From Vulnerabilities to Remediation: A Systematic Literature Review of LLMs in Code Security

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Basic, Enna, Giaretta, Alberto
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914400592461824
author Basic, Enna
Giaretta, Alberto
author_facet Basic, Enna
Giaretta, Alberto
contents Large Language Models (LLMs) have emerged as powerful tools for automating programming tasks, including security-related ones. However, they can also introduce vulnerabilities during code generation, fail to detect existing vulnerabilities, or report nonexistent ones. This systematic literature review investigates the security benefits and drawbacks of using LLMs for code-related tasks. In particular, it focuses on the types of vulnerabilities introduced by LLMs when generating code. Moreover, it analyzes the capabilities of LLMs to detect and fix vulnerabilities, and examines how prompting strategies impact these tasks. Finally, it examines how data poisoning attacks impact LLMs performance in the aforementioned tasks.
format Preprint
id arxiv_https___arxiv_org_abs_2412_15004
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle From Vulnerabilities to Remediation: A Systematic Literature Review of LLMs in Code Security
Basic, Enna
Giaretta, Alberto
Cryptography and Security
Artificial Intelligence
Computation and Language
Large Language Models (LLMs) have emerged as powerful tools for automating programming tasks, including security-related ones. However, they can also introduce vulnerabilities during code generation, fail to detect existing vulnerabilities, or report nonexistent ones. This systematic literature review investigates the security benefits and drawbacks of using LLMs for code-related tasks. In particular, it focuses on the types of vulnerabilities introduced by LLMs when generating code. Moreover, it analyzes the capabilities of LLMs to detect and fix vulnerabilities, and examines how prompting strategies impact these tasks. Finally, it examines how data poisoning attacks impact LLMs performance in the aforementioned tasks.
title From Vulnerabilities to Remediation: A Systematic Literature Review of LLMs in Code Security
topic Cryptography and Security
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2412.15004