Static application security testing remains difficult to deploy at scale in Python repositories because practical tools must be accurate, fast, and interpretable under extreme class imbalance. This paper introduces SecureLite, a lightweight pipeline that combines (i) a compact vulnerability detector trained on statement‑annotated data and (ii) an LLM‑assisted triage stage that converts detector evidence into actionable fix guidance. We conduct experiments on the DetectVul/CVEFixes dataset, using its provided train/test splits (4,584/1,146 Python functions). Each function is represented as a sequence of statements, statement types, and per‑statement vulnerability labels. We convert these labels into a function‑level target and compare four efficient detectors: token TF‑IDF + logistic regression (SGD), type‑aware token TF‑IDF, character TF‑IDF, and a LightGBM model over 15 static features. We additionally train a tiny Transformer encoder (TinyVulFormer‑XS) to test whether a minimal self‑attention model can compete with linear baselines under small‑data constraints. On the test set, the best lightweight models (character TF‑IDF and type‑aware token TF‑IDF) achieve AUROC 0.925 and AUPRC 0.381 with an F1 score of 0.421 at a 0.5 decision threshold, outperforming both static‑feature boosting and the tiny Transformer. We further analyze threshold sensitivity, error modes, and how LLM triage can reduce analyst time by proposing fixes and unit tests for high‑risk predictions. The resulting system offers a reproducible, CPU‑friendly baseline for Python vulnerability screening and a practical blueprint for integrating lightweight detection with LLM‑guided remediation.
Copyrights © 2026