{"id":"https://openalex.org/W4399516134","doi":"https://doi.org/10.1145/3643651.3659892","title":"Evaluating Large Language Models for Real-World Vulnerability Repair in C/C++ Code","display_name":"Evaluating Large Language Models for Real-World Vulnerability Repair in C/C++ Code","publication_year":2024,"publication_date":"2024-06-11","ids":{"openalex":"https://openalex.org/W4399516134","doi":"https://doi.org/10.1145/3643651.3659892"},"language":"en","primary_location":{"id":"doi:10.1145/3643651.3659892","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3643651.3659892","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 10th ACM International Workshop on Security and Privacy Analytics","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3643651.3659892","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100322329","display_name":"Lan Zhang","orcid":"https://orcid.org/0000-0003-3964-8034"},"institutions":[{"id":"https://openalex.org/I203172682","display_name":"Northern Arizona University","ror":"https://ror.org/0272j5188","country_code":"US","type":"education","lineage":["https://openalex.org/I203172682"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lan Zhang","raw_affiliation_strings":["Northern Arizona University, Flagstaff, USA"],"raw_orcid":"https://orcid.org/0000-0003-3964-8034","affiliations":[{"raw_affiliation_string":"Northern Arizona University, Flagstaff, USA","institution_ids":["https://openalex.org/I203172682"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058926362","display_name":"Qingtian Zou","orcid":"https://orcid.org/0000-0002-1412-4800"},"institutions":[{"id":"https://openalex.org/I130769515","display_name":"Pennsylvania State University","ror":"https://ror.org/04p491231","country_code":"US","type":"education","lineage":["https://openalex.org/I130769515"]},{"id":"https://openalex.org/I867280407","display_name":"The University of Texas Southwestern Medical Center","ror":"https://ror.org/05byvp690","country_code":"US","type":"healthcare","lineage":["https://openalex.org/I867280407"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qingtian Zou","raw_affiliation_strings":["Penn State University &amp; University of Texas Southwestern Medical Center, State College, USA"],"raw_orcid":"https://orcid.org/0000-0002-1412-4800","affiliations":[{"raw_affiliation_string":"Penn State University &amp; University of Texas Southwestern Medical Center, State College, USA","institution_ids":["https://openalex.org/I867280407","https://openalex.org/I130769515"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5088206056","display_name":"Anoop Singhal","orcid":"https://orcid.org/0000-0002-2602-3927"},"institutions":[{"id":"https://openalex.org/I1321296531","display_name":"National Institute of Standards and Technology","ror":"https://ror.org/05xpvk416","country_code":"US","type":"funder","lineage":["https://openalex.org/I1321296531","https://openalex.org/I1343035065"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Anoop Singhal","raw_affiliation_strings":["National Institute of Standards and Technology, Gaithersburg, USA"],"raw_orcid":"https://orcid.org/0000-0002-2602-3927","affiliations":[{"raw_affiliation_string":"National Institute of Standards and Technology, Gaithersburg, USA","institution_ids":["https://openalex.org/I1321296531"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100656311","display_name":"Xiaoyan Sun","orcid":"https://orcid.org/0000-0002-0321-2338"},"institutions":[{"id":"https://openalex.org/I107077323","display_name":"Worcester Polytechnic Institute","ror":"https://ror.org/05ejpqr48","country_code":"US","type":"education","lineage":["https://openalex.org/I107077323"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiaoyan Sun","raw_affiliation_strings":["Worcester Polytechnic Institute, Worcester, USA"],"raw_orcid":"https://orcid.org/0000-0002-0321-2338","affiliations":[{"raw_affiliation_string":"Worcester Polytechnic Institute, Worcester, USA","institution_ids":["https://openalex.org/I107077323"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100346908","display_name":"Peng Liu","orcid":"https://orcid.org/0000-0003-4175-504X"},"institutions":[{"id":"https://openalex.org/I130769515","display_name":"Pennsylvania State University","ror":"https://ror.org/04p491231","country_code":"US","type":"education","lineage":["https://openalex.org/I130769515"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Peng Liu","raw_affiliation_strings":["Penn State University, State College, USA"],"raw_orcid":"https://orcid.org/0000-0003-4175-504X","affiliations":[{"raw_affiliation_string":"Penn State University, State