arrow
返回

SA2Pat: enhancing binary security patch function localization via security advisory-guided LLMs

delete2026-08-03
delete0
PRE
AI
Z
Zetan Li
X
Xiaoya Zhu
卓力 封面图
卓力 (Zhuo Li)
M
Min Li
李聪 封面图
李聪 (Cong Li)
X
Xiaokang Yin
Y
Yaobin Xie *
S
Shengli Liu
DOI:10.1007/s10664-026-10942-zdelete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In modern software supply chains, security patch function localization seeks to establish a precise correlation between a Common Vulnerabilities and Exposures (CVE) entry and the function in the codebase that contains its patch. Existing approaches predominantly rely on source code information. Thus, when security audits must be conducted directly on binary files, traditional source-code-based localization methods become ineffective. To address this gap, we propose SA2Pat (Security Advisory to Patch), a framework that accurately localizes security patches by learning from patterns in historical vulnerability fixes. SA2Pat first utilizes IDA Pro and BinDiff to identify pairs of modified functions between vulnerable and patched binaries. It then treats the security advisory text as a query to retrieve reference samples from a constructed external knowledge base containing historical vulnerability patches, thereby guiding a large language model (LLM) to locate the patched function. To mitigate the frequent absence of Common Weakness Enumeration (CWE) IDs in security advisories, we employ a fine-tuned SecureBERT model to predict the likely CWE ID, ensuring that the input information remains complete. Experimental results on a dataset of 364 real-world CVEs—constructed by augmenting the PatchDiscovery benchmark with recent vulnerability patches—indicate that SA2Pat improves the F1-score by 19.35 percentage points over baseline methods. An ablation study shows that removing the reference samples decreases the F1-score by 16.6 percentage points, while removing CWE information reduces it by 4.8 percentage points, demonstrating that both components contribute critically to performance. When the oracle CWE is replaced by the SecureBERT classifier’s prediction in an end-to-end setting, SA2Pat still attains an F1-score of 70.8%, close to the 72.2% under oracle CWE. Moreover, SA2Pat remains effective across different LLM backbones.
Keyword:
Security patch function localization
LLM
Program analysis
Patch presence test
Software supply chain

期刊

Empirical Software Engineering 封面图
Empirical Software Engineering
IF:
3.6
论文数:
2.0K
被引数:
5.3K

机构

P
pla information engineering university
学者数:
2.8K
论文数: 1.6K
被引数: 2
引用论文

引用论文

FoC: Figure Out the Cryptographic Functions in Stripped Binaries with LLMs
err2026-01-31
err0
PREAI
errShang,Xiuwei; Chen,Guoqiang; Cheng,Shaoyin; Guo,Shikai; Zhang,Yanming; Zhang,Weiming; Yu,Nenghai
err分享
err收藏
HexT5: Unified Pre-Training for Stripped Binary Code Information Inference
err
IF0
err2023-09-11
err0
PREAI
errJiaqi Xiong; Guoqiang Chen; Kejiang Chen; Han Gao; Shaoyin Cheng; Weiming Zhang
err分享
err收藏
PDiff: Semantic-based Patch Presence Testing for Downstream Kernels
err2020-11-02
err0
PREAI
errZheyue Jiang; Yuan Zhang; Jun Xu; Qi Wen; Zhenghe Wang; Xiaohan Zhang; Xinyu Xing; Min Yang; Zhemin Yang
err分享
err收藏
学者 查看更多内容