Section 01
Introduction to Vul-RAG Reproducibility Study: Performance Bottlenecks of Open-Weight Models in Vulnerability Detection
Original Authors & Source
- Original Author/Team: IT Security Research Team at Esslingen University of Applied Sciences, Germany
- Source Platform: arXiv
- Original Title: Revisiting Vul-RAG: Reproducibility and Replicability of RAG-based Vulnerability Detection with Open-Weight Models
- Original Link: http://arxiv.org/abs/2606.04739v1
- Publication Date: June 3, 2026
- Open-Source Code: https://github.com/hs-esslingen-it-security/revisiting-Vul-RAG
Core Insights
A reproducibility study on the RAG-based vulnerability detection framework reveals that even with the latest open-weight models, the pairwise accuracy of vulnerability detection still has a bottleneck of around 0.30, which is difficult to break by simply increasing the model size. The study explores the reproducibility and transferability issues of the Vul-RAG framework, providing key references for model applications in the software security field.