Sangjun Chae

dblp:420/7883 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
1since 2021 · last 2025
0009-0008-3997-8969ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%
Software engineering, system software, and programming languages
1 paper
Program synthesis and code generation · 100%

Topics — the 2 heaviest of 2, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › secure software development
secure code generation
0.912025
Poster: Insecure Coding Habits Die Hard. Can PEFT Really Turn LLMs into Secure Coders? · CCS 2025
Program synthesis and code generation
code generation with language models
0.912025
Poster: Insecure Coding Habits Die Hard. Can PEFT Really Turn LLMs into Secure Coders? · CCS 2025

Methods — techniques the papers use, named apart from their topics

prompt tuning · 1.7prefix tuning · 1.7parameter-efficient fine-tuning · 1.7
YearPublicationVenuePosition
2025 Poster: Insecure Coding Habits Die Hard. Can PEFT Really Turn LLMs into Secure Coders?
abstract
Large language models (LLMs) have advanced automated code generation but often produce code with critical security flaws, including buffer overflows, memory leaks, and unsafe file handling.While prior work emphasizes post-hoc vulnerability detection, we introduce a framework for secure-by-construction code generation via parameter-efficient fine-tuning (PEFT).We construct a secure training dataset by automatically fixing 7 high-impact vulnerability types in 37,540 C code samples from CodeNet, achieving 95.36% CWE reduction.We then apply prompt and prefix tuning to four open-source models (CodeGen-16B/6B-multi and StarCoder2-7B/3B), updating fewer than 1% of the parameters.On the LLMSe-cEval benchmark, our approach increases secure code generations from 20 to 36 for StarCoder2-3B and from 10 to 27 for CodeGen-6B.These results demonstrate that PEFT can substantially improve code security without full model retraining.
Sangjun Chae, Jangseop Choi, Taeyang Kim, Eun Jung, Sanghak Oh, Hyoungshick Kim
CCS1