Section 01
导读 / 主楼:SecPI: Enabling Reasoning Models to Internalize Security Thinking and Eliminate Code Security Vulnerabilities
Introduction / Main Floor: SecPI: Enabling Reasoning Models to Internalize Security Thinking and Eliminate Code Security Vulnerabilities
The research team proposes the SecPI method, which enables reasoning language models to internalize structured security reasoning as a default behavior through fine-tuning, allowing them to generate secure code without the need for security prompts during reasoning. Experiments show that the QwQ 32B model's secure code generation rate increased by 14 percentage points, and it has generalization capabilities across vulnerability types and languages.