TOSSS: a CVE-based Software Security Benchmark for Large Language Models
arXiv cs.LG / 3/12/2026
📰 NewsIdeas & Deep AnalysisModels & Research
Key Points
- TOSSS (Two-Option Secure Snippet Selection) is proposed as a CVE-based benchmark to evaluate LLMs' ability to choose secure code snippets over vulnerable ones.
- The benchmark uses the CVE database and is designed to be extensible to incorporate newly disclosed vulnerabilities over time.
- It outputs a security score from 0 to 1, where 1 means the model always selects secure snippets and 0 means it always selects vulnerable ones.
- The study evaluates 14 open-source and closed-source models on C/C++ and Java, with scores ranging from 0.48 to 0.89.
- The authors suggest TOSSS could serve as a complementary security-focused metric in model benchmark reports.
Related Articles
I Was Wrong About AI Coding Assistants. Here's What Changed My Mind (and What I Built About It).
Dev.to

Interesting loop
Reddit r/LocalLLaMA
Qwen3.5-122B-A10B Uncensored (Aggressive) — GGUF Release + new K_P Quants
Reddit r/LocalLLaMA
A supervisor or "manager" Al agent is the wrong way to control Al
Reddit r/artificial
FeatherOps: Fast fp8 matmul on RDNA3 without native fp8
Reddit r/LocalLLaMA