LogicEval: A Systematic Framework for Evaluating Automated Repair Techniques for Logical Vulnerabilities in Real-World Software

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Rashid, Syed Md Mukit, Ishtiaq, Abdullah Al, Tu, Kai, Dong, Yilu, Wu, Tianwei, Ranjbar, Ali, Yang, Tianchang, Sultana, Najrin, Mehnaz, Shagufta, Hussain, Syed Rafiul
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917430207447040
author Rashid, Syed Md Mukit
Ishtiaq, Abdullah Al
Tu, Kai
Dong, Yilu
Wu, Tianwei
Ranjbar, Ali
Yang, Tianchang
Sultana, Najrin
Mehnaz, Shagufta
Hussain, Syed Rafiul
author_facet Rashid, Syed Md Mukit
Ishtiaq, Abdullah Al
Tu, Kai
Dong, Yilu
Wu, Tianwei
Ranjbar, Ali
Yang, Tianchang
Sultana, Najrin
Mehnaz, Shagufta
Hussain, Syed Rafiul
contents Logical vulnerabilities in software stem from flaws in program logic rather than memory safety, which can lead to critical security failures. Although existing automated program repair techniques primarily focus on repairing memory corruption vulnerabilities, they struggle with logical vulnerabilities because of their limited semantic understanding of the vulnerable code and its expected behavior. On the other hand, recent successes of large language models (LLMs) in understanding and repairing code are promising. However, no framework currently exists to analyze the capabilities and limitations of such techniques for logical vulnerabilities. We aim to systematically evaluate both traditional and LLM based repair approaches for addressing real world logical vulnerabilities. To facilitate our assessment, we created the first ever dataset, LogicDS, comprising 122 logical vulnerabilities that reflect tangible security impact. We also developed a systematic framework, LogicEval, to evaluate patches for logical vulnerabilities. Evaluations suggest that compilation and testing failures are primarily driven by prompt sensitivity, loss of code context, and difficulty in patch localization.
format Preprint
id arxiv_https___arxiv_org_abs_2604_12994
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle LogicEval: A Systematic Framework for Evaluating Automated Repair Techniques for Logical Vulnerabilities in Real-World Software
Rashid, Syed Md Mukit
Ishtiaq, Abdullah Al
Tu, Kai
Dong, Yilu
Wu, Tianwei
Ranjbar, Ali
Yang, Tianchang
Sultana, Najrin
Mehnaz, Shagufta
Hussain, Syed Rafiul
Cryptography and Security
Artificial Intelligence
Logical vulnerabilities in software stem from flaws in program logic rather than memory safety, which can lead to critical security failures. Although existing automated program repair techniques primarily focus on repairing memory corruption vulnerabilities, they struggle with logical vulnerabilities because of their limited semantic understanding of the vulnerable code and its expected behavior. On the other hand, recent successes of large language models (LLMs) in understanding and repairing code are promising. However, no framework currently exists to analyze the capabilities and limitations of such techniques for logical vulnerabilities. We aim to systematically evaluate both traditional and LLM based repair approaches for addressing real world logical vulnerabilities. To facilitate our assessment, we created the first ever dataset, LogicDS, comprising 122 logical vulnerabilities that reflect tangible security impact. We also developed a systematic framework, LogicEval, to evaluate patches for logical vulnerabilities. Evaluations suggest that compilation and testing failures are primarily driven by prompt sensitivity, loss of code context, and difficulty in patch localization.
title LogicEval: A Systematic Framework for Evaluating Automated Repair Techniques for Logical Vulnerabilities in Real-World Software
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2604.12994