Khiem Ton

dblp:387/3902 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
1since 2021 · last 2024
0009-0000-7581-5413ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program synthesis and code generation · 100%
Network and information security
1 paper
Systems and software security · 77% Blockchain and cryptocurrency security · 23%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › secure software development
secure code generation
0.812024
Demo: SGCode: A Flexible Prompt-Optimizing System for Secure Generation of Code · CCS 2024
Program synthesis and code generation
code generation with language models
0.812024
Demo: SGCode: A Flexible Prompt-Optimizing System for Secure Generation of Code · CCS 2024
Program synthesis and code generation › code generation with language models
secure code generation
0.812024
Demo: SGCode: A Flexible Prompt-Optimizing System for Secure Generation of Code · CCS 2024
Blockchain and cryptocurrency security › smart contract security
vulnerability detection
0.212024
Demo: SGCode: A Flexible Prompt-Optimizing System for Secure Generation of Code · CCS 2024

Methods — techniques the papers use, named apart from their topics

prompt optimization · 1.5large language model · 1.5generative adversarial graph neural network · 1.5
YearPublicationVenuePosition
2024 Demo: SGCode: A Flexible Prompt-Optimizing System for Secure Generation of Code
abstract
This paper introduces SGCode, a flexible prompt-optimizing system to generate secure code with large language models (LLMs). SGCode integrates recent prompt-optimization approaches with LLMs in a unified system accessible through front-end and back-end APIs, enabling users to 1) generate secure code, which is free of vulnerabilities, 2) review and share security analysis, and 3) easily switch from one prompt optimization approach to another, while providing insights on model and system performance. We populated SGCode on an AWS server with PromSec, an approach that optimizes prompts by combining an LLM and security tools with a lightweight generative adversarial graph neural network to detect and fix security vulnerabilities in the generated code. Extensive experiments show that SGCode is practical as a public tool to gain insights into the trade-offs between model utility, secure code generation, and system cost. SGCode has only a marginal cost compared with prompting LLMs. SGCode is available at: http://3.131.141.63:8501/.
Khiem Ton, Nhi Nguyen, Mahmoud Nazzal, Abdallah Khreishah, Cristian Borcea, NhatHai Phan, Ruoming Jin, Issa M. Khalil, Yelong Shen
CCS1