAS pattern matcher69    router.py          Input routing + output card70api/71    main.py            FastAPI endpoints72frontend/73    index.html         Web UI74data/75    atlas_cases.json   25 MITRE ATLAS techniques (hand-crafted)76notebooks/77    01_roberta_finetune.ipynb78    02_qwen_qlora.ipynb79```80 81## Links82- [Try the application here!](https://huggingface.co/spaces/martynattakit/CodeSentinel-CWE_Classification)83- [Medium Blog](https://medium.com/@martyxc2018/codesentinel-ai-cwe-classification-a3ed88f2be28)84 85## Acknowledgements86 87- **My mentor and TA from AI Builders 2025**88  For making this project possible by giving me guidances, feedbacks throughout the development of this project.89