VulStamp: Vulnerability Assessment using Large Language Model

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Shen, Hao, Hu, Ming, Xie, Xiaofei, Li, Jiaye, Chen, Mingsong
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913911207362560
author Shen, Hao
Hu, Ming
Xie, Xiaofei
Li, Jiaye
Chen, Mingsong
author_facet Shen, Hao
Hu, Ming
Xie, Xiaofei
Li, Jiaye
Chen, Mingsong
contents Although modern vulnerability detection tools enable developers to efficiently identify numerous security flaws, indiscriminate remediation efforts often lead to superfluous development expenses. This is particularly true given that a substantial portion of detected vulnerabilities either possess low exploitability or would incur negligible impact in practical operational environments. Consequently, vulnerability severity assessment has emerged as a critical component in optimizing software development efficiency. Existing vulnerability assessment methods typically rely on manually crafted descriptions associated with source code artifacts. However, due to variability in description quality and subjectivity in intention interpretation, the performance of these methods is seriously limited. To address this issue, this paper introduces VulStamp, a novel intention-guided framework, to facilitate description-free vulnerability assessment. Specifically, VulStamp adopts static analysis together with Large Language Model (LLM) to extract the intention information of vulnerable code. Based on the intention information, VulStamp uses a prompt-tuned model for vulnerability assessment. Furthermore, to mitigate the problem of imbalanced data associated with vulnerability types, VulStamp integrates a Reinforcement Learning (RL)-based prompt-tuning method to train the assessment model.
format Preprint
id arxiv_https___arxiv_org_abs_2506_11484
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle VulStamp: Vulnerability Assessment using Large Language Model
Shen, Hao
Hu, Ming
Xie, Xiaofei
Li, Jiaye
Chen, Mingsong
Software Engineering
Although modern vulnerability detection tools enable developers to efficiently identify numerous security flaws, indiscriminate remediation efforts often lead to superfluous development expenses. This is particularly true given that a substantial portion of detected vulnerabilities either possess low exploitability or would incur negligible impact in practical operational environments. Consequently, vulnerability severity assessment has emerged as a critical component in optimizing software development efficiency. Existing vulnerability assessment methods typically rely on manually crafted descriptions associated with source code artifacts. However, due to variability in description quality and subjectivity in intention interpretation, the performance of these methods is seriously limited. To address this issue, this paper introduces VulStamp, a novel intention-guided framework, to facilitate description-free vulnerability assessment. Specifically, VulStamp adopts static analysis together with Large Language Model (LLM) to extract the intention information of vulnerable code. Based on the intention information, VulStamp uses a prompt-tuned model for vulnerability assessment. Furthermore, to mitigate the problem of imbalanced data associated with vulnerability types, VulStamp integrates a Reinforcement Learning (RL)-based prompt-tuning method to train the assessment model.
title VulStamp: Vulnerability Assessment using Large Language Model
topic Software Engineering
url https://arxiv.org/abs/2506.11484