• EN
  • FR
Site carrière CEA : toutes nos offres d'emploi
CEA

Suivez nous

  •  

  • Accueil
  • Déposer une candidature spontanée
  • Ma recherche, mon alerte
  • CDI/CDD pour alternants/stag. CEA
  • Consulter nos sujets de Thèses
  • Un souci ? Contactez-nous
 

Connexion Espace candidat

J'ai déjà un espace candidat

Connexion à l'espace candidat




Mot de passe perdu

S'inscrire Je me crée un espace candidat

Vous n'avez pas encore votre propre espace candidat. Créez-le en cliquant ici.
Un souci ? Contactez-nous à
admin-poem@cea.fr

 

Vous êtes ici :  Accueil  ›  Liste des offres  ›  Détail de l'offre

Ma sélection : 0 offre(s)
Site carrière CEA : toutes nos offres d'emploi
CEA

Suivez nous

  •  

Menu Site carrière CEA

  • Accueil
  • Déposer une candidature spontanée
  • Ma recherche, mon alerte
  • CDI/CDD pour alternants/stag. CEA
  • Consulter nos sujets de Thèses
  • Un souci ? Contactez-nous
Pause
Lecture
Moteur de recherche d'offres d'emploi CEA
Voir toutes les offres
Flux RSS et autres flux
Information

Large language models for automatic bug finding in source code analysis H/F

  • Envoyer cette offre à un ami
  • Imprimer cette offre (nouvelle fenêtre)
  •  


Vacancy details

General information

CEA (logo)

Organisation

The French Alternative Energies and Atomic Energy Commission (CEA) is a key player in research, development and innovation in four main areas :
• defence and security,
• nuclear energy (fission and fusion),
• technological research for industry,
• fundamental research in the physical sciences and life sciences.

Drawing on its widely acknowledged expertise, and thanks to its 16000 technicians, engineers, researchers and staff, the CEA actively participates in collaborative projects with a large number of academic and industrial partners.

The CEA is established in ten centers spread throughout France
  

Reference

2025-37598  

Description de l'unité

CEA-Leti's Information Technology Security Evaluation Facility (ITSEF) is a security evaluation laboratory certified by the Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI) (France's national cybersecurity agency). It provides security evaluations for industrial products to obtain certification from the above certification bodies. It evaluates secure integrated microcircuits, HSMs and various smart cards such as bank cards, passports, health insurance cards, etc. It can also conduct "security tests" for pre-evaluations of electronic components and equipment. CEA-Leti ITSEF also performs security audits of design and production sites for secure products. CEA-Leti ITSEF designs, develops and advances internal hardware and software attack test benches to support security evaluations.

Position description

Category

Mathematics, information, scientific, software

Contract

Internship

Job title

Large language models for automatic bug finding in source code analysis H/F

Subject

JOIN US, TO DO WHAT?

Contribute to technological innovation for clean and safe energy, health and well-being, sustainable transportation, information and communications, space exploration, safety and security: that is the mission of CEA - Leti.

In the context of an ITSEF, the security evaluation of a software component usually requires a source code review (audit) performed by an evaluator who needs to be assisted by static analysis tools that can be configured and customized to help checking security requirements. The code analysis methodology applied at Leti ITSEF mainly consists in the following 2 operations: (1) extract a piece of source code to verify a particular property, (2) try to automatically prove the property, and in case of unknown status (the proof failed) search path conditions to violate the property. Such violations may reveal vulnerabilities to be exploited by malicious input data (software attack) combined with fault injection (hardware attack). 

Contract duration (months)

6

Job description

Join us for an internship!

CEA Tech Corporate from CEA Tech on Vimeo

As an intern at CEA, you will have the opportunity to work in a world-renowned research environment. Our teams are made up of passionate and dedicated experts, offering a framework conducive to learning and collaboration. You will have access to state-of-the-art equipment and first-rate research resources to carry out your assignments.

 

Main goals

(1) Investigate how LLM can be used to assist evaluators in finding bug automatically in source code. For example, a research question is how IA could assist the user in generating formal specification, which is a long repetitive and complex process.

