Vul-R2: A Reasoning LLM for Automated Vulnerability Repair

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wen, Xin-Cheng, Lin, Zirui, Yang, Yijun, Gao, Cuiyun, Ye, Deheng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914078958551040
author Wen, Xin-Cheng
Lin, Zirui
Yang, Yijun
Gao, Cuiyun
Ye, Deheng
author_facet Wen, Xin-Cheng
Lin, Zirui
Yang, Yijun
Gao, Cuiyun
Ye, Deheng
contents The exponential increase in software vulnerabilities has created an urgent need for automatic vulnerability repair (AVR) solutions. Recent research has formulated AVR as a sequence generation problem and has leveraged large language models (LLMs) to address this problem. Typically, these approaches prompt or fine-tune LLMs to generate repairs for vulnerabilities directly. Although these methods show state-of-the-art performance, they face the following challenges: (1) Lack of high-quality, vulnerability-related reasoning data. Current approaches primarily rely on foundation models that mainly encode general programming knowledge. Without vulnerability-related reasoning data, they tend to fail to capture the diverse vulnerability repair patterns. (2) Hard to verify the intermediate vulnerability repair process during LLM training. Existing reinforcement learning methods often leverage intermediate execution feedback from the environment (e.g., sandbox-based execution results) to guide reinforcement learning training. In contrast, the vulnerability repair process generally lacks such intermediate, verifiable feedback, which poses additional challenges for model training.
format Preprint
id arxiv_https___arxiv_org_abs_2510_05480
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Vul-R2: A Reasoning LLM for Automated Vulnerability Repair
Wen, Xin-Cheng
Lin, Zirui
Yang, Yijun
Gao, Cuiyun
Ye, Deheng
Artificial Intelligence
Software Engineering
The exponential increase in software vulnerabilities has created an urgent need for automatic vulnerability repair (AVR) solutions. Recent research has formulated AVR as a sequence generation problem and has leveraged large language models (LLMs) to address this problem. Typically, these approaches prompt or fine-tune LLMs to generate repairs for vulnerabilities directly. Although these methods show state-of-the-art performance, they face the following challenges: (1) Lack of high-quality, vulnerability-related reasoning data. Current approaches primarily rely on foundation models that mainly encode general programming knowledge. Without vulnerability-related reasoning data, they tend to fail to capture the diverse vulnerability repair patterns. (2) Hard to verify the intermediate vulnerability repair process during LLM training. Existing reinforcement learning methods often leverage intermediate execution feedback from the environment (e.g., sandbox-based execution results) to guide reinforcement learning training. In contrast, the vulnerability repair process generally lacks such intermediate, verifiable feedback, which poses additional challenges for model training.
title Vul-R2: A Reasoning LLM for Automated Vulnerability Repair
topic Artificial Intelligence
Software Engineering
url https://arxiv.org/abs/2510.05480