发表机构
The University of Melbourne; Monash University(墨尔本大学; 莫纳什大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对现有智能体漏洞修复方法缺乏多维度程序上下文工程的问题,提出AgenticRepair框架,协调三个LLM子智能体构建三类上下文,在SEC-Bench上取得73%的修复成功率,显著优于基线。
AI 中文摘要
自动化漏洞修复旨在减少从漏洞分类报告中修补安全缺陷所需的时间和精力。近期的智能体AI方法在自动化程序修复中展现出良好效果,但漏洞修复比通用缺陷修复需要更丰富的程序上下文——安全工程师在实践中常规收集这类上下文,而现有智能体方法并未对其进行工程化处理。我们识别出三个关键缺口:捕获跨文件数据流和内存操作模式的代码结构上下文、揭示崩溃语义和内存来源的运行时执行上下文、恢复脆弱代码模式如何被引入的提交历史上下文。我们提出AgenticRepair,一款通过多维度程序上下文工程解决上述缺口的智能体漏洞修复框架。AgenticRepair协调三个专用LLM子智能体来构建上下文,这些上下文随后被嵌入专用修复子智能体的内存中,用于生成受上下文约束的补丁。在包含300个真实实例的SEC-Bench上,基于 sanitizer的补丁验证显示,AgenticRepair达到73%的成功率,比最强基线高出29%。我们的消融研究证实,三个上下文维度相互补充,多智能体支架和基础模型能力各自发挥关键作用。总体而言,这些发现确立了多维度程序上下文工程是智能体漏洞修复的有前景设计方向。
英文摘要
Automated vulnerability repair aims to reduce the time and effort required to patch security flaws from a vulnerability triage report. Recent agentic AI approaches have shown promising results in automated program repair. However, vulnerability repair demands richer program context than general bug repair - context that security engineers routinely assemble in practice but that existing agentic approaches do not engineer. We identify three critical gaps: code-structure context capturing cross-file data flows and memory operation patterns, runtime-execution context revealing crash semantics and memory origins, and commit-history context recovering how fragile code patterns were introduced. We present AgenticRepair, an agentic vulnerability repair framework that addresses the gaps through multi-faceted program context engineering. AgenticRepair orchestrates three specialized LLM subagents to engineer the contexts, which are then embedded into the memory of a dedicated repair subagent for context-conditioned patch synthesis. Evaluated on SEC-Bench comprising 300 real-world instances with sanitizer-based patch verification, AgenticRepair achieves a 73% success rate, substantially outperforming the strongest baseline by 29%. Our ablation study confirms that the three context facets are mutually complementary, and that multi-agent scaffolding and base-model capacity each play an essential role. Collectively, these findings establish multi-faceted program context engineering as a promising design direction for agentic vulnerability repair.
CommentsUnder Review at IEEE TSE