DOE OSTI · 2585485
Mini Report: LLMs for Vulnerability Repair in Code
Abstract
Software vulnerability repair is a notoriously difficult task that is both time consuming and labor intensive. While research into this area has a long history, the recent successes of large language models (LLMs) across many tasks have also spurred efforts to leverage LLM capabilities for automated software vulnerability repair. Currently, there are limitations in the capabilities of LLMs to fix bugs and insufficiently addressed problems in the evaluations of these studies may cause performance to not transfer when they are used in practice. Additionally, most research in the area treats finding and fixing bugs as separate concerns - how to best combine all the subtasks involved in removing vulnerabilities from code remains an open question. In this report, we summarize our findings and opinions on the current state of the art in LLM-assisted code vulnerability repair, highlighting current unresolved problems in the field as well as potential applications and future research.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Lee, Jina, Kavaler, David Minh, Heidbrink, Scott Jared, Casalnuovo, Casey. 2024-03-01. Mini Report: LLMs for Vulnerability Repair in Code. https://doi.org/10.2172/2585485
Cite the original work for its findings. Save a collection to share your selection of sources.