24 of 24 SAST Findings Were False — The Real Bug Was Three Lines Away
Bandit flagged every mark_safe() call in the codebase. All 24 were false positives. The actual stor…
Bandit flagged every mark_safe() call in the codebase. All 24 were false positives. The actual stor…
Scanning requirements.txt found nothing, because it could not even install. Scanning what the runni…
Security headers were configured once in the server block and applied to most of the site. Adding a…
A production Django site served traceback pages for months. No bad decision caused it — three envir…
A three-tier verification framework (SHA-256 commits → Fisher-selected proofs → full ZK) with 1000x…
How to cryptographically prove correct LLM inference without revealing model weights. Sumcheck redu…
FisherLD proposed Fisher-guided layer-wise KD for LLM recommenders, got accepted at AAAI 2026 Works…
Three fused index modalities (structural, semantic, relational) with cross-modal incremental propag…
3 GPT-3.5-turbo experts + 1 free local verifier achieve better-than-GPT-4 code analysis at 22% lowe…