{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T16:23:20Z","timestamp":1784564600551,"version":"3.55.0"},"reference-count":133,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2025,5,27]],"date-time":"2025-05-27T00:00:00Z","timestamp":1748304000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001321","name":"National Research Foundation","doi-asserted-by":"crossref","award":["NRF-NRFI08-2022-0002"],"award-info":[{"award-number":["NRF-NRFI08-2022-0002"]}],"id":[{"id":"10.13039\/501100001321","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2025,6,30]]},"abstract":"<jats:p>The significant advancements in Large Language Models (LLMs) have resulted in their widespread adoption across various tasks within Software Engineering (SE), including vulnerability detection and repair. Numerous studies have investigated the application of LLMs to enhance vulnerability detection and repair tasks. Despite the increasing research interest, there is currently no existing survey that focuses on the utilization of LLMs for vulnerability detection and repair. In this paper, we aim to bridge this gap by offering a systematic literature review of approaches aimed at improving vulnerability detection and repair through the utilization of LLMs. The review encompasses research work from leading SE, AI, and Security conferences and journals, encompassing 43 papers published across 25 distinct venues, along with 15 high-quality preprint papers, bringing the total to 58 papers. By answering three key research questions, we aim to (1) summarize the LLMs employed in the relevant literature, (2) categorize various LLM adaptation techniques in vulnerability detection, and (3) classify various LLM adaptation techniques in vulnerability repair. Based on our findings, we have identified a series of limitations of existing studies. Additionally, we have outlined a roadmap highlighting potential opportunities that we believe are pertinent and crucial for future research endeavors.<\/jats:p>","DOI":"10.1145\/3708522","type":"journal-article","created":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T12:05:27Z","timestamp":1734523527000},"page":"1-31","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":101,"title":["Large Language Model for Vulnerability Detection and Repair: Literature Review and the Road Ahead"],"prefix":"10.1145","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4558-0622","authenticated-orcid":false,"given":"Xin","family":"Zhou","sequence":"first","affiliation":[{"name":"School of Computing and Information Systems, Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3688-4437","authenticated-orcid":false,"given":"Sicong","family":"Cao","sequence":"additional","affiliation":[{"name":"Yangzhou University, Yangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5165-5080","authenticated-orcid":false,"given":"Xiaobing","family":"Sun","sequence":"additional","affiliation":[{"name":"Yangzhou University, Yangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4367-7201","authenticated-orcid":false,"given":"David","family":"Lo","sequence":"additional","affiliation":[{"name":"School of Computing and Information Systems, Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,5,27]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"ACM Digital Library. Retrieved from https:\/\/dl.acm.org"},{"key":"e_1_3_2_3_2","unstructured":"arXiv Database. Retrieved from https:\/\/arxiv.org"},{"key":"e_1_3_2_4_2","unstructured":"IEEE Xplore Database. Retrieved from https:\/\/ieeexplore.ieee.org"},{"key":"e_1_3_2_5_2","unstructured":"ScienceDirect Database. Retrieved from https:\/\/www.sciencedirect.com"},{"key":"e_1_3_2_6_2","unstructured":"SpringerLink Database. Retrieved from https:\/\/link.springer.com"},{"key":"e_1_3_2_7_2","unstructured":"Web of Science Database. Retrieved from https:\/\/www.webofscience.com"},{"key":"e_1_3_2_8_2","unstructured":"Wiely Database. Retrieved from https:\/\/onlinelibrary.wiley.com"},{"key":"e_1_3_2_9_2","unstructured":"Online Appendix for This Review. 2024. Retrieved from https:\/\/docs.google.com\/document\/d\/18-UrkfH35CNMGRjjsDYZGK6L1aC9wP3GsKCtrIekcUQ\/edit?usp=sharing"},{"key":"e_1_3_2_10_2","unstructured":"Baleegh Ahmad Shailja Thakur Benjamin Tan Ramesh Karri and Hammond Pearce. 