All resources
Topic

rag

2 resources across 2 kinds

Frameworks & agents

  1. Vul-RAG, a knowledge-level retrieval-augmented-generation framework for LLM-based vulnerability detection: it extracts vulnerability knowledge from CVEs into a knowledge base and uses it to judge whether given code is vulnerable. Ships the LinuxVul benchmark (4,667 vulnerable/patched function pairs from 2,174 Linux-kernel CVEs across the top-10 CWEs); the authors report finding 10 previously-unknown kernel bugs, 6 receiving CVE assignments.

    Open ↗

References

  1. A vulnerability-intelligence platform that aggregates CVEs from seven public sources (GHSA, NVD, CVEfixes, MegaVul, BigVul, MoreFixes, Security DPO) into a canonical schema and indexes them with vector embeddings for code-similarity, pattern-based, cross-project and natural-language search. Built on Python/FastAPI with ChromaDB and transformer embeddings, it can also generate Semgrep/CodeQL detection rules and exposes REST and CLI interfaces.

    Open ↗