filtering-unsupported-llm-generated-vulnerability-reports-security-triage-statistical-machine-text
mechanismsingle paperpending review

For filtering unsupported LLM-generated vulnerability reports in security triage, statistical machine-text detectors are the wrong instrument: they score provenance, not correctness, and human-written security reports are template-driven and low-perplexity, so they trip the same signal that flags machine text.

Ingested from a paper but not yet reviewed by a human. It is deliberately inert: it does not move any technique’s standing, does not count toward the backtest, and is excluded anywhere a claim would carry weight. Read the source before relying on it.

Capability: Stating false facts confidently

Observed on

Security artifacts with rigid templates and standardized formatting — bug bounty reports, stack traces, patch descriptions; argued, not measured here..

Sources

Status: pending-reviewLast checked: 2026-09-09Evidence activity: not checked yet
Contest this claim

Disagreeing is the most useful thing you can do here. Both sides of every contested claim in this catalog were assembled by the same person, which is its weakest point.

Related claims

Notes

Drafted from the paper by a model and filed unreviewed. Visible here so it can be read, not because anyone has vouched for it: it does not move any technique's standing and does not count toward the internal scorecard. Drafted confidence: medium. Falsifier as drafted: A statistical AI-text detector applied to a mixed corpus of human and LLM bug bounty reports achieves both low false-positive rates on human reports and high separation of unsupported claims from grounded ones. Proposed technique, not catalogued: Deductive coverage scoring of vulnerability claims.