2023. Fixing hardware security bugs with large language models. arXiv:2302.01215. Retrieved from https:\/\/arxiv.org\/abs\/2302.01215"},{"key":"e_1_3_2_11_2","doi-asserted-by":"crossref","unstructured":"Wasi Uddin Ahmad Saikat Chakraborty Baishakhi Ray and Kai-Wei Chang. 2021. Unified pre-training for program understanding and generation. arXiv:2103.06333. Retrieved from https:\/\/arxiv.org\/abs\/2103.06333","DOI":"10.18653\/v1\/2021.naacl-main.211"},{"key":"e_1_3_2_12_2","unstructured":"Akari Asai Zeqiu Wu Yizhong Wang Avirup Sil and Hannaneh Hajishirzi. 2023. Self-rag: Learning to retrieve generate and critique through self-reflection. arXiv:2310.11511. Retrieved from https:\/\/arxiv.org\/abs\/2310.11511"},{"key":"e_1_3_2_13_2","unstructured":"Berkay Berabi Alexey Gronskiy Veselin Raychev Gishor Sivanrupan Victor Chibotaru and Martin T. Vechev. 2024. DeepCode AI fix: Fixing security vulnerabilities with large language models. arXiv:2402.13291. Retrieved from https:\/\/arxiv.org\/abs\/2402.13291"},{"key":"e_1_3_2_14_2","first-page":"1877","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","author":"Brown Tom","year":"2020","unstructured":"Tom Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared D Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, et al. 2020. Language models are few-shot learners. In Proceedings of the International Conference on Neural Information Processing Systems, 1877\u20131901."},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549162"},{"key":"e_1_3_2_16_2","unstructured":"Mark Chen Jerry Tworek Heewoo Jun Qiming Yuan Henrique Ponde de Oliveira Pinto Jared Kaplan Harri Edwards Yuri Burda Nicholas Joseph Greg Brockman et al. 2021. Evaluating large language models trained on code. arXiv:2107.03374. Retrieved from https:\/\/arxiv.org\/abs\/2107.03374"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607242"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3147265"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3156637"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00022"},{"key":"e_1_3_2_21_2","unstructured":"Jacob Devlin Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv:1810.04805. Retrieved from https:\/\/arxiv.org\/abs\/1810.04805"},{"key":"e_1_3_2_22_2","unstructured":"Yangruibo Ding Yanjun Fu Omniyyah Ibrahim Chawin Sitawarin Xinyun Chen Basel Alomair David A. Wagner Baishakhi Ray and Yizheng Chen. 2024. Vulnerability detection with code language models: How far are we? arXiv:2403.18624. Retrieved from https:\/\/arxiv.org\/abs\/2403.18624"},{"key":"e_1_3_2_23_2","unstructured":"Xueying Du Geng Zheng Kaixin Wang Jiayi Feng Wentai Deng Mingwei Liu Bihuan Chen Xin Peng Tao Ma and Yiling Lou. 2024. Vul-RAG: Enhancing LLM-based vulnerability detection via knowledge-level RAG. arXiv:2406.11147. Retrieved from https:\/\/arxiv.org\/abs\/2406.11147"},{"key":"e_1_3_2_24_2","doi-asserted-by":"crossref","unstructured":"Zhangyin Feng Daya Guo Duyu Tang Nan Duan Xiaocheng Feng Ming Gong Linjun Shou Bing Qin Ting Liu Daxin Jiang et al. 2020. Codebert: A pre-trained model for programming and natural languages. arXiv:2002.08155. Retrieved from https:\/\/arxiv.org\/abs\/2002.08155","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"e_1_3_2_25_2","volume-title":"Proceedings of the 11th International Conference on Learning Representations (ICLR \u201923)","author":"Fried Daniel","year":"2023","unstructured":"Daniel Fried, Armen Aghajanyan, Jessy Lin, Sida Wang, Eric Wallace, Freda Shi, Ruiqi Zhong, Scott Yih, Luke Zettlemoyer, and Mike Lewis. 2023. InCoder: A generative model for code infilling and synthesis. In Proceedings of the 11th International Conference on Learning Representations (ICLR \u201923). OpenReview.Net. Retrieved from https:\/\/openreview.net\/pdf?id=hQwb-lbM6EL"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3632746"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528452"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1007\/S10664-023-10346-3"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"e_1_3_2_30_2","volume-title":"ChatGPT for Vulnerability Detection, Classification, and Repair: How Far Are We?","author":"Fu Michael","year":"2023","unstructured":"Michael Fu, Chakkrit Tantithamthavorn, Van Nguyen, and Trung Le. 2023. ChatGPT for Vulnerability Detection, Classification, and Repair: How Far Are We? APSEC."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3092566"},{"key":"e_1_3_2_32_2","unstructured":"GitHub. 