Explaining Software Vulnerabilities with Large Language Models

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Johnson, Oshando, Fomina, Alexandra, Krishnamurthy, Ranjith, Chaudhari, Vaibhav, Shanmuganathan, Rohith Kumar, Bodden, Eric
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911251256311808
author Johnson, Oshando
Fomina, Alexandra
Krishnamurthy, Ranjith
Chaudhari, Vaibhav
Shanmuganathan, Rohith Kumar
Bodden, Eric
author_facet Johnson, Oshando
Fomina, Alexandra
Krishnamurthy, Ranjith
Chaudhari, Vaibhav
Shanmuganathan, Rohith Kumar
Bodden, Eric
contents The prevalence of security vulnerabilities has prompted companies to adopt static application security testing (SAST) tools for vulnerability detection. Nevertheless, these tools frequently exhibit usability limitations, as their generic warning messages do not sufficiently communicate important information to developers, resulting in misunderstandings or oversight of critical findings. In light of recent developments in Large Language Models (LLMs) and their text generation capabilities, our work investigates a hybrid approach that uses LLMs to tackle the SAST explainability challenges. In this paper, we present SAFE, an Integrated Development Environment (IDE) plugin that leverages GPT-4o to explain the causes, impacts, and mitigation strategies of vulnerabilities detected by SAST tools. Our expert user study findings indicate that the explanations generated by SAFE can significantly assist beginner to intermediate developers in understanding and addressing security vulnerabilities, thereby improving the overall usability of SAST tools.
format Preprint
id arxiv_https___arxiv_org_abs_2511_04179
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Explaining Software Vulnerabilities with Large Language Models
Johnson, Oshando
Fomina, Alexandra
Krishnamurthy, Ranjith
Chaudhari, Vaibhav
Shanmuganathan, Rohith Kumar
Bodden, Eric
Software Engineering
Artificial Intelligence
The prevalence of security vulnerabilities has prompted companies to adopt static application security testing (SAST) tools for vulnerability detection. Nevertheless, these tools frequently exhibit usability limitations, as their generic warning messages do not sufficiently communicate important information to developers, resulting in misunderstandings or oversight of critical findings. In light of recent developments in Large Language Models (LLMs) and their text generation capabilities, our work investigates a hybrid approach that uses LLMs to tackle the SAST explainability challenges. In this paper, we present SAFE, an Integrated Development Environment (IDE) plugin that leverages GPT-4o to explain the causes, impacts, and mitigation strategies of vulnerabilities detected by SAST tools. Our expert user study findings indicate that the explanations generated by SAFE can significantly assist beginner to intermediate developers in understanding and addressing security vulnerabilities, thereby improving the overall usability of SAST tools.
title Explaining Software Vulnerabilities with Large Language Models
topic Software Engineering
Artificial Intelligence
url https://arxiv.org/abs/2511.04179