[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-scanner-catches-ai-coding-models-trained-to-write-insecure-code":10,"sections":34},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":29,"feedback":33,"feedback_at":22,"cost_usd":33,"total_tokens":33},7822,"scanner-catches-ai-coding-models-trained-to-write-insecure-code","Scanner Catches AI Coding Models Trained to Write Insecure Code","CodeScan, a new black-box tool, flags code-generation AI models poisoned to secretly write vulnerable code, catching 97%+ of cases across 117 models.","A new scanner can catch AI coding assistants that have been secretly trained to slip security bugs into their output, without needing access to the model's internals.\n\nThe tool, called CodeScan, is a black-box auditing framework built for code-generation LLMs that attackers have backdoored or poisoned to write insecure code on cue. It works by feeding a model many different clean prompts, then comparing the structure of what comes back using abstract syntax tree normalization, so that different-looking but semantically identical code gets grouped as the same pattern. When a structure keeps recurring across generations, an LLM-based check inspects it for known vulnerability types, and if it finds one, the model gets flagged as compromised. The researchers tested CodeScan against four attack methods, covering both backdoor and poisoning styles, across three vulnerability classes, running it on 117 models spanning three architectures and multiple sizes. They reported detection accuracy above 97%, with far fewer false positives than prior methods.\n\nThis matters because software teams are leaning harder on AI-generated code, and a poisoned model could quietly plant the same exploitable bug across thousands of codebases before anyone notices. Older detection methods look at token-level consistency in generated text, which falls apart for source code, since the same vulnerability can be written a dozen syntactically different ways. Normalizing at the AST level instead of the token level is the actual novel move here.\n\nIt's still a lab result, not a shipped product. And it requires the defender to already know which vulnerability classes to hunt for, so it won't catch a poisoning attack nobody thought to look for.","[\"ai\",\"security\",\"code-generation\",\"data-poisoning\"]","2026-09-25T04:00:00.000Z","2026-09-26T00:54:39.361Z","2026-09-26T00:54:43.046Z","published",null,[],"security",[26,24,27,28],"ai","code-generation","data-poisoning",[30],{"name":31,"url":32},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2603.17174",0,{"sections":35},[36,40,44,49,54,59,64,69,74,79,84,89,94,99],{"name":37,"slug":26,"count":38,"latest_published_at":39},"AI",4527,"2026-09-25T16:31:14.000Z",{"name":41,"slug":24,"count":42,"latest_published_at":43},"Security",741,"2026-09-25T15:52:13.000Z",{"name":45,"slug":46,"count":47,"latest_published_at":48},"Policy","policy",390,"2026-09-25T16:24:59.000Z",{"name":50,"slug":51,"count":52,"latest_published_at":53},"Deals","deals",256,"2026-09-25T17:00:53.000Z",{"name":55,"slug":56,"count":57,"latest_published_at":58},"Hardware","hardware",185,"2026-09-25T15:00:22.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":63},"Science","science",140,"2026-09-25T11:55:23.000Z",{"name":65,"slug":66,"count":67,"latest_published_at":68},"Consumer Tech","consumer-tech",132,"2026-09-25T15:30:00.000Z",{"name":70,"slug":71,"count":72,"latest_published_at":73},"Software","software",88,"2026-09-24T23:06:55.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Dev Tools","dev-tools",82,"2026-09-25T09:59:40.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Startups","startups",76,"2026-09-25T18:33:59.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",46,"2026-09-25T02:12:57.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",30,"2026-09-24T20:07:31.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]