Λεπτομέρειες βιβλιογραφικής εγγραφής
| Τίτλος: |
Security Analysis of Large Language Models on API Misuse Programming Repair. |
| Συγγραφείς: |
Zhang, Rui, Qiao, Ziyue, Yu, Yong, Vocaturo, Eugenio |
| Πηγή: |
International Journal of Intelligent Systems; 11/19/2024, Vol. 2024, p1-18, 18p |
| Θεματικοί όροι: |
Language models, Security systems software, Resource management, Empirical research, Awareness |
| Περίληψη: |
Application programming interface (API) misuse refers to misconceptions or carelessness in the anticipated usage of APIs, threatening the software system's security. Moreover, API misuses demonstrate significant concealment and are challenging to uncover. Recent advancements have explored enhanced LLMs in a variety of software engineering (SE) activities, such as code repair. Nonetheless, the security implications of using LLMs for these purposes remain underexplored, particularly concerning the issue of API misuse. In this paper, we present an empirical study to observe the bug‐fixing capabilities of LLMs in addressing API misuse related to monitoring resource management (MRM API misuse). Initially, we propose APImisRepair, a real‐world benchmark for repairing MRM API misuse, including buggy programs, corresponding fixed programs, and descriptions of API misuse. Subsequently, we assess the performance of several LLMs using the APImisRepair benchmark. Findings reveal the vulnerabilities of LLMs in repairing MRM API misuse and find several reasons, encompassing factors such as fault localization and a lack of awareness regarding API misuse. Additionally, we have insights on improving LLMs in terms of their ability to fix MRM API misuse and introduce a crafted approach, APImisAP. Experimental results demonstrate that APImisAP exhibits a certain degree of improvement in the security of LLMs. [ABSTRACT FROM AUTHOR] |
|
Copyright of International Journal of Intelligent Systems is the property of Wiley-Blackwell and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) |
| Βάση Δεδομένων: |
Complementary Index |