2602.01438v2 Feb 01, 2026 cs.CR

CIPHER: 응답의 하이브리드 평가를 통한 암호화 취약점 프로파일링

CIPHER: Cryptographic Insecurity Profiling via Hybrid Evaluation of Responses

Max Manolov
Max Manolov
Citations: 1
h-index: 1
Siddharth Shukla
Siddharth Shukla
Citations: 54
h-index: 3
Cheng-Ting Chou
Cheng-Ting Chou
Citations: 17
h-index: 2
Ryan Lagasse
Ryan Lagasse
Lockheed AI Center, Algoverse AI Research
Citations: 17
h-index: 2
Tony Gao
Tony Gao
Citations: 1
h-index: 1

대규모 언어 모델(LLM)은 개발자를 지원하는 데 점점 더 많이 사용되고 있지만, LLM의 암호화 기능 구현에는 종종 악용 가능한 결함이 포함되어 있습니다. 사소한 설계 선택(예: 정적 초기화 벡터 또는 인증 누락)은 보안 보장을 눈에 띄지 않게 무효화할 수 있습니다. 본 논문에서는 CIPHER(Cryptographic Insecurity Profiling via Hybrid Evaluation of Responses)를 소개합니다. CIPHER는 제어된 보안 지침 조건 하에서 LLM이 생성한 Python 코드의 암호화 취약점 발생률을 측정하는 벤치마크입니다. CIPHER는 각 작업에 대해 안전/중립/불안전 프롬프트 변형을 사용하고, 암호화 관련 특정 취약점 분류 체계를 사용하며, 자동화된 평가 파이프라인을 통해 라인 단위의 출처를 추적합니다. 다양한 LLM을 대상으로 실험한 결과, 명시적인 안전 프롬프트는 일부 특정 문제를 완화하는 데 도움이 되지만, 전반적인 암호화 취약점을 확실하게 제거하지는 못하는 것으로 나타났습니다. 벤치마크와 재현 가능한 평가 파이프라인은 출판 시 공개될 예정입니다.

Original Abstract

Large language models (LLMs) are increasingly used to assist developers with code, yet their implementations of cryptographic functionality often contain exploitable flaws. Minor design choices (e.g., static initialization vectors or missing authentication) can silently invalidate security guarantees. We introduce CIPHER(Cryptographic Insecurity Profiling via Hybrid Evaluation of Responses), a benchmark for measuring cryptographic vulnerability incidence in LLM-generated Python code under controlled security-guidance conditions. CIPHER uses insecure/neutral/secure prompt variants per task, a cryptography-specific vulnerability taxonomy, and line-level attribution via an automated scoring pipeline. Across a diverse set of widely used LLMs, we find that explicit secure prompting reduces some targeted issues but does not reliably eliminate cryptographic vulnerabilities overall. The benchmark and reproducible scoring pipeline will be publicly released upon publication.

1 Citations
0 Influential
1.5 Altmetric
8.5 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!