Measuring the Reasoning Boundaries of Large Language Models for Implicit Security Invariants in Code: A Controlled Empirical Study
This paper investigates the trust boundary of LLMassisted code security auditing, focusing on implicit security properties (security invariants) that are not expressed as explicit local rules but must hold throughout correct workflows. We propose a six-level semantic taxonomy spanning from explicit defects to workflow/...