Skip to content

About RELATED_CWEs #4

@phandat128

Description

@phandat128

Hi teams, thank you for releasing such an excellent paper and repo, it helped me a lot.
I just have a small question about the RELATED_CWE in your dataset, where did it come from? It seems you are hardcoding it, both in train and test dataset. For example, CWE-20 always comes along with ["CWE-362", "CWE-415", "CWE-269"], this can make model instead of detecting the real vulnerabilities in code, it only focuses on the top 4 CWEs (if not provided, it will hallucinate) and also always return the main CWE in top 4 (because for each right CWE, the related CWEs are not changing, and each CWE in the related CWEs, in other side has another top 3 related ones?). Have you considered this case?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions