SearcharxivSearch

arXiv subjects

Xingbo Pan

Publications and source records attributed to Xingbo Pan.

3 recordsLinked to original sources

SecCodeBench-V2 Technical Report

We introduce SecCodeBench-V2, a publicly released benchmark for evaluating Large Language Model (LLM) copilots' capabilities of generating secure code. SecCodeBench-V2 comprises 98 generation and fix scenarios derived from Alibaba Group's industrial productions, where the underlying security issues span 22 common CWE (Common Weakness Enumeration) categories across five programming languages: Java, C, Python, Go, and JavaScript. SecCodeBench-V2 adopts a function-level task formulation: each scenario provides a complete project scaffold and requires the model to implement or patch a designated target function under fixed interfaces and dependencies. For each scenario, SecCodeBench-V2 provides executable proof-of-concept (PoC) test cases for both functional validation and security verification. All test cases are authored and double-reviewed by security experts, ensuring high fidelity, broad coverage, and reliable ground truth. Beyond the benchmark itself, we build a unified evaluation pipeline that assesses models primarily via dynamic execution. For most scenarios, we compile and run model-generated artifacts in isolated environments and execute PoC test cases to validate both functional correctness and security properties. For scenarios where security issues cannot be adjudicated with deterministic test cases, we additionally employ an LLM-as-a-judge oracle. To summarize performance across heterogeneous scenarios and difficulty levels, we design a Pass@K-based scoring protocol with principled aggregation over scenarios and severity, enabling holistic and comparable evaluation across models. Overall, SecCodeBench-V2 provides a rigorous and reproducible foundation for assessing the security posture of AI coding assistants, with results and artifacts released at https://alibaba.github.io/sec-code-bench. The benchmark is publicly available at https://github.com/alibaba/sec-code-bench.

cs.CR

One-photon-interference quantum secure direct communication

Quantum secure direct communication (QSDC) is a quantum communication paradigm that transmits confidential messages directly using quantum states. Measurement-device-independent (MDI) QSDC protocols can eliminate the security loopholes associated with measurement devices. To enhance the practicality and performance of MDI-QSDC protocols, we propose a one-photon-interference MDI QSDC (OPI-QSDC) protocol which transcends the need for quantum memory, ideal single-photon sources, or entangled light sources. The security of our OPI-QSDC protocol has also been analyzed using quantum wiretap channel theory. Furthermore, our protocol could double the distance of usual prepare-and-measure protocols, since quantum states sending from adjacent nodes are connected with single-photon interference, which demonstrates its potential to extend the communication distance for point-to-point QSDC.

quant-ph

Mixed-encoding one-photon-interference quantum secure direct communication

Quantum secure direct communication (QSDC) guarantees both the security and reliability of information transmission using quantum states. One-photon-interference QSDC (OPI-QSDC) is a technique that enhances the transmission distance and ensures secure point-to-point information transmission, but it requires complex phase locking technology. This paper proposes a mixed-encoding one-photon-interference QSDC (MO-QSDC) protocol that removes the need for phase locking technology. Numerical simulations demonstrate that the MO-QSDC protocol could also beat the PLOB bound.

quant-ph