Konrad Rieck 🌈

@rieck.mlsec.org

Machine Learning and Security, Professor of Computer Science at TU Berlin,

Yesterday, Lukas presented at #ICSE2026 results I didn't believe when he first showed them to me. A classifier based on simple code metrics matches frontier LLMs for vulnerability discovery in performance, as long as they are not agentic. 🧵 (1/4)

Paper: LLM-based Vulnerability Discovery through the Lens of Code Metrics

4 Jahre lang haben wir im Bayer. Forschungsverbund ForDaySec.de untersucht, wie IT-Sicherheit im Alltag funktioniert. Informatik, Soziologie und Recht, 5 Unis, 8 Teilprojekte. Am Mittwoch (25.3.) stellen wir die Ergebnisse in München vor. 1/2

A researcher used more than 2,000 em-dashes in his papers, revealing AI-based manipulation in 400+ papers since 1985. Professor Zeller claims he "typed" these dashes into the paper by using "two hyphens" and a "typesetting" system.

$ cd ~/Papers/
$ grep -e '[ ~]-- ' */*.tex | wc -l
    2258
$