From Model to Breach: Towards Actionable LLM-Generated Vulnerabilities Reporting
This paper addresses the insufficient risk assessment of security vulnerabilities introduced by LLM-based programming assistants. We propose the first risk-aware evaluation framework integrating vulnerability severity, generation probability, and prompt exposure (PE)—a novel metric quantifying the susceptibility of vulnerabilities to adversarial prompting. We further introduce model exposure (ME) to measure vulnerability prevalence across models. Empirical analysis reveals that even for long-disclosed vulnerabilities, mainstream open-source code-generation models remain significantly susceptible, confirming a fundamental trade-off between security and functionality. Our contributions are threefold: (1) formal definition and empirical validation of the PE/ME dual-metric framework; (2) establishment of an actionable vulnerability prioritization mechanism grounded in quantitative risk estimation; and (3) identification of critical limitations in current security hardening techniques under realistic prompt distributions—thereby providing both theoretical foundations and practical guidance for targeted remediation of high-risk vulnerabilities.