Team Ai
Modelpublic

jacpacd/vuln-detector-codebert

sourceHugging Facemitupdated 1y agoView on Hugging Face
1likes33downloads
README.md83 linesDownload Raw Back to root
1---2license: mit3language:4- code5library_name: transformers6tags:7- text-classification8- code-classification9- vulnerability-detection10- automatic-vulnerability-detection11- secure-coding12---13 14# Vulnerability Detector for C Code (SARD)15 16This model is a fine-tuned version of `microsoft/codebert-base` designed to detect vulnerabilities in C source code functions. 17 18## Model Description19 20This is a binary text-classification model that takes a C function as input and classifies it as either **Vulnerable** (`LABEL_1`) or **Safe** (`LABEL_0`).21 22The model was specifically fine-tuned on the [NIST SARD (Software Assurance Reference Dataset)](https://samate.nist.gov/SARD/), focusing on common C vulnerabilities like Memory Leaks, Buffer Overflows, and other CWEs present in the Juliet Test Suite. Due to the clean and structured nature of the SARD dataset, the model achieved a very high accuracy on the validation set.23 24## Intended Uses & Limitations25 26This model is intended as a proof-of-concept tool to assist developers in identifying potentially vulnerable code patterns during the development lifecycle.27 28**Limitations:**29*   The model is highly specialized for the types of vulnerabilities found in the SARD dataset. Its performance on real-world, messy, or obfuscated code may be lower.30*   It should be used as an assistive tool, not as a replacement for comprehensive security audits or other static analysis tools.31*   The model classifies entire functions and may not pinpoint the exact line of code responsible for the vulnerability.32 33## How to Use34 35The model can be easily used with the `transformers` library `pipeline`.36 37```python38from transformers import pipeline39 40# Load the classifier pipeline41classifier = pipeline("text-classification", model="jacpacd/vuln-detector-codebert-c-sard")42 43# Example of a vulnerable C function (Memory Leak)44vulnerable_code = """45void CWE401_Memory_Leak__strdup_char_01_bad()46{47    char * data;48    data = NULL;49    {50        char myString[] = "myString";51        /* POTENTIAL FLAW: Allocate memory from the heap */52        data = strdup(myString);53        printLine(data);54    }55    /* POTENTIAL FLAW: No deallocation of memory */56    ;57}58"""59 60# Example of a safe C function61safe_code = """62void CWE401_Memory_Leak__strdup_char_01_goodB2G()63{64    char * data;65    data = NULL;66    {67        char myString[] = "myString";68        data = strdup(myString);69        printLine(data);70    }71    /* FIX: Deallocate memory */72    free(data);73}74"""75 76results_vuln = classifier(vulnerable_code)77results_safe = classifier(safe_code)78 79print(f"Vulnerable Code Prediction: {results_vuln[0]}")80# Expected output: {'label': 'LABEL_1', 'score': 0.99...}81 82print(f"Safe Code Prediction: {results_safe[0]}")83# Expected output: {'label': 'LABEL_0', 'score': 0.99...}