vix.ing · top · new · best · stats

LLM-based Vulnerable Code Augmentation: Generate or Refactor?

2025/12/09 by Ouchebara, Dyna Soumhane, Dupont, Stéphane
Computer Science · #Web Application Security Vulnerabilities #Advanced Malware Detection Techniques #Security and Verification in Computing

paper · pdf · doi:10.48550/arxiv.2512.08493

Abstract

Vulnerability code-bases often suffer from severe imbalance, limiting the effectiveness of Deep Learning-based vulnerability classifiers. Data Augmentation could help solve this by mitigating the scarcity of under-represented vulnerability types. In this context, we investigate LLM-based augmentation for vulnerable functions, comparing controlled generation of new vulnerable samples with semantics-preserving refactoring of existing ones. Using Qwen2.5-Coder to produce augmented data and CodeBERT as a classifier on the SVEN dataset, we find that our approaches are indeed effective in enriching vulnerable code-bases through a simple process and with reasonable quality, and that a hybrid strategy best boosts vulnerability classifiers' performance. Code repository is available here : https://github.com/DynaSoumhaneOuchebara/LLM-based-code-augmentation-Generate-or-Refactor-

Citations

Related