SecureVibe: Making Vibe Coding More Secure

📅 2026-09-29
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the issue of functionally correct yet security-compromised code generated through vibe coding by proposing SECUREVIBE, a method designed to enhance an agent's planning and testing capabilities against latent risks. The approach establishes a security-oriented training paradigm that integrates supervised fine-tuning, reinforcement learning, and prompt-guided self-supervision, leveraging verifiable execution feedback to reinforce secure model behaviors. Experimental results demonstrate that SECUREVIBE improves security pass@1 on the BaxBench benchmark by 6.9 percentage points and achieves an 11.5 percentage point gain on the SusVibes benchmark. These findings indicate that the proposed method significantly enhances code security while preserving functional correctness.
📝 Abstract
As vibe coding becomes increasingly capable and widespread, security vulnerabilities in even functionally correct solutions are a growing concern. When investigating functionally correct but insecure solutions, we find that the insecure agent is less than half as likely to conduct effective planning and testing for the hidden security risks behind the functional requirements. Motivated by this, we develop SECUREVIBE, a training recipe that explicitly targets planning and testing for code security. SECUREVIBE constructs training signals around these security behaviors. It includes supervised fine-tuning on the security suite with 4 security tasks, and post-training methods, SECUREVIBE_rl and SECUREVIBE_hg, to enhance security capabilities from verifiable execution feedback and hint-based self-supervision. Our SECUREVIBE outperforms the baseline on two types of security coding tasks across 4 benchmarks. Specifically, SECUREVIBE improves the security pass@1 by 6.9 points on BaxBench. The gains extend to unseen CWE categories, with improvements of 11.5 points on SusVibes. Meanwhile, it also improves functionality pass@1 by 13.6 points on the security coding task SusVibes and 4.1 points on the generic coding task SWE-bench Verified. Further analysis offers two practical insights: (i) diversifying supervision across security planning, coding, and testing strengthens security behaviors more effectively than adding coding trajectories alone, and (ii) hint-guided supervision is particularly valuable when the agent's existing security capabilities are insufficient to learn effectively from outcome feedback.
Problem

Research questions and friction points this paper is trying to address.

Vibe Coding
Security Vulnerabilities
Code Security
AI Agent
Secure Planning and Testing
Innovation

Methods, ideas, or system contributions that make the work stand out.

Vibe Coding Security
Planning and Testing
Reinforcement Learning
Hint-guided Self-supervision
Post-training
🔎 Similar Papers
No similar papers found.