Downloads · 30 days
752
7% of all-time downloads
QCRI/LLMxCPG-Q
LLMxCPG-Q is a machine learning model from QCRI. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
LLMxCPG-Q is a specialized Large Language Model designed for vulnerability analysis. It is a fine-tuned version of the Qwen2.5-Coder-32B-Instruct model, specifically trained to generate CPGQL queries for use with the…
Downloads · 30 days
752
7% of all-time downloads
All-time downloads
10.4K
Public
Parameters
32.8B
65.5 GB on disk
Likes
8
Public
Click a slice to open those files.
.safetensors65.5 GB · 100%
From the Hugging Face model README
LLMxCPG-Q is a specialized Large Language Model designed for vulnerability analysis. It is a fine-tuned version of the Qwen2.5-Coder-32B-Instruct model, specifically trained to generate CPGQL queries for use with the Joern static analysis tool.
This model serves as the first phase of the LLMxCPG framework, which combines Code Property Graphs (CPG) with Large Language Models (LLM) for robust vulnerability detection. LLMxCPG-Q's core function is to generate precise queries that identify vulnerability-relevant execution paths in source code, enabling the creation of focused code slices.
The model takes a code snippet as input and outputs a valid CPGQL query. This query is then used by the Joern tool to traverse the Code Property Graph and extract a concise, vulnerability-focused code slice. This approach is highly effective because it overcomes the low-resource nature of the CPGQL language and allows for targeted program analysis.
For more information, please visit the official GitHub repository: https://github.com/qcri/llmxcpg