Oct 2026· Zenodo (CERN European Organization for Nuclear Research)
Advanced Malware Detection Techniques
Abstract
Small code language models are now easy to run on a developer's own laptop, and one thing people ask them to do is a quick security pass over code before it ships. I wanted to know how far that trust holds for one narrow but dangerous flaw family, cryptographic API misuse. I built CryptoBench, a set of thirty-six vulnerable snippets spread across nine misuse classes, plus eighteen secure counterparts, two per class, so a model earns nothing by calling everything unsafe, and I ran it against seven open code models from 0.5B to 14B parameters. Detection turned out to be strongly class dependent. Pooled over the three models that separate safe from unsafe code, MD5 or SHA-1 misuse was flagged 82% of the time against a 3% false-positive rate on its secure controls, and ECB mode 90% against 33%. The controls also cut the other way. Disabled TLS verification was flagged 97% of the time, yet correctly verified TLS code was flagged 87% of the time, and hardcoded keys (58%) were flagged less often than keys read from the environment (63%), so neither class shows real discrimination. The models miss misuse that hides inside ordinary use of a general-purpose API. The clearest case is a weak random number generator standing in for a cryptographic one, caught 38% of the time with no false alarms, and going from a 7B to a 14B model raised that from 6 to 11 of 20, a difference that is not statistically significant. Two of the highest raw scores in my set came from models that label almost everything vulnerable, which a matched secure control exposes at once. I release the benchmark and the full per-trial results.
Supporting data, adapters, predictions and code for the article *Low-Cost LoRA Fine-Tuning of Small Language Models for Multi-Step Arithmetic Reasoning* by Jake O'Grady, Asena Isik Gürhan, Chee Fong Ting and Effirul Ramlan (University of Galway). We generated 20,000 GSM8K-derived arithmetic problems with step-by-step s...
O'Grady, Jake, Gürhan, Asena Isik, Chee, Fong Ting et al.· Zenodo (CERN European Organi...· 465 citations
The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.
Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al.· IEEE Transactions on Softwar...· 178 citations· ⚡14
Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.
M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al.· e-Informatica Software Engin...· 157 citations· ⚡17
This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.
Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al.· Empirical Software Engineeri...· 127 citations· ⚡15
The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.
Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al.· Journal of Systems and Softw...· 111 citations· ⚡8
This study investigates how Lean internal startup facilitates software product innovation in large companies and identifies its enablers and inhibitors, and shows the potential of the method-in-action framework to investigate the Lean startup approach in non-startup context.
Henry Edison, Nina M. Smørsgård, Xiaofeng Wang et al.· Journal of Systems and Softw...· 78 citations· ⚡6