Searcharxiv⌕ Search

arXiv · 2610.04639

When Talk Isn't Code: Comparing LLM Agents That Simulate and Develop Software

Abstract

LLMs are used both to simulate network protocol implementations, as honeypots do, and to write them. Prior work evaluates the two uses separately, from a model's answers or conversations in one case and from its generated code in the other. We observe that a knowledge probe (asking the model which security checks an implementation needs) and a conversation can credit security checks that the generated program lacks, but no study has compared them with the code the same model writes. To fill this gap, we present the first such comparison between simulation mode (S-mode), where the model plays the implementation in a conversation, and development mode (D-mode), where the model writes the program and the program is attacked, with a knowledge probe as a baseline. We design and implement a harness that judges all three with one attack suite and one oracle, and evaluate 15 LLMs on four protocol implementations. We find that with the full security specification, the median model's attack success is at most 4\% on reassembly, HTTP, and firewall implementations in both modes, but 13\% in S-mode and 15\% in D-mode on DNS. In D-mode, adding the missing DNS requirement to the specification cuts that attack from 100\% to 34\% and changes only that check, whereas deleting a stated rule weakens the program on other checks too. Asking the model beforehand does not predict which checks a program has, since 13 of the 14 models that write a DNS resolver name the check, yet all 42 programs lack it. S-mode is a useful first filter, flagging 82\% of the real DNS vulnerabilities and leaving 96\% of the safe cases unflagged. It errs in both directions, over-reporting security checks that D-mode does not implement and under-reporting checks that D-mode does. S-mode can screen but not replace D-mode testing, and security requirements should be written down even when a model can recite them.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Xiang Li, Aichun Huang, Mingming Zhang, Zheli Liu. 2026-10-03. When Talk Isn't Code: Comparing LLM Agents That Simulate and Develop Software. https://arxiv.org/abs/2610.04639

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Can we find bugs using LLM-generated oracles?

Unit testing is vital in software development. Typically, a unit test consists of a test prefix and a test oracle which captures the developer's intended behaviour. Traditional test generation tools (e.g. Randoop and Evosuite) often produce oracles that mirror the program's actual behavior rather than the expected one, limiting their ability to automatically detect bugs as users must manually verify if the generated assertions are correct. Recent approaches leverage Large Language Models (LLMs), trained on vast datasets, to generate developer-like code and test cases. Although successful in generating tests, the question of whether such LLM-generated oracles can automatically find bugs, i.e., expected software behavior, remains unanswered. We conduct a controlled experiment to answer this question, by studying LLMs on two tasks, namely, test oracle classification and generation, and assessing whether LLM oracles capture the actual or the expected behavior. The study includes test cases and oracles written by developers and automatically generated for 24 Java repositories. Our findings show that LLM-based test generation approaches mainly capture the actual program behavior making bug detection difficult. We also find that LLMs are better at generating oracles than classifying them. Notably, LLM-generated oracles have a higher fault detection potential than the Evosuite ones.

cs.SE↗

SELU: A Software Engineering Language Understanding Benchmark

Large Language Models (LLMs) have demonstrated remarkable capabilities in code understanding and generation. However, their effectiveness on non-code Software Engineering (SE) tasks remains underexplored. We present 'Software Engineering Language Understanding' (SELU), the first comprehensive benchmark for evaluating LLMs on 22 SE textual artifacts NLU tasks, spanning from identifying whether a requirement is functional or non-functional to estimating the effort required to implement a development task. SELU covers classification, regression, Named Entity Recognition (NER), and Masked Language Modeling (MLM) tasks, with data drawn from diverse sources such as issue tracking systems and developer forums. We fine-tune 22 open-source LLMs, both generalist and domain-adapted; and prompt two proprietary alternatives using zero-shot a 3-shot prompting strategies. Performance is measured using metrics such as F1-macro, SMAPE, F1-micro, and accuracy, and compared via the Bayesian signed-rank test. Our results show that fine-tuned models across various sizes and architectures perform best, exhibiting high mean performance and low across-task variance. Furthermore, domain adaptation via code-focused pre-training does not yield significant improvements and might even be counterproductive for developer communication tasks.

cs.SE↗

Mut4All: Fuzzing Compilers via LLM-Synthesized Mutators Learned from Bug Reports

Mutation-based fuzzing is effective for uncovering compiler bugs, but designing high-quality mutators for modern languages with complex constructs (e.g., templates, macros) remains challenging. Existing methods rely heavily on manual design or human-in-the-loop correction, limiting scalability and cross-language generalizability. We present Mut4All, a fully automated, language-agnostic framework that synthesizes mutators using Large Language Models (LLMs) and compiler-specific knowledge from bug reports. It consists of three agents: (1) a mutator invention agent that identifies mutation targets and generates mutator metadata using compiler-related insights; (2) a mutator implementation synthesis agent, fine-tuned to produce initial implementations; and (3) a mutator refinement agent that verifies and corrects the mutators via unit-test feedback. Mut4All processes 1400 bug reports (700 Rust, 700 C++), yielding 444 Rust and 561 C++ mutators at ~$0.08 each via GPT-4o. Our customized fuzzer, using these mutators, finds 62 bugs in Rust compilers (44 new, 32 fixed) and 38 bugs in C++ compilers (17 new, 3 fixed). Mut4All outperforms existing methods in both unique crash detection and coverage, ranking first on Rust and second on C++.

cs.SE↗