arrow
Return

Leveraging Static Analysis for Feedback-Driven Security Patching in LLM-Generated Code

delete2025-12-05
delete0
delete
OA
AI
K
Kamel Alrashedy *
A
Abdullah Aljasser
P
Pradyumna Tambwekar
M
Matthew Gombolay
DOI:10.3390/jcp5040110delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Large language models (LLMs) have shown remarkable potential for automatic code generation. Yet, these models share a weakness with their human counterparts: inadvertently generating code with security vulnerabilities that could allow unauthorized attackers to access sensitive data or systems. In this work, we propose Feedback-Driven Security Patching (FDSP), wherein LLMs automatically refine vulnerable generated code. The key to our approach is a unique framework that leverages automatic static code analysis to enable the LLM to create and implement potential solutions to code vulnerabilities. Further, we curate a novel benchmark, PythonSecurityEval, that can accelerate progress in the field of code generation by covering diverse, real-world applications, including databases, websites, and operating systems. Our proposed FDSP approach achieves the strongest improvements, reducing vulnerabilities by up to 33% when evaluated with Bandit and 12% with CodeQL and outperforming baseline refinement methods.
Keywords:
large language models
secure AI code
security patching

Journal

J
Journal of Cybersecurity and Privacy
IF:
0
Papers:
131
Citations:
0

Organization

U
university system of georgia
Scholars:
7.3W
Papers: 6.5W
Citations: 101
Cited Papers

Cited Papers

Software Testing With Large Language Models: Survey, Landscape, and Vision
err2024-04-01
err31
errOAAI
errWang, Junjie; Huang, Yuchao; Chen, Chunyang; Liu, Zhe; Wang, Song; Wang, Qing
errShare
errSave
Algorithms on Strings, Trees and Sequences
err
IF0
err2010-06-23
err0
PREAI
errDan Gusfield
errShare
errSave
CodeGeeX: A Pre-Trained Model for Code Generation with Multilingual Benchmarking on HumanEval-X
err2023-08-04
err0
errOAAI
errQinkai Zheng; Xiao Xia; Xu Zou; Yuxiao Dong; Shan Wang; Yufei Xue; Lei Shen; Zihan Wang; Andi Wang; Yang Li; Teng Su; Zhilin Yang; Jie Tang
errShare
errSave
Python Coding Style Compliance on Stack Overflow
err2019-05-01
err0
errOAAI
errNikolaos Bafatakis; Niels Boecker; Wenjie Boon; Martin Cabello Salazar; Jens Krinke; Gazi Oznacar; Robert White
errShare
errSave
researcher View more