DIP: Dead code Insertion based Black-box Attack for Programming Language Model
CheolWon Na, YunSeok Choi, Jee-Hyong Lee
Abstract
Automatic processing of source code, such as code clone detection and software vulnerability detection, is very helpful to software engineers. Large pre-trained Programming Language (PL) models (such as CodeBERT, Graph-CodeBERT, CodeT5, etc.), show very powerful performance on these tasks. However, these PL models are vulnerable to adversarial examples that are generated with slight perturbation. Unlike natural language, an adversarial example of code must be semantic-preserving and compilable. Due to the requirements, it is hard to directly apply the existing attack methods for natural language models. In this paper, we propose DIP (Dead code Insertion based Blackbox Attack for Programming Language Model), a high-performance and efficient black-box attack method to generate adversarial examples using dead code insertion. We evaluate our proposed method on 9 victim downstream-task large code models. Our method outperforms the state-of-the-art black-box attack in both attack efficiency and attack quality, while generated adversarial examples are compiled preserving semantic functionality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 92117a15-b6fc-45ec-8687-ea5c155f045bCited by top-tier papers5
- Can LLMs Obfuscate Code? A Systematic Analysis of Large Language Models into Assembly Code ObfuscationSeyedreza Mohseni, Seyedali Mohammadi, Deepa Tilwani, Yash Saxena et al.AAAI 2025 · 6 citations
- XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding AssistantsAdam Storek, Mukur Gupta, Noopur Bhatt, Aditya Gupta et al.ACL 2026 · 5 citations
- Mutual Learning-Based Framework for Enhancing Robustness of Code Models via Adversarial TrainingYangsen Wang, Yizhou Chen, Yifan Zhao, Zhihao Gong et al.ASE 2024 · 3 citations
- HogVul: Black-box Adversarial Code Generation Framework Against LM-based Vulnerability DetectorsJingxiao Yang, Ping He, Tianyu Du, Sun Bing et al.AAAI 2026 · 2 citations
- Effective Code Membership Inference for Code Completion Models via Adversarial PromptsYuan Jiang, Zehao Li, Shan Huang, Christoph Treude et al.ASE 2025 · 1 citation
Builds on12
- GraphCodeBERT: Pre-training Code Representations with Data FlowDaya Guo, Shuo Ren, Shuai Lu, Zhangyin Feng et al.ICLR 2021 · 1,644 citations
- Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and EntailmentDi Jin, Zhijing Jin, Joey Tianyi Zhou, Peter SzolovitsAAAI 2020 · 1,333 citations
- CodeT5: Identifier-aware Unified Pre-trained Encoder-Decoder Models for Code Understanding and GenerationYue Wang, Weishi Wang, Shafiq R. Joty, Steven C. H. HoiEMNLP 2021 · 1,224 citations
- BERT-ATTACK: Adversarial Attack Against BERT Using BERTLinyang Li, Ruotian Ma, Qipeng Guo, Xiangyang Xue et al.EMNLP 2020 · 529 citations
- Adversarial examples for models of codeNoam Yefet, Uri Alon, Eran YahavOOPSLA 2020 · 162 citations
Related papers
- Natural Attack for Pre-trained Models of CodeZhou Yang, Jieke Shi, Junda He, David LoICSE 2022 · 150 citations
- ContraBERT: Enhancing Code Pre-trained Models via Contrastive LearningShangqing Liu, Bozhi Wu, Xiaofei Xie, Guozhu Meng et al.ICSE 2023 · 56 citations
- Statement-Level Adversarial Attack on Vulnerability Detection Models via Out-of-Distribution FeaturesXiaohu Du, Ming Wen, Haoyu Wang, Zichao Wei et al.FSE 2025 · 1 citation
- Compressing Pre-trained Models of Code into 3 MBJieke Shi, Zhou Yang, Bowen Xu, Hong Jin Kang et al.ASE 2022 · 42 citations
- Black-Box Adversarial Attacks on LLM-Based Code CompletionSlobodan Jenko, Niels Mündler, Jingxuan He, Mark Vero et al.ICML 2025