2023. GitHub Copilot. Retrieved from https:\/\/copilot.github.com"},{"key":"e_1_3_2_33_2","first-page":"7212","volume-title":"Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (ACL)","author":"Guo Daya","year":"2022","unstructured":"Daya Guo, Shuai Lu, Nan Duan, Yanlin Wang, Ming Zhou, and Jian Yin. 2022. UniXcoder: Unified cross-modal pre-training for code representation. In Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (ACL). ACL, 7212\u20137225."},{"key":"e_1_3_2_34_2","unstructured":"Daya Guo Shuo Ren Shuai Lu Zhangyin Feng Duyu Tang Shujie Liu Long Zhou Nan Duan Alexey Svyatkovskiy Shengyu Fu et al. 2020. Graphcodebert: Pre-training code representations with data flow. arXiv:2009.08366. Retrieved from https:\/\/arxiv.org\/abs\/2009.08366"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN55064.2022.9892280"},{"key":"e_1_3_2_36_2","first-page":"1865","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"He Jingxuan","year":"2023","unstructured":"Jingxuan He and Martin Vechev. 2023. Large language models for code: Security hardening and adversarial testing. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 1865\u20131879."},{"issue":"3","key":"e_1_3_2_37_2","first-page":"1","article-title":"Representation learning for stack overflow posts: How far are we?","volume":"33","author":"He Junda","year":"2023","unstructured":"Junda He, Xin Zhou, Bowen Xu, Ting Zhang, Kisub Kim, Zhou Yang, Ferdian Thung, Ivana Clairine Irsan, and David Lo. 2023. Representation learning for stack overflow posts: How far are we? ACM Transactions on Software Engineering and Methodology 33, 3, Article 69 (2023), 1\u201314.","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"e_1_3_2_38_2","unstructured":"Xinying Hou Yanjie Zhao Yue Liu Zhou Yang Kailong Wang Li Li Xiapu Luo David Lo John C. Grundy and Haoyu Wang. 2023. Large Language Models for Software Engineering: A Systematic Literature Review. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:261048648"},{"key":"e_1_3_2_39_2","unstructured":"Nafis Tanveer Islam Joseph Khoury Andrew Seong Gonzalo De La Torre Parra Elias Bou-Harb and Peyman Najafirad. 2024. LLM-powered code vulnerability repair with reinforcement learning and semantic reward. arXiv:2401.03374. Retrieved from https:\/\/arxiv.org\/abs\/2401.03374"},{"key":"e_1_3_2_40_2","volume-title":"Proceedings of the AAAI Workshop","author":"Islam Nafis Tanveer","year":"2024","unstructured":"Nafis Tanveer Islam and Peyman Najafirad. 2024. Code security vulnerability repair using reinforcement learning with large language models. In Proceedings of the AAAI Workshop."},{"key":"e_1_3_2_41_2","unstructured":"Minhao Jiang Ken Ziyu Liu Ming Zhong Rylan Schaeffer Siru Ouyang Jiawei Han and Sanmi Koyejo. 2024. Investigating data contamination for pre-training language models. arxiv:2401.06059."},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3671016.3671388"},{"key":"e_1_3_2_43_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Kanade Aditya","year":"2019","unstructured":"Aditya Kanade, Petros Maniatis, Gogul Balakrishnan, and Kensen Shi. 2019. Learning and evaluating contextual embedding of source code. In Proceedings of the International Conference on Machine Learning. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:220425306"},{"key":"e_1_3_2_44_2","unstructured":"Avishree Khare Saikat Dutta Ziyang Li Alaia Solko-Breslin Rajeev Alur and Mayur Naik. 2023. Understanding the effectiveness of large language models in detecting security vulnerabilities. arXiv: 2311.16169. Retrieved from https:\/\/arxiv.org\/abs\/2311.16169"},{"key":"e_1_3_2_45_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems (NeurIPS \u201922)","author":"Kojima Takeshi","year":"2022","unstructured":"Takeshi Kojima, Shixiang Shane Gu, Machel Reid, Yutaka Matsuo, and Yusuke Iwasawa. 2022. Large language models are zero-shot reasoners. In Proceedings of the International Conference on Neural Information Processing Systems (NeurIPS \u201922). Sanmi Koyejo, S. Mohamed, A. Agarwal, Danielle Belgrave, K. Cho, and A. Oh (Eds.), Retrieved from http:\/\/papers.nips.cc\/paper_files\/paper\/2022\/hash\/8bb0d291acd4acf06ef112099c16f326-Abstract-Conference.html"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM59687.2023.00024"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3643991.3644919"},{"key":"e_1_3_2_48_2","volume-title":"Proceedings of the Annual Conference on Neural Information Processing Systems (NeurIPS \u201920)","author":"Lewis Patrick S. H.","year":"2020","unstructured":"Patrick S. H. Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni, Vladimir Karpukhin, Naman Goyal, Heinrich K\u00fcttler, Mike Lewis, Wen-tau Yih, Tim Rockt\u00e4schel, et al. 2020. Retrieval-augmented generation for knowledge-intensive NLP tasks. In Proceedings of the Annual Conference on Neural Information Processing Systems (NeurIPS \u201920). Hugo Larochelle, Marc\u2019Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.), Retrieved from https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/6b493230205f780e1bc26945df7481e5-Abstract.html"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616262"},{"key":"e_1_3_2_50_2","unstructured":"Raymond Li Loubna Ben Allal Yangtian Zi Niklas Muennighoff Denis Kocetkov Chenghao Mou Marc Marone Christopher Akiki Jia Li Jenny Chim et al. 2023. StarCoder: May the Source Be with You! Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:258588247"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639218"},{"key":"e_1_3_2_52_2","volume-title":"Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE)","author":"Li Zhen","year":"2024","unstructured":"Zhen Li, Ning Wang, Deqing Zou, Yating Li, Ruqian Zhang, Shouhuai Xu, Chao Zhang, and Hai Jin. 2024. On the effectiveness of function-level vulnerability detectors for inter-procedural vulnerabilities. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE)."},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3608128"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.2993293"},{"key":"e_1_3_2_55_2","unstructured":"Yinhan Liu Myle Ott Naman Goyal Jingfei Du Mandar Joshi Danqi Chen Omer Levy Mike Lewis Luke Zettlemoyer and Veselin Stoyanov. 2019. Roberta: A robustly optimized bert pretraining approach. arXiv:1907.11692. Retrieved from https:\/\/arxiv.org\/abs\/1907.11692"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSC59305.2023.00041"},{"key":"e_1_3_2_57_2","volume-title":"Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE)","author":"Liu Zhongxin","year":"2024","unstructured":"Zhongxin Liu, Zhijie Tang, Junwei Zhang, Xin Xia, and Xiaohu Yang. 2024. Pre-training by predicting program dependencies for vulnerability analysis tasks. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE)."},{"key":"e_1_3_2_58_2","unstructured":"David Lo. 2023. Trustworthy and synergistic artificial intelligence for software engineering: Vision and roadmaps. arXiv:2309.04142. Retrieved from https:\/\/arxiv.org\/abs\/2309.04142"},{"key":"e_1_3_2_59_2","unstructured":"Shuai Lu Daya Guo Shuo Ren Junjie Huang Alexey Svyatkovskiy Ambrosio Blanco Colin Clement Dawn Drain Daxin Jiang Duyu Tang et al. 2021. Codexglue: A machine learning benchmark dataset for code understanding and generation. arXiv:2102.04664. Retrieved from https:\/\/arxiv.org\/abs\/2102.04664"},{"key":"e_1_3_2_60_2","volume-title":"Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE)","author":"Rahman Md Mahbubur","year":"2024","unstructured":"Md Mahbubur Rahman, Ira Ceka, Chengzhi Mao, Saikat Chakraborty, Baishakhi Ray, and Wei Le. 2024. Towards causal deep learning for vulnerability detection. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE)."},{"key":"e_1_3_2_61_2","unstructured":"Meta. 2023. Code llama: Open Foundation Models for Code. Retrieved from https:\/\/ai.meta.com\/research\/publications\/code-llama-open-foundation-models-for-code\/"},{"key":"e_1_3_2_62_2","unstructured":"Microsoft. 2024. Microsoft Copilot for Security. Retrieved from https:\/\/microsoft.github.io\/PartnerResources\/skilling\/microsoft-security-academy\/microsoft-security-copilot"},{"key":"e_1_3_2_63_2","unstructured":"Shervin Minaee Tomas Mikolov Narjes Nikzad Meysam Chenaghlu Richard Socher Xavier Amatriain and Jianfeng Gao. 2024. Large language models: A survey. arxiv:2402.06196. Retrieved from https:\/\/arxiv.org\/abs\/2402.06196"},{"key":"e_1_3_2_64_2","unstructured":"Chao Ni Liyu Shen Xiaodan Xu Xin Yin and Shaohua Wang. 2024. Learning-based models for vulnerability detection: An extensive study. arXiv:2408.07526. Retrieved from https:\/\/arxiv.org\/abs\/2408.07526"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616358"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598037"},{"key":"e_1_3_2_67_2","unstructured":"Erik Nijkamp Hiroaki Hayashi