Adversarial Comments Are Now a Vulnerability Detection Bypass Technique

TL;DR AI
2 min readKey summary
Researchers say adversarial comments can steer LLM vulnerability detectors to mark unsafe code as safe.
The ALIBI attack framework injected malicious natural-language and tool-output-style comments into source code.
It reportedly achieved over 90% success against four detectors, including multi-agent systems like Sentinel.
The finding shows that comments can become a prompt-injection path that hides real bugs from AI security tools.
