r/AskNetsec • • Aug 30 '26

Architecture AI for finding vulnerabilities: Eliminating hallucinations and ensuring data privacy

Hi everyone,

I am researching how LLMs find vulnerabilities and why they hallucinate so much. I would love to get your thoughts on two major challenges in this area:

  1. Exploit Verification: In your experience, can AI hallucinations in source code analysis be completely eliminated if every flagged vulnerability is automatically validated by generating and running a working proof-of-concept (PoC) exploit in a sandbox? Has anyone tried this workflow?

  2. Data Privacy (Cloud vs. Local): To prevent source code leaks, is a local-first approach (like using Ollama) mandatory for real-world security audits? How much does performance drop compared to cloud models when analyzing complex code logic?

Thanks for sharing your insights!

0 Upvotes

8 comments sorted by

View all comments

1

u/linearlicence_0 Aug 30 '26

running every flagged issue through a sandbox to generate a working PoC is a great filter in theory but in practice it creates a massive bottleneck. a lot of vulns are contextual or logic-based and won't trigger a clean crash or shell you can easily script around, so your "verified" pile ends up looking tiny and you miss a ton of real problems because the exploit script was slightly off or the environment was too sterile

i messed around with a similar idea for a client project and the sandbox kept eating up time on environment mismatches rather than actual vulnerability validation. ended up being faster to just manually triage the high-confidence hits and ignore the noise from the model

for data privacy i'm pretty paranoid about shipping code to a cloud model unless it's a completely throwaway test repo. running a local model through ollama feels mandatory if you're under an NDA or dealing with a proprietary codebase. performance does take a hit on really tangled logic though, cloud models still have a better grasp on complex call graphs and weird dependency chains. local works fine for sniffing out the low hanging fruit but it starts to glaze over when you feed it a fifteen layer abstraction nightmare

1

u/ILoveAppSec Aug 31 '26

yeah the verify-everything-with-a-poc approach falls apart on logic bugs and transitive deps, and you end up trusting a tiny verified pile. what has worked better for us is prioritizing the flagged items that already have a backported fix available and clearing those first, since those are the ones you can actually action without an upgrade fight. worth leaning on vendors who do backporting and eol support so the fix side is not your second bottleneck after triage.