arXiv:2412.15004cs.CRcs.AI2024-12综述被引 21

系统梳理LLM在代码安全中的漏洞与修复能力

From Vulnerabilities to Remediation: A Systematic Literature Review of LLMs in Code Security

  • 分析LLM生成代码时引入的漏洞类型
  • 评估LLM检测与修复漏洞的有效性
  • 揭示提示策略与数据投毒对性能影响

大型语言模型(LLMs)已成为自动化编程任务的强大工具,包括安全相关任务。然而,它们在代码生成过程中也可能引入漏洞、无法识别现有漏洞或误报不存在的漏洞。本系统性文献综述研究了使用LLMs进行代码相关任务的安全收益与风险。特别关注了LLM在生成代码时引入的漏洞类型。同时分析了LLMs在漏洞检测与修复方面的能力,并探讨了提示策略对这些任务的影响。最后,考察了数据投毒攻击对上述任务中LLMs性能的影响。

原文摘要 · Abstract (English)

Large Language Models (LLMs) have emerged as powerful tools for automating programming tasks, including security-related ones. However, they can also introduce vulnerabilities during code generation, fail to detect existing vulnerabilities, or report nonexistent ones. This systematic literature review investigates the security benefits and drawbacks of using LLMs for code-related tasks. In particular, it focuses on the types of vulnerabilities introduced by LLMs when generating code. Moreover, it analyzes the capabilities of LLMs to detect and fix vulnerabilities, and examines how prompting strategies impact these tasks. Finally, it examines how data poisoning attacks impact LLMs performance in the aforementioned tasks.

代码安全LLM漏洞检测系统综述

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。