Caiming Xiong Silvio Savarese and Yingbo Zhou. 2023. CodeGen2: Lessons for training LLMs on programming and natural languages. arXiv:2305.02309. Retrieved from https:\/\/arxiv.org\/abs\/2305.02309"},{"key":"e_1_3_2_68_2","unstructured":"Erik Nijkamp Hiroaki Hayashi Caiming Xiong Silvio Savarese and Yingbo Zhou. 2023. Codegen2: Lessons for training llms on programming and natural languages. arXiv:2305.02309. Retrieved from https:\/\/arxiv.org\/abs\/2305.02309"},{"key":"e_1_3_2_69_2","volume-title":"Proceedings of the 11th International Conference on Learning Representations (ICLR \u201923)","author":"Nijkamp Erik","year":"2023","unstructured":"Erik Nijkamp, Bo Pang, Hiroaki Hayashi, Lifu Tu, Huan Wang, Yingbo Zhou, Silvio Savarese, and Caiming Xiong. 2023. CodeGen: An open large language model for code with multi-turn program synthesis. In Proceedings of the 11th International Conference on Learning Representations (ICLR \u201923). OpenReview.Net. Retrieved from https:\/\/openreview.net\/pdf?id=iaYcJKpY2B_"},{"key":"e_1_3_2_70_2","unstructured":"Yu Nong Mohammed Aldeen Long Cheng Hongxin Hu Feng Chen and Haipeng Cai. 2024. Chain-of-thought prompting of large language models for discovering and fixing software vulnerabilities. arXiv:2402.17230. Retrieved from https:\/\/arxiv.org\/abs\/2402.17230"},{"key":"e_1_3_2_71_2","unstructured":"Yu Nong Haoran Yang Long Cheng Hongxin Hu and Haipeng Cai. 2024b. Automated software vulnerability patching using large language models. arXiv:2408.13597. Retrieved from https:\/\/arxiv.org\/abs\/2408.13597"},{"key":"e_1_3_2_72_2","unstructured":"OpenAI. 2022. GPT-3.5. Retrieved from https:\/\/platform.openai.com\/docs\/models\/gpt-3-5"},{"key":"e_1_3_2_73_2","unstructured":"OpenAI. 2023. GPT-4 technical report. arXiv:2303.08774. Retrieved from https:\/\/arxiv.org\/abs\/2303.08774"},{"key":"e_1_3_2_74_2","unstructured":"Shirui Pan Linhao Luo Yufei Wang Chen Chen Jiapu Wang and Xindong Wu. 2023. Unifying large language models and knowledge graphs: A roadmap. arXiv:2306.08302. Retrieved from https:\/\/arxiv.org\/abs\/2306.08302"},{"key":"e_1_3_2_75_2","first-page":"2339","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP)","author":"Pearce Hammond","year":"2023","unstructured":"Hammond Pearce, Benjamin Tan, Baleegh Ahmad, Ramesh Karri, and Brendan Dolan-Gavitt. 2023. Examining zero-shot vulnerability repair with large language models. In Proceedings of the IEEE Symposium on Security and Privacy (SP). IEEE, 2339\u20132356."},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM59687.2023.00026"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW60843.2023.00058"},{"key":"e_1_3_2_78_2","unstructured":"Yujia Qin Shihao Liang Yining Ye Kunlun Zhu Lan Yan Yaxi Lu Yankai Lin Xin Cong Xiangru Tang Bill Qian Sihan Zhao Lauren Hong Runchu Tian Ruobing Xie Jie Zhou Mark Gerstein Dahai Li Zhiyuan Liu and Maosong Sun. 2023. ToolLLM: Facilitating large language models to master 16000+ real-world APIs. arXiv:2307.16789. Retrieved from https:\/\/arxiv.org\/abs\/2307.16789"},{"issue":"8","key":"e_1_3_2_79_2","first-page":"9","article-title":"Language models are unsupervised multitask learners","volume":"1","author":"Radford Alec","year":"2019","unstructured":"Alec Radford, Jeffrey Wu, Rewon Child, David Luan, Dario Amodei, Ilya Sutskever, et al. 2019. Language models are unsupervised multitask learners. OpenAI Blog 1, 8 (2019), 9.","journal-title":"OpenAI Blog"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.5555\/3455716.3455856"},{"key":"e_1_3_2_81_2","unstructured":"Shuo Ren Daya Guo Shuai Lu Long Zhou Shujie Liu Duyu Tang Neel Sundaresan Ming Zhou Ambrosio Blanco and Shuai Ma. 2020. CodeBLEU: A method for automatic evaluation of code synthesis. arXiv:2009.10297. Retrieved from https:\/\/arxiv.org\/abs\/2009.10297"},{"key":"e_1_3_2_82_2","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security \u201924)USENIX Association","author":"Risse Niklas","year":"2024","unstructured":"Niklas Risse and Marcel B\u00f6hme. 2024. Uncovering the limits of machine learning for automatic vulnerability detection. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security \u201924). Davide Balzarotti and Wenyuan Xu (Eds.), USENIX Association. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/risse"},{"key":"e_1_3_2_83_2","unstructured":"John Schulman Filip Wolski Prafulla Dhariwal Alec Radford and Oleg Klimov. 