TOSSS: a CVE-based Software Security Benchmark for Large Language Models
arXiv cs.LG / 3/12/2026
📰 NewsIdeas & Deep AnalysisModels & Research
Key Points
- TOSSS (Two-Option Secure Snippet Selection) is proposed as a CVE-based benchmark to evaluate LLMs' ability to choose secure code snippets over vulnerable ones.
- The benchmark uses the CVE database and is designed to be extensible to incorporate newly disclosed vulnerabilities over time.
- It outputs a security score from 0 to 1, where 1 means the model always selects secure snippets and 0 means it always selects vulnerable ones.
- The study evaluates 14 open-source and closed-source models on C/C++ and Java, with scores ranging from 0.48 to 0.89.
- The authors suggest TOSSS could serve as a complementary security-focused metric in model benchmark reports.
Related Articles
How to Build an AI Team: The Solopreneur Playbook
Dev.to
CrewAI vs AutoGen vs LangGraph: Which Agent Framework to Use
Dev.to

14 Best Self-Hosted Claude Alternatives for AI and Coding in 2026
Dev.to
[P] Finetuned small LMs to VLM adapters locally and wrote a short article about it
Reddit r/MachineLearning
Experiment: How far can a 28M model go in business email generation?
Reddit r/LocalLLaMA