Fixing Security Vulnerabilities with Agentic AI in OSS-Fuzz
Critical open source software systems undergo significant validation in the form of lengthy fuzz campaigns. The fuzz campaigns typically conduct a biased random search over the domain of program inputs, to find inputs which crash the software system. Such fuzzing is useful to enhance the security of software systems in general since even closed source software may use open-source components. Hence testing open source software is of paramount importance. Currently OSS-Fuzz is the most significant and widely used infra-structure for continuous validation of open source systems. Unfortunately even though OSS-Fuzz has identified more than 13,000 vulnerabilities across 1000 or more software projects, the detected vulnerabilities may remain unpatched, as vulnerability fixing is often manual in practice.
In this work, we explore the use of Large Language Model (LLM) agents for automated vulnerability remediation. To our knowledge, this is the first study of LLM-assisted security patching on OSS-Fuzz. We adapt the AutoCodeRover agent, which typically fixes bugs from issue descriptions, to the security domain. Instead of issue text, our agent extracts vulnerability-relevant code elements through the execution of the exploit input, and augments patch generation with static typing information. We evaluate our agent in two settings. On a benchmark of historical vulnerabilities detected by OSS-Fuzz, our agent generates plausible patches for 61% to 72% of the cases. We then conduct the first evaluation of LLM agents on real-world, unpatched vulnerabilities reported by OSS-Fuzz. In this setting, the agent performs comparably to its benchmark results. Moreover, several agent-generated patches have already been merged into widely used open-source projects. These results demonstrate both the practicality of automated vulnerability remediation with LLM agents, and the feasibility of an end-to-end software protection cycle from detection to repair.
Wed 15 AprDisplayed time zone: Brasilia, Distrito Federal, Brazil change
11:00 - 12:30 | AI for Software Engineering 1Research Track / SE In Practice (SEIP) at Asia I Chair(s): Italo Santos University of Hawai‘i at Mānoa | ||
11:00 15mTalk | CREME: Robustness Enhancement of Code LLMs via Layer-Aware Model Editing Research Track Shuhan Liu Zhejiang University, Xing Hu Zhejiang University, Kerui Huang , Xiaohu Yang Zhejiang University, David Lo Singapore Management University, Xin Xia Zhejiang University | ||
11:15 15mTalk | Repairing LLM Executions for Secure Automatic Programming Research Track Ali El Husseini National University of Singapore, Yacine Izza National University of Singapore, Blaise Genest IPAL - CNRS - CNRS@CREATE, Abhik Roychoudhury National University of Singapore | ||
11:30 15mTalk | SecureReviewer: Enhancing Large Language Models for Secure Code Review through Secure-Aware Fine-Tuning Research Track Fang Liu Beihang University, Simiao Liu Beihang University, Yinghao Zhu Beihang University, Xiaoli Lian Beihang University, China, Li Zhang Beihang University Pre-print | ||
11:45 15mTalk | Find My Code Twin: Improving SNIPPET SEARCH Performance Using LLMs in Practice SE In Practice (SEIP) Seokjun Ko Samsung Electronics Co., Eunbi Jang AI Center, Samsung Electronics, Dahyeon Choi AI Center, Samsung Electronics, daeha ryu Innovation Center, Samsung Electronics, jinyoung park Innovation Center, Samsung Electronics, changseo park Innovation Center, Samsung Electronics DOI Media Attached | ||
12:00 15mTalk | Fixing Security Vulnerabilities with Agentic AI in OSS-Fuzz SE In Practice (SEIP) Yuntong Zhang National University of Singapore, Jiawei Wang University of Southern California, Dominic Berzin National University of Singapore, Martin Mirchev SonarSource, Abhik Roychoudhury National University of Singapore | ||
12:15 15mTalk | EvoC2Rust: A Skeleton-guided Framework for Project-Level C-to-Rust Translation SE In Practice (SEIP) Chaofan Wang Shanghai Jiao Tong University, Tingrui Yu Shanghai Jiao Tong University, Chen Xie Shanghai Jiao Tong University, Jie Wang Huawei Technologies Co., Ltd, Dong Chen Huawei Technologies Co., Ltd, Wenrui Zhang Huawei Technologies Co., Ltd, Yuling Shi Shanghai Jiao Tong University, Xiaodong Gu Shanghai Jiao Tong University, Beijun Shen Shanghai Jiao Tong University | ||