(2) Assess how LLM perform and can be complementary to traditional tools used for evaluation (formal methods, using Frama-C and Lazart). 

Internship tasks

•Literature review of LLMs solutions for automatic bug finding.


•Test of LLMs on open benchmarks of source code containing vulnerabilities ([3,4])


•Evaluation of a scope where LLM is relevant (i.e. where it performs better than traditional tools, where it can be complementary, to assist the evaluator)


•Proposition of a methodology to assist source code analysis with LLMs 

 

References

[1] Sauze-Kadar Marine, Thomas. Loubier. (2025). A Multi-Model Approach to Enhance Automatic Matching of Vulnerabilities to Attack Patterns. Récupéré sur https://www.scitepress.org/DigitalLibrary/Link.aspx?doi=10.5220/0013555900003979

[2] Lacombe, G., Feliot, D., Boespflug, E. et al. Combining static analysis and dynamic symbolic execution in a toolchain to detect fault injection vulnerabilities. J Cryptogr Eng 14, 147–164 (2024). https://doi.org/10.1007/s13389-023-00310-8

[3] WooKey challenge: https://wookey-project.github.io/  

[4] ANSSI, Amossys, EDSI, LETI, Lexfo, Oppida, Quarkslab, SERMA, Synacktiv, Thales, Trusted Labs. (2020) Inter-CESTI: Methodological and Technical Feedbacks on Hardware Devices Evaluations. https://www.sstic.org/2020/presentation/inter-cesti_methodological_and_technical_feedbacks_on_hardware_devices_evaluations/

Methods / Means

LLM, IA, static code analysis, Formal methods, cybersecurity

Applicant Profile

What do we expect from you?

We are looking for a motivated and curious candidate (BAC+5) in the field of cybersecurity to join our team. The candidate must have good programming skills (Python, C, assembly, …) and some basic knowledge in artificial intelligence, embedded system security, vulnerability exploits.

A prior technical knowledge in formal methods for static code analysis is highly valued. A proactive and autonomous profile, an enthusiasm for scientific research are encouraged.

We offer:


An internship in the heart of the Grenoble metropolitan area, easily accessible via the CEA's soft mobility program.

A unique research environment dedicated to topics with high societal impact.

Experience in a cutting-edge field of innovation with strong industrial development potential.

Training to strengthen your skills or acquire new ones in embedded electronics, information technology, telecommunications, and/or cybersecurity.

 

In accordance with the CEA's commitments to the integration of people with disabilities, this job is open to all. The CEA offers accommodations and/or organizational possibilities for the inclusion of workers with disabilities.

 

Position location

Site

Grenoble

Job location

France, Auvergne-Rhône-Alpes, Isère (38)

Location

Grenoble

Candidate criteria

Languages

English (Intermediate)

Prepared diploma

Bac+5 - Diplôme École d'ingénieurs

Requester

Position start date

02/02/2026


Autres offres

Ces offres pourraient vous intéresser

Stage - Bac+4/+5 - Rédaction de fiches réflexes à destination des personnels d'astreinte - H/F

Ajouter cette offre à ma sélection : Stage - Bac+4/+5 - Rédaction de fiches réflexes à destination des personnels d'astreinte - H/F (2025-37280-S1724)
  • Réf. : 2025-37280-S1724
  • Stage
  • Lot (46)
  • GRAMAT

Stage Ingénieur/Master 2 - Détection de métaux lourds et toxiques chimiques dans l'air H/F

Ajouter cette offre à ma sélection : Stage Ingénieur/Master 2 - Détection de métaux lourds et toxiques chimiques dans l'air H/F (2025-37565)
  • Réf. : 2025-37565
  • Stage
  • Isère (38)
  • GRENOBLE

CDD - Chargé de relations sociales H/F

Ajouter cette offre à ma sélection : CDD - Chargé de relations sociales H/F (2025-37632)
  • Réf. : 2025-37632
  • CDD
  • Cote d'Or (21)
  • 21120 Is-sur-Tille
  • Mentions légales
  • Cookies
  • Paramétrer vos cookies
  • Accessibilité : partiellement conforme
  • Plan du site
Aller en haut