❌

Normal view

SecureVibeBench: Evaluating Secure Coding Capabilities of Code Agents with Realistic Vulnerability Scenarios

arXiv:2509.22097v2 Announce Type: replace-cross Abstract: Large language model-powered code agents are rapidly transforming software engineering, yet the security risks of their generated code have become a critical concern. Existing benchmarks have provided valuable insights, but they fail to capture scenarios in which vulnerabilities are actually introduced by human developers, making fair comparisons between humans and agents infeasible. We therefore introduce SecureVibeBench, a benchmark of 105 C/C++ secure coding tasks sourced from 41 projects in OSS-Fuzz for code agents. SecureVibeBench has the following features: (i) realistic task settings that require multi-file edits in large repositories, (ii)~aligned contexts based on real-world open-source vulnerabilities with precisely identified vulnerability introduction points, and (iii) comprehensive evaluation that combines functionality testing and security checking with both static and dynamic oracles. We evaluate 5 popular code agents like OpenHands, supported by 5 LLMs (e.g., Claude sonnet 4.5) on SecureVibeBench. Results show that current agents struggle to produce both correct and secure code, as even the best-performing one, produces merely 23.8\% correct and secure solutions on SecureVibeBench.

AI Agents and Epidemic Intelligence on Respiratory Infectious Diseases: Toward a Conceptual Framework Integrating Decision Support

Traditional epidemic intelligence relies heavily on human epidemiologists for data interpretation and reporting, which makes it resource intensive, slow to respond, and vulnerable to variability in professional expertise. To overcome these limitations, we propose an expanded conceptual epidemic intelligence quadripartite framework that extends the classical trinity of (1) surveillance, (2) risk evaluation, and (3) early warning with a fourth pillar, (4) decision support and intervention optimization through AI agents. Acting as 24/7 digital epidemiologists, multiagent systems can integrate heterogeneous signals from multisource surveillance systems, conduct contextual risk evaluation and adaptive forecasting, generate tailored early warnings, and provide actionable recommendations for targeted controlβ€”closing the loop between detection and response. Embedding interpretability and mandatory human-in-the-loop oversight enhances trust and accountability. Nonetheless, real-world deployment requires addressing context-specific challenges of data quality, interoperability, robustness, governance, circular reporting, and equity. If designed with transparency, inclusiveness, and resilience, AI agents have the potential to transform epidemic intelligence into a continuously adaptive and globally connected system.
❌