arXiv:2502.18474cs.SEcs.AI2025-02综述被引 41

综述大模型在程序分析中的应用,涵盖静态、动态与混合方法。

A Contemporary Survey of Large Language Model Assisted Program Analysis

  • 按静态、动态、混合三类梳理大模型在程序分析中的应用
  • 指出当前研究在漏洞检测与代码理解上的有效提升
  • 适合关注大模型赋能软件安全的研究者参考

软件系统复杂性的提升推动了程序分析技术的发展,传统方法已难以满足现代软件开发需求。为应对这一挑战,具备上下文感知能力的大语言模型(LLMs)因在代码理解方面的优势受到广泛关注。自引入以来,研究人员已广泛探索其在程序分析中的应用。尽管已有针对网络安全领域中LLM应用的综述,但专门聚焦于程序分析的全面回顾仍较为稀缺。本文系统性地综述了LLMs在程序分析中的应用,将现有工作分为静态分析、动态分析和混合方法三类。通过整合最新研究,我们识别出该领域的未来方向与关键挑战。本综述旨在展示LLMs在推动程序分析实践中的潜力,并为安全研究人员提供改进检测框架或开发领域专用模型的实用洞见。

原文摘要 · Abstract (English)

The increasing complexity of software systems has driven significant advancements in program analysis, as traditional methods unable to meet the demands of modern software development. To address these limitations, deep learning techniques, particularly Large Language Models (LLMs), have gained attention due to their context-aware capabilities in code comprehension. Recognizing the potential of LLMs, researchers have extensively explored their application in program analysis since their introduction. Despite existing surveys on LLM applications in cybersecurity, comprehensive reviews specifically addressing their role in program analysis remain scarce. In this survey, we systematically review the application of LLMs in program analysis, categorizing the existing work into static analysis, dynamic analysis, and hybrid approaches. Moreover, by examining and synthesizing recent studies, we identify future directions and challenges in the field. This survey aims to demonstrate the potential of LLMs in advancing program analysis practices and offer actionable insights for security researchers seeking to enhance detection frameworks or develop domain-specific models.

程序分析大模型安全研究综述

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。