cs.LGOct 4, 2026

Hidden in the Comments: A Context-Injection Attack Surface in Code LLMs

Authors: Noor Munir, Francesco Quinzan, Stephen Roberts

Organizations: Department of Engineering Science, University of Oxford, Oxford OX1 3PJ, UK

Abstract

Code large language model (Code LLM) assistants generate code from heterogeneous development contexts, including open files, imported modules, pasted snippets, and comments, much of which may originate from untrusted sources. We investigate whether insecure instructions embedded in such contexts can steer Code LLMs toward vulnerable code without access to model weights or training data. We evaluate ten open-weight Code LLMs spanning 3B--13B parameters, including four base and six instruction-tuned models, across ten web-application weakness classes. We compare completion tasks containing insecure instructions embedded as code comments with benign tasks without malicious instructions. Attack-condition completions contained a medium-or-higher weakness in {\bf 77.4--92.3}% of cases, compared with {\bf 1.7--5.1}% in the benign condition. Base and instruction-tuned models averaged 86.5% and 84.5% vulnerable outputs, respectively; equivalence testing and three matched model pairs indicated reductions of at most 8.1% after instruction tuning. Susceptibility showed no clear association with model scale or specialization. Among vulnerable attack outputs, 86.2--91.0% were rated high or critical, and the effect persisted without the pattern-based detector. Post-generation screening reduced but did not eliminate the risk, the strongest screen leaving roughly one-third undetected. These findings identify inference-time context injection as a substantial attack surface and motivate provenance-aware training objectives.

Figures & tables

Appendix figures & tables4 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Minimal Prompt Perturbations Lead to Code Vulnerabilities: Prompt Fragility and Hidden-State Signals in Coding LLMs

    May 28, 2026Alexander Sternfeld, Andrei Kucharavy, Ljiljana DolamicVulnerable CodeAi-Assisted Programming Tasks

  2. Poison with Style: A Practical Poisoning Attack on Code Large Language Models

    May 26, 2026Khang Tran, Yazan Boshmaf, Issa Khalil +3Attacker Large Language ModelPoisoning

  3. Interpreting and Steering for Safe and Correct Code Generation

    Aug 30, 2026Hao Yan, Ziyu YaoLarge Language Model SafetyVulnerable Code