Large Language Model for Vulnerability Detection and Repair: Literature Review and the Road Ahead
2024/12/18 by Xin Zhou, Sicong Cao, Xiaobing Sun +1 · 22 citations
Computer Science · #Network Security and Intrusion Detection #Software Engineering Research #Topic Modeling
paper · doi:10.1145/3708522
openalex publication_date 2024/12/18 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/30
Abstract
The significant advancements in Large Language Models (LLMs) have resulted in their widespread adoption across various tasks within Software Engineering (SE), including vulnerability detection and repair. Numerous studies have investigated the application of LLMs to enhance vulnerability detection and repair tasks. Despite the increasing research interest, there is currently no existing survey that focuses on the utilization of LLMs for vulnerability detection and repair. In this paper, we aim to bridge this gap by offering a systematic literature review of approaches aimed at improving vulnerability detection and repair through the utilization of LLMs. The review encompasses research work from leading SE, AI, and Security conferences and journals, encompassing 43 papers published across 25 distinct venues, along with 15 high-quality preprint papers, bringing the total to 58 papers. By answering three key research questions, we aim to (1) summarize the LLMs employed in the relevant literature, (2) categorize various LLM adaptation techniques in vulnerability detection, and (3) classify various LLM adaptation techniques in vulnerability repair. Based on our findings, we have identified a series of limitations of existing studies. Additionally, we have outlined a roadmap highlighting potential opportunities that we believe are pertinent and crucial for future research endeavors.
Citations
Cited by
- ArchISMiner: A Framework for Automatic Mining of Architectural Issue-Solution Pairs from Online Developer Communities
- POLAR: Automating Cyber Threat Prioritization through LLM-Powered Assessment
- Vul-R2: A Reasoning LLM for Automated Vulnerability Repair
- SecureFixAgent: A Hybrid LLM Agent for Automated Python Static Vulnerability Repair
- Large Language Models for Security Operations Centers: A Comprehensive Survey
- When Code Crosses Borders: A Security-Centric Study of LLM-based Code Translation
- AVIATOR: Towards AI-Agentic Vulnerability Injection Workflow for High-Fidelity, Large-Scale Code Security Dataset
- A Systematic Literature Review on Detecting Software Vulnerabilities with Large Language Models
- Secure coding for web applications: Frameworks, challenges, and the role of LLMs
- Repairing vulnerabilities without invisible hands. A differentiated replication study on LLMs
- Expert-in-the-Loop Systems with Cross-Domain and In-Domain Few-Shot Learning for Software Vulnerability Detection
- Explicit Vulnerability Generation with LLMs: An Investigation Beyond Adversarial Attacks
- Improving LLM Reasoning for Vulnerability Detection via Group Relative Policy Optimization
- LLM-Based Multi-Agent Systems for Software Engineering: Literature Review, Vision, and the Road Ahead
- MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
- SoK: Automated Vulnerability Repair: Methods, Tools, and Assessments
- Vul4Py: Benchmarking Automated Vulnerability Repair in Python with Paired Exploit and Functional Oracles
- LibVulnWatch: A Deep Assessment Agent System and Leaderboard for Uncovering Hidden Vulnerabilities in Open-Source AI Libraries
- SoK: AI Secure Code Generation: Progress, Pitfalls, and Paths Forward
- Multi-task Code LLMs: Data Mix or Model Merge?
- Frontier AI's Impact on the Cybersecurity Landscape
- Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey
Related