Reducing False Positives in Static Bug Detection with LLMs: An Empirical Study in Industry

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Du, Xueying, Feng, Jiayi, Zou, Yi, Xu, Wei, Ma, Jie, Zhang, Wei, Liu, Sisi, Peng, Xin, Lou, Yiling
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912851328761856
author Du, Xueying
Feng, Jiayi
Zou, Yi
Xu, Wei
Ma, Jie
Zhang, Wei
Liu, Sisi
Peng, Xin
Lou, Yiling
author_facet Du, Xueying
Feng, Jiayi
Zou, Yi
Xu, Wei
Ma, Jie
Zhang, Wei
Liu, Sisi
Peng, Xin
Lou, Yiling
contents Static analysis tools (SATs) are widely adopted in both academia and industry for improving software quality, yet their practical use is often hindered by high false positive rates, especially in large-scale enterprise systems. These false alarms demand substantial manual inspection, creating severe inefficiencies in industrial code review. While recent work has demonstrated the potential of large language models (LLMs) for false alarm reduction on open-source benchmarks, their effectiveness in real-world enterprise settings remains unclear. To bridge this gap, we conduct the first comprehensive empirical study of diverse LLM-based false alarm reduction techniques in an industrial context at Tencent, one of the largest IT companies in China. Using data from Tencent's enterprise-customized SAT on its large-scale Advertising and Marketing Services software, we construct a dataset of 433 alarms (328 false positives, 105 true positives) covering three common bug types. Through interviewing developers and analyzing the data, our results highlight the prevalence of false positives, which wastes substantial manual effort (e.g., 10-20 minutes of manual inspection per alarm). Meanwhile, our results show the huge potential of LLMs for reducing false alarms in industrial settings (e.g., hybrid techniques of LLM and static analysis eliminate 94-98% of false positives with high recall). Furthermore, LLM-based techniques are cost-effective, with per-alarm costs as low as 2.1-109.5 seconds and $0.0011-$0.12, representing orders-of-magnitude savings compared to manual review. Finally, our case analysis further identifies key limitations of LLM-based false alarm reduction in industrial settings.
format Preprint
id arxiv_https___arxiv_org_abs_2601_18844
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Reducing False Positives in Static Bug Detection with LLMs: An Empirical Study in Industry
Du, Xueying
Feng, Jiayi
Zou, Yi
Xu, Wei
Ma, Jie
Zhang, Wei
Liu, Sisi
Peng, Xin
Lou, Yiling
Software Engineering
Artificial Intelligence
Static analysis tools (SATs) are widely adopted in both academia and industry for improving software quality, yet their practical use is often hindered by high false positive rates, especially in large-scale enterprise systems. These false alarms demand substantial manual inspection, creating severe inefficiencies in industrial code review. While recent work has demonstrated the potential of large language models (LLMs) for false alarm reduction on open-source benchmarks, their effectiveness in real-world enterprise settings remains unclear. To bridge this gap, we conduct the first comprehensive empirical study of diverse LLM-based false alarm reduction techniques in an industrial context at Tencent, one of the largest IT companies in China. Using data from Tencent's enterprise-customized SAT on its large-scale Advertising and Marketing Services software, we construct a dataset of 433 alarms (328 false positives, 105 true positives) covering three common bug types. Through interviewing developers and analyzing the data, our results highlight the prevalence of false positives, which wastes substantial manual effort (e.g., 10-20 minutes of manual inspection per alarm). Meanwhile, our results show the huge potential of LLMs for reducing false alarms in industrial settings (e.g., hybrid techniques of LLM and static analysis eliminate 94-98% of false positives with high recall). Furthermore, LLM-based techniques are cost-effective, with per-alarm costs as low as 2.1-109.5 seconds and $0.0011-$0.12, representing orders-of-magnitude savings compared to manual review. Finally, our case analysis further identifies key limitations of LLM-based false alarm reduction in industrial settings.
title Reducing False Positives in Static Bug Detection with LLMs: An Empirical Study in Industry
topic Software Engineering
Artificial Intelligence
url https://arxiv.org/abs/2601.18844