A zero on security evals may be your verifier's fault, not the model's

himanshustwts · x · 2026-09-12

When building cybersecurity evals (SAST/CWE, CVE tasks), raw scores can mislead: a model may identify a more precise child CWE but score 0 because ground truth only mapped the broader parent CWE; or it may miss the intended vulnerability yet uncover another valid bug the verifier never checks. The author argues reading reasoning traces should be a rite of passage for eval builders — a zero can mean the model failed or that your verifier couldn't recognize a valid solution, and the score alone won't tell you which.

Original post →

More from coding & agent

coding & agent channel →