INTENTFIX: Automated Logic Vulnerability Repair via LLM-Driven Intent Modeling
Logic vulnerabilities, which arise from semantic gaps between a developer’s intent and the actual code, represent a critical and growing challenge in software security. Unlike syntactic bugs, these vulnerabilities pass traditional testing while harboring critical security flaws that can lead to severe breaches. We introduce INTENTFIX, a novel framework that automatically repairs logic vulnerabilities through intent-centric security analysis. INTENTFIX first leverages a Large Language Model (LLM) to systematically extract and formalize the developer’s implicit intent into a structured model. It then performs a differential analysis between this intent model and the implementation to precisely identify semantic gaps. Finally, it synthesizes and refines a patch through a multi-aspect, LLM-driven reasoning process. We evaluated INTENTFIX on a comprehensive dataset of 1,107 real-world CVE cases across five vulnerability types and 19 programming languages, achieving a patch accuracy of 64.5%, a 1.97× improvement over strong Chain-of-Thought (CoT) LLM baselines. This work makes three primary contributions: (1) We formalize intent-centric analysis as a new theoretical foundation for logic vulnerability repair. (2) We introduce a novel, structured framework that effectively harnesses an LLM’s reasoning capabilities for security. (3) We provide extensive empirical evidence validating our approach and offering new insights into the role of context in automated program repair.
Wed 15 AprDisplayed time zone: Brasilia, Distrito Federal, Brazil change
16:00 - 17:30 | AI for Software Engineering 9Research Track at Europa II Chair(s): Patrizio Pelliccione Gran Sasso Science Institute, L'Aquila, Italy | ||
16:00 15mTalk | Rethinking the Capability of Fine-Tuned Language Models for Automated Vulnerability Repair Research Track Woorim Han Seoul National University, Yeongjun Kwak Ulsan National Institute of Science and Technology (UNIST), miseon Yu Seoul National University, Kyeongmin Kim Ulsan National Institute of Science and Technology (UNIST), Younghan Lee Sungshin Women's University, Hyungon Moon Ulsan National Institute of Science and Technology (UNIST), Yunheung Paek Seoul National University, Korea Pre-print | ||
16:15 15mTalk | STEM-EF: A Model for Assessing Scrum Team Effectiveness Based on Emotional Factors Research Track Ramon Nóbrega dos Santos VIRTUS/UFCG, Hyggo Almeida VIRTUS/UFCG, Mirko Perkusich VIRTUS, Danyllo Albuquerque VIRTUS/UFCG, Felipe Cunha VIRTUS/UFCG, Thiago Rique VIRTUS/UFCG, Ademar Sousa Neto VIRTUS/UFCG, Angelo Perkusich VIRTUS/UFCG | ||
16:30 15mTalk | INTENTFIX: Automated Logic Vulnerability Repair via LLM-Driven Intent Modeling Research Track Jinseok Heo Sungkyunkwan University, Dongwook Choi SungKyunKwan University, Jinyoung Kim Sungkyunkwan University, Misoo Kim Chonnam National University, Eunseok Lee Sungkyunkwan University | ||
16:45 15mTalk | Well Begun is Half Done: Location-Aware and Trace-Guided Iterative Automated Vulnerability RepairDistinguished Paper Award Research Track Zhenlei Ye Yangzhou University, Xiaobing Sun Yangzhou University, Sicong Cao Nanjing University of Posts and Telecommunications, Lili Bo Yangzhou University, Bin Li Yangzhou University | ||
17:00 15mTalk | From Code to Correctness: Closing the Last Mile of Code Generation with Hierarchical Debugging Research Track Yuling Shi Shanghai Jiao Tong University, Songsong Wang University of California, Davis, Chengcheng Wan East China Normal University, Wang Min University of Pennsylvania, Xiaodong Gu Shanghai Jiao Tong University Pre-print | ||
17:15 15mTalk | Unlocking LLM Repair Capabilities Through Cross-Language Translation and Multi-Agent Refinement Research Track Wenqiang LUO City University of Hong Kong, Jacky Keung City University of Hong Kong, Boyang Yang Yanshan University, Jacques Klein University of Luxembourg, Tegawendé F. Bissyandé University of Luxembourg, Haoye Tian Aalto University, Xuan-Bach D. Le University of Melbourne | ||