arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2405.20455cs.SE

DepsRAG:面向软件依赖管理的智能体推理与规划

DepsRAG: Towards Agentic Reasoning and Planning for Software Dependency Management

Mohannad Alhanahnah, Yazan Boshmaf

更新

AI总结:

DepsRAG是一个多智能体框架,通过构建包含直接和传递依赖的知识图谱并结合RAG与Critic-Agent反馈机制,辅助开发者对软件依赖进行推理,实验表明其准确率提升三倍。

AI中文摘要:

在大型语言模型(LLMs)具备先进能力的时代,一个独特的机遇应运而生:开发基于LLM的数字助理工具,通过在导入软件依赖和开源库之前促进对其的全面推理来支持软件开发者。这一推理过程十分艰巨,需要多种专用工具和专门知识,每种工具和知识聚焦于不同方面(例如,安全分析工具可能忽略循环依赖等设计缺陷,而这些缺陷会损害软件的可维护性),从而在软件开发生命周期中造成重大瓶颈。在本文中,我们介绍了DepsRAG,这是一个多智能体框架,旨在协助开发者对软件依赖进行推理。DepsRAG首先构建一个全面的知识图谱(KG),其中包含直接依赖和传递依赖。开发者可以通过对话界面与DepsRAG交互,提出关于依赖的查询。DepsRAG采用检索增强生成(RAG)技术,通过从知识图谱以及外部来源(如Web和漏洞数据库)检索相关信息来增强这些查询,从而展示了其对新颖场景的适应性。DepsRAG融入了Critic-Agent反馈回路,以确保LLM生成响应的准确性和清晰度。我们使用GPT-4-Turbo和Llama-3在三个多步推理任务上对DepsRAG进行了评估,观察到在集成Critic-Agent机制后准确率提高了三倍。DepsRAG的演示和实现可在以下地址获取:https://github.com/Mohannadcse/DepsRAG。

英文摘要:

In the era of Large Language Models (LLMs) with their advanced capabilities, a unique opportunity arises to develop LLM-based digital assistant tools that can support software developers by facilitating comprehensive reasoning about software dependencies and open-source libraries before importing them. This reasoning process is daunting, mandating multiple specialized tools and dedicated expertise, each focusing on distinct aspects (e.g., security analysis tools may overlook design flaws such as circular dependencies, which hinder software maintainability). Creating a significant bottleneck in the software development lifecycle. In this paper, we introduce DepsRAG, a multi-agent framework designed to assist developers in reasoning about software dependencies. DepsRAG first constructs a comprehensive Knowledge Graph (KG) that includes both direct and transitive dependencies. Developers can interact with DepsRAG through a conversational interface, posing queries about the dependencies. DepsRAG employs Retrieval-Augmented Generation (RAG) to enhance these queries by retrieving relevant information from the KG as well as external sources, such as the Web and vulnerability databases, thus demonstrating its adaptability to novel scenarios. DepsRAG incorporates a Critic-Agent feedback loop to ensure the accuracy and clarity of LLM-generated responses. We evaluated DepsRAG using GPT-4-Turbo and Llama-3 on three multi-step reasoning tasks, observing a threefold increase in accuracy with the integration of the Critic-Agent mechanism. DepsRAG demo and implementation are available: https://github.com/Mohannadcse/DepsRAG.

↑