SpecAuditor: Generating Audit Specifications for LLM-Driven Bug Detection
Miaoqian Lin, Hao Chen
Abstract
Static analysis has been widely used for bug detection in real-world systems. However, traditional static analysis depends on manually written rules that match specific code forms. They often fail to handle semantically equivalent code variants and diverse bug patterns. Recent advances in large language models (LLMs) provide new opportunities for bug detection due to their capability to understand code semantics. However, directly applying LLMs to bug auditing is ineffective and expensive. Without clear guidance, LLMs fall back on memorized common patterns. They struggle with system-specific semantics and rare bug patterns that require domain knowledge. Therefore, it is necessary to provide high-quality audit specifications that clearly describe where to audit and under what conditions a bug occurs, for guiding LLMs to perform effective bug detection. In this paper, we propose SpecAuditor, an end-to-end framework that automatically generates and applies audit specifications for LLM-driven bug detection. SpecAuditor leverages historical bug patches to obtain specifications and then uses them to detect new bugs. Instead of directly extracting syntactic patterns from patches, SpecAuditor generalizes specifications at the semantic level to obtain new, broader specifications, thereby significantly extending the coverage of bug detection. In particular, SpecAuditor proceeds in three stages: (1) It extracts seed specifications from bug patches and validates them via differential checking. (2) It generalizes each seed specification to capture its underlying behavior and uses documentation-based semantic retrieval to identify other code entities performing similar behaviors, generating new specifications for them. (3) It performs LLM-driven bug detection by combining AST-based code search with LLM-based semantic auditing, followed by context-aware report pruning to reduce false positives. Our evaluation on the Linux kernel shows that SpecAuditor generates diverse specifications that go beyond syntactic patterns seen in patches. Using these specifications, SpecAuditor detects 71 long-latent new bugs, with an average lifetime of more than 7 years, including memory leaks, use-after-free, and out-of-bounds bugs. To date, 52 bugs have been confirmed by maintainers and 37 have been fixed. Moreover, 21 of the bug patches have been backported to the Linux stable trees for long-term release stability.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 1a4879bb-6c98-4f23-a298-5e6919940902Cited by top-tier papers1
Ask how each one uses itRelated papers
- KNighter: Transforming Static Analysis with LLM-Synthesized CheckersChenyuan Yang, Zijie Zhao, Zichen Xie, Haoyu Li et al.SOSP 2025 · 1 citation
- RFCAudit: AI Agent for Auditing Protocol Implementations Against RFC SpecificationsMingwei Zheng, Chengpeng Wang, Xuwei Liu, Jinyao Guo et al.ASE 2025 · 5 citations
- Mining Long Tail Bugs: Identifying Rare and Overlooked Issues in CodeWentao Liang, Yanjun Wu, Xiang Ling, Tianyue Luo et al.FSE 2026
- LLMSQLMUTATOR: LLM-Powered Test Case Generation for Database Using Bug ReportsChenglin Tian, Chaofan Li, Yawen Li, Yingxia ShaoICDE 2026
- Towards More Accurate Static Analysis for Taint-Style Bug Detection in Linux KernelHaonan Li, Hang Zhang, Kexin Pei, Zhiyun QianASE 2025 · 5 citations
