Core PhD Question
Can Transformer models understand the full lifecycle of a vulnerability; from vulnerable code, to patch, to advisory, to regression risk; and determine whether a security fix is complete, safe, and trustworthy?
So we are not planning to do the following:
Not vulnerability detection. Not automated patching. But “security patch trustworthiness intelligence.”