2017. Proximal policy optimization algorithms. arXiv:1707.06347. Retrieved from https:\/\/arxiv.org\/abs\/1707.06347"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3608141"},{"key":"e_1_3_2_85_2","first-page":"1","volume-title":"Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering","author":"Sejfia Adriana","year":"2024","unstructured":"Adriana Sejfia, Satyaki Das, Saad Shafiq, and Nenad Medvidovi\u0107. 2024. Toward improved deep learning-based vulnerability detection. In Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, 1\u201312."},{"issue":"3","key":"e_1_3_2_86_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2187671.2187673","article-title":"Mitigating program security vulnerabilities: Approaches and challenges","volume":"44","author":"Shahriar Hossain","year":"2012","unstructured":"Hossain Shahriar and Mohammad Zulkernine. 2012. Mitigating program security vulnerabilities: Approaches and challenges. ACM Computing Surveys 44, 3 (2012), 1\u201346.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_2_87_2","doi-asserted-by":"crossref","unstructured":"Zhihong Shao Yeyun Gong Yelong Shen Minlie Huang Nan Duan and Weizhu Chen. 2023. Enhancing retrieval-augmented large language models with iterative retrieval-generation synergy. arXiv:2305.15294. Retrieved from https:\/\/arxiv.org\/abs\/2305.15294","DOI":"10.18653\/v1\/2023.findings-emnlp.620"},{"key":"e_1_3_2_88_2","unstructured":"Alexey Shestov Anton Cheshkov Rodion Levichev Ravil Mussabayev Pavel Zadorozhny Evgeny Maslov Chibirev Vadim and Egor Bulychev. 2024. Finetuning large language models for vulnerability detection. arXiv:2401.17010. Retrieved from https:\/\/arxiv.org\/abs\/2401.17010"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00188"},{"key":"e_1_3_2_90_2","unstructured":"Benjamin Steenhoek Md Mahbubur Rahman Shaila Sharmin and Wei Le. 2023. Do language models Learn semantics of code? A case study in vulnerability detection. arXiv:2311.04109. Retrieved from https:\/\/arxiv.org\/abs\/2311.04109"},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.443"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1016\/J.JSS.2023.111623"},{"key":"e_1_3_2_93_2","unstructured":"Edward Targett. 2022. We analysed 90 000+ Software Vulnerabilities: Here's What We Learned. Retrieved from https:\/\/www.thestack.technology\/analysis-of-cves-in-2022-software-vulnerabilities-cwes-most-dangerous\/"},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567985"},{"issue":"4","key":"e_1_3_2_95_2","first-page":"107504","article-title":"DetectVul: A statement-level code vulnerability detection for Python","volume":"163","author":"Tran Hoai-Chau","year":"2024","unstructured":"Hoai-Chau Tran, Anh-Duy Tran, and Kim-Hung Le. 2024. DetectVul: A statement-level code vulnerability detection for Python. Future Generation Computer Systems 163, 4 (2024), 107504.","journal-title":"Future Generation Computer Systems"},{"key":"e_1_3_2_96_2","doi-asserted-by":"crossref","unstructured":"Harsh Trivedi Niranjan Balasubramanian Tushar Khot and Ashish Sabharwal. 2022. Interleaving retrieval with chain-of-thought reasoning for knowledge-intensive multi-step questions. arXiv:2212.10509. Retrieved from https:\/\/arxiv.org\/abs\/2212.10509","DOI":"10.18653\/v1\/2023.acl-long.557"},{"key":"e_1_3_2_97_2","volume-title":"Proceedings of the International Conference on Neural Information Processing Systems","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, Lukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. In Proceedings of the International Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_98_2","unstructured":"Vicarius. 2023. Vuln \\(\\_\\) GPT debuts as AI-powered approach to find and remediate software vulnerabilities. Retrieved from https:\/\/venturebeat.com\/ai\/got-vulns-vuln_gpt-debuts-as-ai-powered-approach-to-find-and-remediate-software-vulnerabilities\/"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639212"},{"key":"e_1_3_2_100_2","unstructured":"Junjie Wang Yuchao Huang Chunyang Chen Zhe Liu Song Wang and Qing Wang. 2023. Software testing with large language model: Survey landscape and vision. arXiv:2307.07221. Retrieved from https:\/\/arxiv.org\/abs\/2307.07221"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-024-40231-1"},{"key":"e_1_3_2_102_2","unstructured":"Ruoke Wang Zongjie Li Chaozheng Wang Yang Xiao and Cuiyun Gao. 