acceptodds
Under review as a conference paper at ICLR 2027

Securing Agentic Code Generation with Intent Code Graph Learning

Abstract

Large language model (LLM) agents have shown strong potential in automating real-world software engineering tasks. However, their deployment introduces new security risks, particularly their susceptibility to adversarial attacks that can manipulate agents into generating vulnerable or malicious code. Detecting such adversarially induced behavior remains a significant challenge. Existing detection approaches include guardrail model-based methods and static analysis-based methods. Guardrail models struggle in long-context settings due to degraded reasoning, while static analyzers depend on predefined security checks whose coverage may not extend to obfuscated or task-dependent malicious behavior. To address these limitations, we propose \tool, a graph-based detector for adversarially manipulated prompt-and-patch pairs. Inspired by semantic alignment between natural language and code, \tool first decomposes prompts into structured intent blocks and generated code into code blocks, enabling fine-grained modeling in long-context settings. It then treats these blocks as nodes and constructs an intent-code graph that captures their semantic correspondences and structural relationships. A graph neural network learns from semantic node representations and their connectivity using benign and synthetically augmented graphs, without training on examples from the evaluated attack algorithms. Experiments across diverse benchmarks, attack methods, and agent-LLM configurations show that \tool generally outperforms the evaluated baselines under attacks with code obfuscation, while static checkers' performance varies substantially across settings despite their advantage on non-obfuscated runs. These results support structural misalignment as a promising detection signal beyond predefined vulnerability checks. Our implementation and generated prompt-and-patch data are publicly available.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.