Mystique: Automated Vulnerability Patch Porting with Semantic and Syntactic-Enhanced LLM
Susheng Wu, Ruisi Wang, Yiheng Cao, Bihuan Chen, Zhuotong Zhou, Yiheng Huang, Junpeng Zhao, Xin Peng
Abstract
Branching repositories facilitates efficient software development but can also inadvertently propagate vulnerabilities. When an original branch is patched, other unfixed branches remain vulnerable unless the patch is successfully ported. However, due to inherent discrepancies between branches, many patches cannot be directly applied and require manual intervention, which is time-consuming and leads to delays in patch porting, increasing vulnerability risks. Existing automated patch porting approaches are prone to errors, as they often overlook essential semantic and syntactic context of vulnerability and fail to detect or refine faulty patches. We propose Mystique, a novel LLM-based approach to address these limitations. Mystique first slices the semantic-related statements linked to the vulnerability while ensuring syntactic correctness, allowing it to extract the signatures for both the original patched function and the target vulnerable function. Mystique then utilizes a fine-tuned LLM to generate a fixed function, which is further iteratively checked and refined to ensure successful porting. Our evaluation shows that Mystique achieved a success rate of 0.954 at function level and of 0.924 at CVE level, outperforming state-of-the-art approaches by at least 13.2% at function level and 12.3% at CVE level. Our evaluation also demonstrates Mystique’s superior generality across various projects, bugs, and programming languages. Mystique successfully ported patches for 34 real-world vulnerable branches.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- PortGPT: Towards Automated Backporting Using Large Language ModelsZhaoyang Li, Zheng Yu, Jingyi Song, Meng Xu et al.S&P 2026 · 2 citations
- Recurring Vulnerability Detection: How Far Are We?Yiheng Cao, Susheng Wu, Ruisi Wang, Bihuan Chen et al.ISSTA 2025 · 1 citation
- Break to Adapt: Knowledge-Based Updates of Breaking Dependencies in JavaScriptYifan Xia, Chengwei Liu, Zifan Xie, Lyuye Zhang et al.FSE 2026
- From Assistance to Autonomy: An Empirical Study of AI Use in a Live Capture-the-Flag (CTF) CompetitionTingxuan Tang, Nicolas Janis, Kalyn Asher Montague, Kevin Eykholt et al.USENIX Security 2026
- Characterizing Regression Bug‑Inducing Changes and Improving LLM‑Based Regression Bug DetectionXuezhi Song, Yijian Wu, Bihuan Chen, Zhengjie Lu et al.ICSE 2026
Builds on18
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu et al.ICLR 2022 · 18,833 citations
- Automated Program Repair in the Era of Large Pre-trained Language ModelsChunqiu Steven Xia, Yuxiang Wei, Lingming ZhangICSE 2023 · 321 citations
- Less training, more repairing please: revisiting automated program repair via zero-shot learningChunqiu Steven Xia, Lingming ZhangFSE 2022 · 223 citations
- Automated Repair of Programs from Large Language ModelsZhiyu Fan, Xiang Gao, Martin Mirchev, Abhik Roychoudhury et al.ICSE 2023 · 213 citations
- Copiloting the Copilots: Fusing Large Language Models with Completion Engines for Automated Program RepairYuxiang Wei, Chunqiu Steven Xia, Lingming ZhangFSE 2023 · 111 citations
Related papers
- PatchPorter: LLM-Driven Security Patch Porting via Version Tracing and Context Selection for NPMZeliang Yu, Ming Wen, Zichao Wei, Yulun Wu et al.ISSTA 2026 · 1 citation
- LLMPort: Cross-file Patch Porting via Task Decomposition and Self-correctionBofei Chen, Lei Zhang, Peng Deng, Nan Wang et al.ASE 2025
- LLMBisect: Breaking Barriers in Bug Bisection with A Comparative Analysis PipelineZheng Zhang, Haonan Li, Xingyu Li, Hang Zhang et al.NDSS 2026 · 1 citation
- Code Change Intention, Development Artifact, and History Vulnerability: Putting Them Together for Vulnerability Fix Detection by LLMXu Yang, Wenhan Zhu, Michael Pacheco, Jiayuan Zhou et al.FSE 2025 · 5 citations
- Not Every Patch is an Island: LLM-Enhanced Identification of Multiple Vulnerability PatchesYi Song, Dongchen Xie, Lin Xu, He Zhang et al.ASE 2025
