Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Fine-tuning Large Language Models for Software Supply Chains Threats Mitigation
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.
2025 (engelsk)Independent thesis Advanced level (degree of Master (Two Years)), 20 poäng / 30 hpOppgave
Abstract [en]

The growing complexity and interconnectivity of software supply chains have elevated the risks of security threats, demanding innovative solutions. This thesis investigates the fine-tuning of Large Language Models (LLMs), particularly Microsoft Phi-2, to enhance their ability to identify and mitigate software supply chain vulnerabilities. Using advanced techniques such as Parameter-Efficient Fine-Tuning (PEFT) with Low-Rank Adaptation (LoRA), the Phi-2 model was trained on a domain-specific dataset comprising incident reports, threat intelligence data, and best practices. 

The methodology encompasses a rigorous evaluation process using quantitative metrics, including ROUGE, BERTScore, and BLEURT, supplemented by qualitative insights derived from semi-structured interviews with cybersecurity experts. The in[1]terviews revealed valuable perspectives on the practical applicability of the fine-tuned model in addressing real-world threats such as compromised third-party components, open-source dependency vulnerabilities, and emerging attack patterns. 

The fine-tuned model exhibited significant improvements in generating contex[1]tually relevant, precise, and actionable threat mitigation strategies compared to its baseline. The findings demonstrate that domain-specific fine-tuning of LLMs is a vi[1]able approach for advancing automated threat detection and response capabilities in software supply chains. This research provides a robust framework for integrating AI[1]driven solutions into the software development lifecycle, contributing to the fields of software engineering and cybersecurity by improving resilience against supply chain attacks.

sted, utgiver, år, opplag, sider
2025. , s. 74
Emneord [en]
Large Language Models, Fine-Tuning, Software Supply Chain Security, Threat Mitigation, Cybersecurity, Microsoft Phi-2, Low-Rank Adaptation (LoRA), ParameterEfficient Fine-Tuning (PEFT), Automated Threat Detection, Software Engineering
HSV kategori
Identifikatorer
URN: urn:nbn:se:bth-27597OAI: oai:DiVA.org:bth-27597DiVA, id: diva2:1944165
Fag / kurs
PA2534 Master's Thesis (120 credits) in Software Engineering
Utdanningsprogram
PAADA Master Qualification Plan in Software Engineering 120,0 hp
Veileder
Examiner
Tilgjengelig fra: 2025-03-18 Laget: 2025-03-12 Sist oppdatert: 2025-09-30bibliografisk kontrollert

Open Access i DiVA

fulltext(1564 kB)418 nedlastinger
Filinformasjon
Fil FULLTEXT01.pdfFilstørrelse 1564 kBChecksum SHA-512
48f0051b4026839243c05d7bc343f05c1492906f62e3c84a0761723117711bbc347276a8b66ca2067c93f28442de6669c46d6a1f0e2e3bd32d6860dffad177f8
Type fulltextMimetype application/pdf

Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar
Totalt: 418 nedlastinger
Antall nedlastinger er summen av alle nedlastinger av alle fulltekster. Det kan for eksempel være tidligere versjoner som er ikke lenger tilgjengelige

urn-nbn

Altmetric

urn-nbn
Totalt: 911 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf