docs: Add Secret Detection Benchmarks section with performance metrics

- Added dedicated section showcasing secret detection benchmark results
- Includes comparison table with recall rates and speeds
- Links to detailed benchmark analysis
- Highlights LLM detector's 84.4% recall on obfuscated secrets
This commit is contained in:
tduhamel42
2025-10-16 14:05:05 +02:00
parent 3f133374d5
commit 73ba98afa8

View File

@@ -67,6 +67,23 @@ If you find FuzzForge useful, please star the repo to support development 🚀
--- ---
## 🔍 Secret Detection Benchmarks
FuzzForge includes three secret detection workflows benchmarked on a controlled dataset of **32 documented secrets** (12 Easy, 10 Medium, 10 Hard):
| Tool | Recall | Secrets Found | Speed |
|------|--------|---------------|-------|
| **LLM (gpt-5-mini)** | **84.4%** | 41 | 618s |
| **LLM (gpt-4o-mini)** | 56.2% | 30 | 297s |
| **Gitleaks** | 37.5% | 12 | 5s |
| **TruffleHog** | 0.0% | 1 | 5s |
📊 [Full benchmark results and analysis](backend/benchmarks/by_category/secret_detection/results/comparison_report.md)
The LLM-based detector excels at finding obfuscated and hidden secrets through semantic analysis, while pattern-based tools (Gitleaks) offer speed for standard secret formats.
---
## 📦 Installation ## 📦 Installation
### Requirements ### Requirements