
StageInformatiqueCEA
CEA Grenoble
France
Mathématiques, information scientifique, logiciel Large Language Model (LLM) for source code analysis in security evaluation H/F Using LLM to identify vulnerabilities by source code analysis is an emerging technique whose limitations have to be studied before it can be integrated in a security evaluation methodology as specified by ANSSI note 26 [1] (Common Criteria certification applicable document). [1] https://cyber.gouv.fr The objective of this internship is to show how the LLM approach modifies the traditional approach using static analysis techniques. Several new LLM-based approaches will have to be defined and experimented on code bases. The complementarity of an LLM with static analysis tools, in particular those provided by the Frama-C platform [2] will have to be studied, for example the automatic generation of formal specifications for Frama-C/WP. [2] https://frama-c.com LLM, static analysis, formal methods, cybersecurity Computer engineering degree, final year.Knowledge of static analysis techniques and software attack techniques (vulnerabilities and exploits).Interest for AI agent assisted software development and for the possible interactions between LLM and static analysis and formal verification tools.
Source : CEA · Récupérée le 30 septembre 2026