Jev와 CodeGraph를 활용한 보안 리뷰
typesafe-security-review 프로젝트는 Jev의 확률 판단을 코드 그래프와 OWASP/CWE 데이터와 결합해 저비용 보안 스캔에 활용합니다.
저자는 Jev를 다른 모델과 비교하여 자체 AI 보안 검증 세트, 독립적인 어려운 양성 벤치마크, 제3자 어려운 양성 벤치마크에서 평가한 결과, Jev는 나쁘지 않지만 프로덕션 준비가 되지 않았고 에어갭도 아니라고 결론지었다.
Because everybody here is comparing Jev with other models. I compared Jev on our #AISecurity Validation set, a independent hard benign benchmark, and a third party hard benign one. Result: #Jev is far from bad but not production ready. Also not air gapped.