arXiv · 2412.15004
From Vulnerabilities to Remediation: A Systematic Literature Review of LLMs in Code Security
Abstract
Large Language Models (LLMs) have emerged as powerful tools for automating programming tasks, including security-related ones. However, they can also introduce vulnerabilities during code generation, fail to detect existing vulnerabilities, or report nonexistent ones. This systematic literature review investigates the security benefits and drawbacks of using LLMs for code-related tasks. In particular, it focuses on the types of vulnerabilities introduced by LLMs when generating code. Moreover, it analyzes the capabilities of LLMs to detect and fix vulnerabilities, and examines how prompting strategies impact these tasks. Finally, it examines how data poisoning attacks impact LLMs performance in the aforementioned tasks.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Enna Basic, Alberto Giaretta. 2024-12-19. From Vulnerabilities to Remediation: A Systematic Literature Review of LLMs in Code Security. https://arxiv.org/abs/2412.15004
Cite the original work for its findings. Save a collection to share your selection of sources.