发表机构
Stevens Institute of Technology(史蒂文斯理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
PatchHolmes提出两阶段补丁检索系统,采用列表式智能体选择,在GitHubAD上显著提升Recall@1,且无需微调或外部API,证明了列表式智能体循环的有效性。
AI 中文摘要
补丁检索,即查找修复已知漏洞的提交的任务,是漏洞管理工作流程的基础,然而在主要咨询数据库中,60%至63%的CVE缺乏补丁链接。我们提出了PatchHolmes,一个两阶段补丁检索系统,将混合第一阶段检索器与智能体第二阶段检查循环相结合。与逐点式先前工作独立评分每个候选不同,第二阶段智能体以列表方式读取前100个候选:它一次看到完整候选列表,并通过四个有预算的工具选择性地读取3至10个提交,然后提交一个最佳提交。在GitHubAD上,PatchHolmes在Recall@1上比逐点二元分类器Favia高出25.34%,比检索加思维链基线IRCoT高出31.40%,每个CVE仅需一次智能体对话,而Favia需要十次;在候选集保持相同的情况下,智能体在Recall@1上比直接采用检索器的最佳候选增加了27.32%,并且相同的智能体,未经修改地转移到PatchFinder_top10,将Recall@1从PatchFinder自身的首选(24.28%)提升至39.86%。在Qwen系列内更换LLM骨干,Recall@1的变化不到1%,而第二个模型系列(gpt-oss)仍远高于无智能体基线,因此增益来自列表式智能体循环;整个系统在冻结的开权重模型上运行于本地Git仓库,无需微调或外部搜索API。
英文摘要
Patch retrieval, the task of finding the commit that fixes a known vulnerability, is the foundation of vulnerability management workflows, yet 60% to 63% of CVEs in the major advisory databases lack a patch link. We present PatchHolmes, a two-phase patch retrieval system that pairs a hybrid first-stage retriever with an agentic second-stage inspection loop. Unlike pointwise prior work that scores each candidate independently, the Phase 2 agent reads the top-100 listwise: it sees the full candidate list at once and selectively reads 3 to 10 commits through four budgeted tools before submitting a single best commit. On GitHubAD, PatchHolmes beats the pointwise binary classifier Favia by 25.34% Recall@1 and the retrieve-and-CoT baseline IRCoT by 31.40%, at one agent conversation per CVE versus Favia's ten; with the candidate set held identical, the agent adds 27.32% Recall@1 over taking the retriever's top candidate, and the same agent, transferred unchanged to PatchFinder_top10, lifts Recall@1 from PatchFinder's own top-1 pick (24.28%) to 39.86%. Swapping the LLM backbone within the Qwen family changes Recall@1 by under 1%, and a second model family (gpt-oss) stays far above the no-agent floor, so the gain comes from the listwise agent loop; the entire system runs on a frozen open-weight model over a local Git repository, without fine-tuning or external search APIs.
CommentsAccepted at AACL-IJCNLP 2026. Code at https://github.com/Aizhouym/PatchHolmes