{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T14:11:22Z","timestamp":1779977482303,"version":"3.53.1"},"reference-count":28,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T00:00:00Z","timestamp":1779926400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2026,6,1]]},"abstract":"<jats:p>\n                    Cybersecurity plays a pivotal role in safeguarding the integrity and reliability of critical systems\u2014spanning healthcare, commerce, transportation, and power infrastructure. Yet software security teams are often critically underfunded and understaffed, given the breadth and complexity of our software infrastructure. Recently, large language models (LLMs) have proven to be a transformative technology that is reshaping how we interact with software. In this article, we explore how LLMs can be leveraged to holistically address longstanding challenges in cybersecurity. We start with a discussion on the structure of a\n                    <jats:italic toggle=\"yes\">cyber reasoning system<\/jats:italic>\n                    \u00a0(CRS) that can both detect and repair vulnerabilities in software\n                    <jats:italic toggle=\"yes\">autonomously<\/jats:italic>\n                    . We follow up by examining LLMs\u2019 strengths in aiding program analysis within such a system, finding that LLM-assisted analyses can accomplish several difficult analysis tasks, such as extrapolating developer intent, filtering or augmenting the output of traditional analysis tools, or even solving complex multilingual constraints. Lastly, we discuss the current challenges and limitations in constructing a composite system that can leverage these components. We hope this article can provide insights into the evolving role of LLMs and inspiration in shaping the future of software security.\n                  <\/jats:p>","DOI":"10.1145\/3770922","type":"journal-article","created":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T20:27:26Z","timestamp":1778617646000},"page":"60-67","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Large Language Models in Software Security Analysis"],"prefix":"10.1145","volume":"69","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6958-7159","authenticated-orcid":false,"given":"Dylan","family":"Wolff","sequence":"first","affiliation":[{"name":"National University of Singapore, School of Computing, Singapore, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9145-964X","authenticated-orcid":false,"given":"Martin","family":"Mirchev","sequence":"additional","affiliation":[{"name":"National University of Singapore, School of Computing, Singapore, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7127-1137","authenticated-orcid":false,"given":"Abhik","family":"Roychoudhury","sequence":"additional","affiliation":[{"name":"National University of Singapore, School of Computing, Singapore, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,28]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"crossref","unstructured":"Aschermann C. et al. NAUTILUS: fishing for deep bugs with grammars. In NDSS\u00a0(2019).","DOI":"10.14722\/ndss.2019.23412"},{"key":"e_1_3_1_3_2","unstructured":"Austin J. et al. Program synthesis with large language models. arXiv:2108.07732 (2021); https:\/\/arxiv.org\/abs\/2108.07732"},{"key":"e_1_3_1_4_2","first-page":"1877","article-title":"Language models are few-shot learners","volume":"33","author":"Brown T.","year":"2020","unstructured":"Brown, T. et al. Language models are few-shot learners. Advances in Neural Information Processing Systems 33 (2020), 1877\u20131901.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2017.2785841"},{"key":"e_1_3_1_6_2","unstructured":"Carlini N. et al. Quantifying memorization across neural language models. In The Eleventh Intern. Conf. on Learning Representations (2022)."},{"key":"e_1_3_1_7_2","doi-asserted-by":"crossref","unstructured":"Fan Z. et al. Automated repair of programs from large language models. In 2023 IEEE\/ACM 45th Intern. Conf. on Software Engineering (2023) 1469\u20131481.","DOI":"10.1109\/ICSE48619.2023.00128"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560602"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3318162"},{"key":"e_1_3_1_10_2","unstructured":"Institute P. Costs and consequences of gaps in vulnerability response (2024); https:\/\/www.servicenow.com\/lpayr\/ponemon-vulnerability-survey.html"},{"key":"e_1_3_1_11_2","unstructured":"Jimenez C.E. et al. SWE-bench: can language models resolve real-world github issues? In The Twelfth Intern. Conf. on Learning Representations (2024)."