2024. NAVRepair: Node-type aware C\/C \\(++\\) code vulnerability repair. arXiv:2405.04994. Retrieved from https:\/\/arxiv.org\/abs\/2405.04994"},{"key":"e_1_3_2_103_2","doi-asserted-by":"crossref","unstructured":"Yue Wang Weishi Wang Shafiq Joty and Steven CH Hoi. 2021. Codet5: Identifier-aware unified pre-trained encoder-decoder models for code understanding and generation. arXiv:2109.00859. Retrieved from https:\/\/arxiv.org\/abs\/2109.00859","DOI":"10.18653\/v1\/2021.emnlp-main.685"},{"key":"e_1_3_2_104_2","first-page":"34","article-title":"VulRep: Vulnerability repair based on inducing commits and fixing commits","volume":"1","author":"Wei Ying","year":"2023","unstructured":"Ying Wei, Lili Bo, Xiaoxue Wu, Yue Li, Zhenlei Ye, Xiaobing Sun, and Bin Li. 2023. VulRep: Vulnerability repair based on inducing commits and fixing commits. EURASIP Journal on Wireless Communications and Networking 2023, 1 (2023), 34.","journal-title":"EURASIP Journal on Wireless Communications and Networking"},{"key":"e_1_3_2_105_2","unstructured":"Xin-Cheng Wen Xinchen Wang Yujia Chen Ruida Hu David Lo and Cuiyun Gao. 2024. VulEval: Towards repository-level evaluation of software vulnerability detection. arXiv:2404.15596. Retrieved from https:\/\/arxiv.org\/abs\/2404.15596"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00144"},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1145\/3671016.3674807"},{"key":"e_1_3_2_108_2","first-page":"38:1","volume-title":"Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering (EASE)","author":"Wohlin Claes","year":"2014","unstructured":"Claes Wohlin. 2014. Guidelines for snowballing in systematic literature studies and a replication in software engineering. In Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering (EASE). ACM, New York, NY, 38:1\u201338:10."},{"key":"e_1_3_2_109_2","first-page":"1282","article-title":"Code vulnerability detection based on deep sequence and graph models: A survey","volume":"2022","author":"Wu Bolun","year":"2022","unstructured":"Bolun Wu, Futai Zou, et al. 2022. Code vulnerability detection based on deep sequence and graph models: A survey. Security and Communication Networks 2022 (2022), 1282\u20131294.","journal-title":"Security and Communication Networks"},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598135"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1145\/3520312.3534862"},{"key":"e_1_3_2_112_2","unstructured":"Fabian Yamaguchi. 2023. Joern: A Source Code Analysis Tool. Retrieved from https:\/\/github.com\/octopus-platform\/joern."},{"key":"e_1_3_2_113_2","unstructured":"Aidan ZH Yang Haoye Tian He Ye Ruben Martins and Claire Le Goues. 2024. Security vulnerability detection with multitask self-instructed fine-tuning of large language models. arXiv:2406.05892. Retrieved from https:\/\/arxiv.org\/abs\/2406.05892"},{"key":"e_1_3_2_114_2","doi-asserted-by":"publisher","DOI":"10.1145\/3649506"},{"key":"e_1_3_2_115_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00192"},{"key":"e_1_3_2_116_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510146"},{"key":"e_1_3_2_117_2","unstructured":"Xin Yin. 2024. Pros and cons! Evaluating ChatGPT on software vulnerability. arXiv:2404.03994. Retrieved from https:\/\/arxiv.org\/abs\/2404.03994"},{"key":"e_1_3_2_118_2","doi-asserted-by":"publisher","DOI":"10.18293\/SEKE2023-077"},{"key":"e_1_3_2_119_2","unstructured":"Chenyuan Zhang Hao Liu Jiutian Zeng Kejing Yang Yuhong Li and Hui Li. 2023. Prompt-enhanced software vulnerability detection using ChatGPT. arXiv:2308.12697. Retrieved from https:\/\/arxiv.org\/abs\/2308.12697"},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2010.12.010"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2023.3286586"},{"issue":"2","key":"e_1_3_2_122_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3631974","article-title":"A survey of learning-based automated program repair","volume":"33","author":"Zhang Quanjun","year":"2023","unstructured":"Quanjun Zhang, Chunrong Fang, Yuxiang Ma, Weisong Sun, and Zhenyu Chen. 2023. A survey of learning-based automated program repair. ACM Transactions on Software Engineering and Methodology 33, 2 (2023), 1\u201369.","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"e_1_3_2_123_2","unstructured":"Quanjun Zhang Chunrong Fang Yang Xie Yaxin Zhang Yun Yang Weisong Sun Shengcheng Yu and Zhenyu Chen. 2023. A survey on large