Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Garg, Aayush, Khan, Zanis Ali, Degiovanni, Renzo, Tang, Qiang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915644122857472
author Garg, Aayush
Khan, Zanis Ali
Degiovanni, Renzo
Tang, Qiang
author_facet Garg, Aayush
Khan, Zanis Ali
Degiovanni, Renzo
Tang, Qiang
contents Automated vulnerability patching is crucial for software security, and recent advancements in Large Language Models (LLMs) present promising capabilities for automating this task. However, existing research has primarily assessed LLMs using publicly disclosed vulnerabilities, leaving their effectiveness on related artificial vulnerabilities largely unexplored. In this study, we empirically evaluate the patching effectiveness and complementarity of several prominent LLMs, such as OpenAI's GPT variants, LLaMA, DeepSeek, and Mistral models, using both real and artificial vulnerabilities. Our evaluation employs Proof-of-Vulnerability (PoV) test execution to concretely assess whether LLM-generated source code successfully patches vulnerabilities. Our results reveal that LLMs patch real vulnerabilities more effectively compared to artificial ones. Additionally, our analysis reveals significant variability across LLMs in terms of overlapping (multiple LLMs patching the same vulnerabilities) and complementarity (vulnerabilities patched exclusively by a single LLM), emphasizing the importance of selecting appropriate LLMs for effective vulnerability patching.
format Preprint
id arxiv_https___arxiv_org_abs_2511_23408
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Garg, Aayush
Khan, Zanis Ali
Degiovanni, Renzo
Tang, Qiang
Cryptography and Security
Artificial Intelligence
Software Engineering
Automated vulnerability patching is crucial for software security, and recent advancements in Large Language Models (LLMs) present promising capabilities for automating this task. However, existing research has primarily assessed LLMs using publicly disclosed vulnerabilities, leaving their effectiveness on related artificial vulnerabilities largely unexplored. In this study, we empirically evaluate the patching effectiveness and complementarity of several prominent LLMs, such as OpenAI's GPT variants, LLaMA, DeepSeek, and Mistral models, using both real and artificial vulnerabilities. Our evaluation employs Proof-of-Vulnerability (PoV) test execution to concretely assess whether LLM-generated source code successfully patches vulnerabilities. Our results reveal that LLMs patch real vulnerabilities more effectively compared to artificial ones. Additionally, our analysis reveals significant variability across LLMs in terms of overlapping (multiple LLMs patching the same vulnerabilities) and complementarity (vulnerabilities patched exclusively by a single LLM), emphasizing the importance of selecting appropriate LLMs for effective vulnerability patching.
title Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
topic Cryptography and Security
Artificial Intelligence
Software Engineering
url https://arxiv.org/abs/2511.23408