},{"key":"e_1_3_1_12_2","doi-asserted-by":"crossref","unstructured":"Kang S. An G. and Yoo S. A quantitative and qualitative evaluation of LLM-based explainable fault localization. Proceedings of the ACM on Software Engineering 1 (Jul. 2024) 1424\u20131446.","DOI":"10.1145\/3660771"},{"key":"e_1_3_1_13_2","doi-asserted-by":"crossref","unstructured":"Legunsen O. et al. How good are the specs? A study of the bug-finding effectiveness of existing Java API specifications. In Proceedings of the 31st IEEE\/ACM Intern. Conf. on Automated Software Engineering (2016) 602\u2013613.","DOI":"10.1145\/2970276.2970356"},{"key":"e_1_3_1_14_2","doi-asserted-by":"crossref","unstructured":"Lemieux C. Inala J.P. Lahiri S.K. and Sen S. CodaMosa: Escaping coverage plateaus in test generation with pre-trained large language models. In Proceedings of the 45th Intern. Conf. on Software Engineering (2023) 919\u2013931.","DOI":"10.1109\/ICSE48619.2023.00085"},{"key":"e_1_3_1_15_2","first-page":"9459","article-title":"Retrieval-augmented generation for knowledge-intensive nlp tasks","volume":"33","author":"Lewis P.","year":"2020","unstructured":"Lewis, P. Retrieval-augmented generation for knowledge-intensive nlp tasks. Advances in Neural Information Processing Systems 33, (2020), 9459\u20139474.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","unstructured":"Li H. Hao Y. Zhai Y. and Qian Z. Enhancing static analysis for practical bug detection: an LLM-integrated approach. Proceedings of the ACM on Programming Languages 8 (2024) 474\u2013499.","DOI":"10.1145\/3649828"},{"key":"e_1_3_1_17_2","unstructured":"Liu D. Metzman J. Chang O. and Team G.O.S.S. AI-powered fuzzing: Breaking the bug hunting barrier. Google Security Blog; https:\/\/security.googleblog.com\/2023\/08\/ai-powered-fuzzing-breaking-bug-hunting.html"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2946563"},{"key":"e_1_3_1_19_2","doi-asserted-by":"crossref","unstructured":"Meng R. Mirchev M. B\u00f6hme M. and Roychoudhury A. Large language model guided protocol fuzzing. In Proceedings of the 31st Annual Network and Distributed System Security Symp. (2024).","DOI":"10.14722\/ndss.2024.24556"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"e_1_3_1_21_2","doi-asserted-by":"crossref","unstructured":"Nguyen H.D.T. Qi D. Roychoudhury A. and Chandra S. Semfix: Program repair via semantic analysis. In 2013 35th Intern. Conf. on Software Engineering (2013) 772\u2013781.","DOI":"10.1109\/ICSE.2013.6606623"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.5555\/3698900.3699138"},{"key":"e_1_3_1_23_2","doi-asserted-by":"crossref","unstructured":"Ruan H. Zhang Y. and Roychoudhury A. Specrover: Code intent extraction via LLMs. In Intern. Conf. on Software Engineering (2025).","DOI":"10.1109\/ICSE55347.2025.00080"},{"key":"e_1_3_1_24_2","unstructured":"Serebryany K. {OSS-Fuzz}-Google\u2019s continuous fuzzing service for open source software. In 26th USENIX Security Symp. (2017)."},{"key":"e_1_3_1_25_2","unstructured":"Wan S. et al. CYBERSECEVAL 3: Advancing the evaluation of cybersecurity risks and capabilities in large language models. arXiv:2408.01605 (2024); https:\/\/arxiv.org\/abs\/2408.01605"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2016.2521368"},{"key":"e_1_3_1_27_2","doi-asserted-by":"crossref","unstructured":"Xia C.S. and Zhang L. Automated program repair via conversation: Fixing 162 out of 337 bugs for $0.42 each using ChatGPT. In Proceedings of the 33rd ACM SIGSOFT Intern. Symp. on Software Testing and Analysis. ACM (2024) 819\u2013831.","DOI":"10.1145\/3650212.3680323"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/32.988498"},{"key":"e_1_3_1_29_2","doi-asserted-by":"crossref","unstructured":"Zhang Y. Ruan H. Fan Z. and Roychoudhury A. AutoCodeRover: Autonomous program improvement. In Intern. Symp. on Software Testing and Analysis (2024).","DOI":"10.1145\/3650212.3680384"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3770922","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T13:57:14Z","timestamp":1779976634000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3770922"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,28]]},"references-count":28,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,6,1]]}},"alternative-id":["10.1145\/3770922"],"URL":"https:\/\/doi.org\/10.1145\/3770922","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,28]]},"assertion":[{"value":"2024-09-26","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}