From Trace to Line: LLM Agent for Real-World OSS Vulnerability Localization

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Xi, Haoran, Shao, Minghao, Dolan-Gavitt, Brendan, Shafique, Muhammad, Karri, Ramesh
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917247412338688
author Xi, Haoran
Shao, Minghao
Dolan-Gavitt, Brendan
Shafique, Muhammad
Karri, Ramesh
author_facet Xi, Haoran
Shao, Minghao
Dolan-Gavitt, Brendan
Shafique, Muhammad
Karri, Ramesh
contents Large language models show promise for vulnerability discovery, yet prevailing methods inspect code in isolation, struggle with long contexts, and focus on coarse function- or file-level detections that offer limited guidance to engineers who need precise line-level localization for targeted patches. We introduce T2L, an executable framework for project-level, line-level vulnerability localization that progressively narrows scope from repository modules to exact vulnerable lines via AST-based chunking and evidence-guided refinement. We provide a baseline agent with an Agentic Trace Analyzer (ATA) that fuses runtime evidence such as crash points and stack traces to translate failure symptoms into actionable diagnoses. To enable rigorous evaluation, we introduce T2L-ARVO, an expert-verified 50-case benchmark spanning five crash families in real-world projects. On T2L-ARVO, our baseline achieves up to 58.0% detection and 54.8% line-level localization rate. Together, T2L framework advance LLM-based vulnerability detection toward deployable, precision diagnostics in open-source software workflows.
format Preprint
id arxiv_https___arxiv_org_abs_2510_02389
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From Trace to Line: LLM Agent for Real-World OSS Vulnerability Localization
Xi, Haoran
Shao, Minghao
Dolan-Gavitt, Brendan
Shafique, Muhammad
Karri, Ramesh
Software Engineering
Cryptography and Security
Machine Learning
Large language models show promise for vulnerability discovery, yet prevailing methods inspect code in isolation, struggle with long contexts, and focus on coarse function- or file-level detections that offer limited guidance to engineers who need precise line-level localization for targeted patches. We introduce T2L, an executable framework for project-level, line-level vulnerability localization that progressively narrows scope from repository modules to exact vulnerable lines via AST-based chunking and evidence-guided refinement. We provide a baseline agent with an Agentic Trace Analyzer (ATA) that fuses runtime evidence such as crash points and stack traces to translate failure symptoms into actionable diagnoses. To enable rigorous evaluation, we introduce T2L-ARVO, an expert-verified 50-case benchmark spanning five crash families in real-world projects. On T2L-ARVO, our baseline achieves up to 58.0% detection and 54.8% line-level localization rate. Together, T2L framework advance LLM-based vulnerability detection toward deployable, precision diagnostics in open-source software workflows.
title From Trace to Line: LLM Agent for Real-World OSS Vulnerability Localization
topic Software Engineering
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2510.02389