arXiv:2505.11677cs.SEcs.LG2025-05

用大模型简化代码警告,提升开发者修复率

Enhancing Code Quality with Generative AI: Boosting Developer Warning Compliance

  • 用大模型重写警告信息,使其更易理解
  • 对重要警告给出严重性说明和修复建议
  • 适合关注代码安全与开发效率的工程师

程序员长期忽视静态分析工具产生的警告,尤其当警告可能为误报时。某些警告看似无关紧要,实则可能预示潜在漏洞,但开发者往往难以理解其影响。由于警告信息冗长且晦涩,若未引发明显问题,常被忽略。大语言模型可简化警告内容,解释关键警告的严重性,并提供修复建议,从而提升开发者对警告的响应与修复意愿。

原文摘要 · Abstract (English)

Programmers have long ignored warnings, especially those generated by static analysis tools, due to the potential for false-positives. In some cases, warnings may be indicative of larger issues, but programmers may not understand how a seemingly unimportant warning can grow into a vulnerability. Because these messages tend to be long and confusing, programmers tend to ignore them if they do not cause readily identifiable issues. Large language models can simplify these warnings, explain the gravity of important warnings, and suggest potential fixes to increase developer compliance with fixing warnings.

代码安全大模型应用开发效率

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。