arXiv:2507.22659cs.SEcs.AI2025-07综述被引 14

系统梳理263篇论文,厘清大模型检测漏洞的研究现状与方向。

A Systematic Literature Review on Detecting Software Vulnerabilities with Large Language Models

  • 系统综述263篇论文,按任务、输入、架构分类
  • 分析数据集覆盖度与多样性,揭示研究盲区
  • 提供可复现指南,适合研究者快速入门

大型语言模型(LLMs)在软件工程中的应用日益广泛,尤其在软件漏洞检测领域引发关注。然而,该领域发展迅速,研究分散,因系统设计和数据集使用差异导致难以比较。本文对2020年1月至2025年11月间发表的263篇相关研究进行了系统性文献综述(SLR),从任务形式、输入表示、系统架构和技术方法等方面进行分类。进一步分析所用数据集的特征、漏洞覆盖范围与多样性。提出细粒度的漏洞检测方法分类体系,识别关键局限,并提出可操作的未来研究方向。通过结构化梳理,提升研究透明度,为研究人员和实践者提供可比、可复现的研究参考。所有资料已公开,维护动态更新的LPM4SVD研究库于https://github.com/hs-esslingen-it-security/Awesome-LLM4SVD。

原文摘要 · Abstract (English)

The increasing adoption of Large Language Models (LLMs) in software engineering has sparked interest in their use for software vulnerability detection. However, the rapid development of this field has resulted in a fragmented research landscape, with diverse studies that are difficult to compare due to differences in, e.g., system designs and dataset usage. This fragmentation makes it difficult to obtain a clear overview of the state-of-the-art or compare and categorize studies meaningfully. In this work, we present a comprehensive systematic literature review (SLR) of LLM-based software vulnerability detection. We analyze 263 studies published between January 2020 and November 2025, categorizing them by task formulation, input representation, system architecture, and techniques. Further, we analyze the datasets used, including their characteristics, vulnerability coverage, and diversity. We present a fine-grained taxonomy of vulnerability detection approaches, identify key limitations, and outline actionable future research opportunities. By providing a structured overview of the field, this review improves transparency and serves as a practical guide for researchers and practitioners aiming to conduct more comparable and reproducible research. We publicly release all artifacts and maintain a living repository of LLM-based software vulnerability detection studies at https://github.com/hs-esslingen-it-security/Awesome-LLM4SVD.

大模型漏洞检测综述系统性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。