College, USA","institution_ids":["https://openalex.org/I130769515"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":7.7608,"has_fulltext":false,"cited_by_count":18,"citation_normalized_percentile":{"value":0.97663841,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"49","last_page":"58"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9983999729156494,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6730426549911499},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5402071475982666},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.5014660358428955},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.3877612054347992},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.248680979013443}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6730426549911499},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5402071475982666},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.5014660358428955},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.3877612054347992},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.248680979013443},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3643651.3659892","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3643651.3659892","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 10th ACM International Workshop on Security and Privacy Analytics","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3643651.3659892","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3643651.3659892","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 10th ACM International Workshop on Security and Privacy Analytics","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5287457552","display_name":null,"funder_award_id":"CNS-2019340, ECCS-2140175, DGE-2409851","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"},{"id":"https://openalex.org/G5374484370","display_name":null,"funder_award_id":"60NANB22D144","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"}],"funders":[{"id":"https://openalex.org/F4320323817","display_name":"Universitas Brawijaya","ror":"https://ror.org/01wk3d929"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":12,"referenced_works":["https://openalex.org/W2131461486","https://openalex.org/W2140073981","https://openalex.org/W2805346154","https://openalex.org/W2806718802","https://openalex.org/W4244452926","https://openalex.org/W4284705844","https://openalex.org/W4382239980","https://openalex.org/W4385302156","https://openalex.org/W4386185161","https://openalex.org/W4386231786","https://openalex.org/W4387561453","https://openalex.org/W4408175000"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"The":[0],"advent":[1],"of":[2,23,43,71,89,145],"Large":[3],"Language":[4],"Models":[5],"(LLMs)":[6],"has":[7],"enabled":[8],"advancement":[9],"in":[10,25,51,56,91,147,159],"automated":[11,148],"code":[12,28,66,104,165],"generation,":[13],"translation,":[14],"and":[15,49,119,143],"summarization.":[16],"Despite":[17],"their":[18,107],"promise,":[19],"evaluating":[20,40],"the":[21,41,87,141,155],"use":[22],"LLMs":[24,90,146],"repairing":[26],"real-world":[27,57,64],"vulnerabilities":[29,55,113],"remains":[30],"underexplored.":[31],"In":[32],"this":[33,37],"study,":[34],"we":[35,124],"address":[36],"gap":[38],"by":[39,131],"capability":[42],"advanced":[44],"LLMs,":[45],"such":[46],"as":[47],"ChatGPT-4":[48],"Claude,":[50],"fixing":[52],"memory":[53,72,78],"corruption":[54,73],"C/C++":[58,65],"code.":[59],"We":[60],"meticulously":[61],"curated":[62],"223":[63],"snippets":[67],"encompassing":[68],"a":[69],"spectrum":[70],"vulnerabilities,":[74],"ranging":[75],"from":[76],"straightforward":[77],"leaks":[79],"to":[80,102],"intricate":[81],"buffer":[82],"errors.":[83],"Our":[84,135],"findings":[85],"demonstrate":[86],"proficiency":[88],"rectifying":[92],"simple":[93],"memor":[94],"errors":[95],"like":[96],"leaks,":[97],"where":[98],"fixes":[99],"are":[100],"confined":[101],"localized":[103],"segments.":[105],"However,":[106],"effectiveness":[108],"diminishes":[109],"when":[110],"addressing":[111],"complicated":[112],"necessitating":[114],"reasoning":[115,160],"about":[116],"cross-cutting":[117],"concerns":[118],"deeper":[120],"program":[121,149],"semantics.":[122],"Furthermore,":[123],"explore":[125],"techniques":[126],"for":[127,157,162],"augmenting":[128],"LLM":[129],"performance":[130],"incorporating":[132],"additional":[133],"knowledge.":[134],"results":[136],"shed":[137],"light":[138],"on":[139,151],"both":[140],"strengths":[142],"limitations":[144],"repair":[150,166],"genuine":[152],"code,":[153],"underscoring":[154],"need":[156],"advancements":[158],"abilities":[161],"handling":[163],"complex":[164],"tasks.":[167]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":15},{"year":2024,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
