← Back to search
paper llmsec-2026-00132

Can Adversarial Code Comments Fool AI Security Reviewers -- Large-Scale Empirical Study of Comment-Based Attacks and Defenses Against LLM Code Analysis

Scott Thornton

2026-02

Abstract

AI-assisted code review is widely used to detect vulnerabilities before production release. Prior work shows that adversarial prompt manipulation can degrade large language model (LLM) performance in code generation. We test whether similar comment-based manipulation misleads LLMs during vulnerability detection. We build a 100-sample benchmark across Python, JavaScript, and Java, each paired with eight comment variants ranging from no comments to adversarial strategies such as authority spoofing

Categories

Cite This Resource

@article{llmsec202600132,
  title = {Can Adversarial Code Comments Fool AI Security Reviewers -- Large-Scale Empirical Study of Comment-Based Attacks and Defenses Against LLM Code Analysis},
  author = {Scott Thornton},
  year = {2026},
  url = {https://arxiv.org/abs/2602.16741},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2602.16741