arrow
Return

Security Analysis of Large Language Models on API Misuse Programming Repair

delete2024-11-19
delete0
delete
OA
AI
R
Rui Zhang
Z
Ziyue Qiao
禹勇 (Yong Yu) *
DOI:10.1155/2024/7135765delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Application programming interface (API) misuse refers to misconceptions or carelessness in the anticipated usage of APIs, threatening the software system's security. Moreover, API misuses demonstrate significant concealment and are challenging to uncover. Recent advancements have explored enhanced LLMs in a variety of software engineering (SE) activities, such as code repair. Nonetheless, the security implications of using LLMs for these purposes remain underexplored, particularly concerning the issue of API misuse. In this paper, we present an empirical study to observe the bug-fixing capabilities of LLMs in addressing API misuse related to monitoring resource management (MRM API misuse). Initially, we propose APImisRepair, a real-world benchmark for repairing MRM API misuse, including buggy programs, corresponding fixed programs, and descriptions of API misuse. Subsequently, we assess the performance of several LLMs using the APImisRepair benchmark. Findings reveal the vulnerabilities of LLMs in repairing MRM API misuse and find several reasons, encompassing factors such as fault localization and a lack of awareness regarding API misuse. Additionally, we have insights on improving LLMs in terms of their ability to fix MRM API misuse and introduce a crafted approach, APImisAP. Experimental results demonstrate that APImisAP exhibits a certain degree of improvement in the security of LLMs.

Journal

International Journal of Intelligent Systems cover
International Journal of Intelligent Systems
IF:
3.7
Papers:
3.0K
Citations:
8.1K

Organization

S
Shaanxi Normal University
Scholars:
1.6W
Papers: 1.1W
Citations: 1.7W
G
Great Bay University
Scholars:
439
Papers: 396
Citations: 504