language models for software engineering. arXiv:2312.15223. Retrieved from https:\/\/arxiv.org\/abs\/2312.15223"},{"key":"e_1_3_2_124_2","article-title":"Pre-trained model-based automated software vulnerability repair: How far are we?","author":"Zhang Quanjun","year":"2023","unstructured":"Quanjun Zhang, Chunrong Fang, Bowen Yu, Weisong Sun, Tongke Zhang, and Zhenyu Chen. 2023d. Pre-trained model-based automated software vulnerability repair: How far are we? IEEE Transactions on Dependable and Secure Computing (2023).","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_125_2","volume-title":"Proceedings of the 8th International Conference on Learning Representations (ICLR \u201920)","author":"Zhang Tianyi","year":"2020","unstructured":"Tianyi Zhang, Varsha Kishore, Felix Wu, Kilian Q. Weinberger, and Yoav Artzi. 2020. BERTScore: Evaluating text generation with BERT. In Proceedings of the 8th International Conference on Learning Representations (ICLR \u201920). OpenReview.net. Retrieved from https:\/\/openreview.net\/forum?id=SkeHuCVFDr"},{"key":"e_1_3_2_126_2","unstructured":"Ziyin Zhang Chaoyu Chen Bingchang Liu Cong Liao Zi Gong Hang Yu Jianguo Li and Rui Wang. 2023. Unifying the perspectives of NLP and software engineering: A survey on language models for code. arXiv:2311.07989. Retrieved from https:\/\/arxiv.org\/abs\/2311.07989"},{"key":"e_1_3_2_127_2","unstructured":"Wayne Xin Zhao Kun Zhou Junyi Li Tianyi Tang Xiaolei Wang Yupeng Hou Yingqian Min Beichen Zhang Junjie Zhang Zican Dong et al. 2023. A survey of large language models. arXiv:2303.18223. Retrieved from https:\/\/arxiv.org\/abs\/2303.18223"},{"key":"e_1_3_2_128_2","first-page":"872","volume-title":"Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE)","author":"Zhou Xin","year":"2024","unstructured":"Xin Zhou, Kisub Kim, Bowen Xu, DongGyun Han, and David Lo. 2024. Out of sight, out of mind: Better automatic vulnerability repair by broadening input ranges and sources. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE). IEEE Computer Society, 872\u2013872."},{"key":"e_1_3_2_129_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00157"},{"key":"e_1_3_2_130_2","unstructured":"Xin Zhou Duc-Manh Tran Thanh Le-Cong Ting Zhang Ivana Clairine Irsan Joshua Sumarlin Bach Le and David Lo. 2024. Comparison of static application security testing tools and large language models for repo-level vulnerability detection. arXiv:2407.16235. Retrieved from https:\/\/arxiv.org\/abs\/2407.16235"},{"key":"e_1_3_2_131_2","first-page":"182","volume-title":"Proceedings of the IEEE International Conference on Software Maintenance and Evolution (ICSME)","author":"Zhou Xin","year":"2023","unstructured":"Xin Zhou, Bowen Xu, DongGyun Han, Zhou Yang, Junda He, and David Lo. 2023. CCBERT: Self-supervised code change representation learning. In Proceedings of the IEEE International Conference on Software Maintenance and Evolution (ICSME). IEEE, 182\u2013193."},{"key":"e_1_3_2_132_2","doi-asserted-by":"publisher","DOI":"10.1145\/3639476.3639762"},{"issue":"7","key":"e_1_3_2_133_2","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1007\/s10664-022-10216-4","article-title":"SPVF: Security property assisted vulnerability fixing via attention-based models","volume":"27","author":"Zhou Zhou","year":"2022","unstructured":"Zhou Zhou, Lili Bo, Xiaoxue Wu, Xiaobing Sun, Tao Zhang, Bin Li, Jiale Zhang, and Sicong Cao. 2022. SPVF: Security property assisted vulnerability fixing via attention-based models. Empirical Software Engineering 27, 7 (2022), 171.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_134_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOMWKSHPS51825.2021.9484500"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708522","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708522","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:17:45Z","timestamp":1750295865000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708522"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,27]]},"references-count":133,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,6,30]]}},"alternative-id":["10.1145\/3708522"],"URL":"https:\/\/doi.org\/10.1145\/3708522","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,27]]},"assertion":[{"value":"2024-04-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-19","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}