Lune

ISSTA2026Top-tier venue

Understanding and Improving Model Editing for Secure Code Generation

Weifeng Sun, Quanjun Zhang, Yuchen Chen, Chengran Yang, Gou Tan, David Lo

2026Year

Abstract

Large language models (LLMs) are widely used for code generation, yet they can reproduce vulnerable code implementations learned from insecure patterns in training data. Prior work has primarily explored inference-time hardening to reduce insecure generations without updating the target model. While effective, this paradigm couples security behavior to the auxiliary component and incurs additional runtime overhead. This paper presents the first systematic empirical study of applying model editing as the model-level hardening mechanism for secure code generation. Unlike inference-time interventions, model editing updates a small subset of parameters to inject security-relevant knowledge directly into the target LLM. We evaluate 3 stateof-the-art editing methods across diverse LLM families and compare them with CoSec, a representative inference-time hardening approach, focusing on: (i) security effectiveness and robustness, (ii) generalization to unseen vulnerabilities, and (iii) functional correctness on general programming tasks. Our results show that model editing yields substantially larger security gains than CoSec on seen vulnerability types, improving security ratios by 15%-25% over vanilla models, and these gains remain stable under prompt perturbations. However, security improvements do not always transfer reliably to unseen vulnerabilities and induce functional regressions on general programming tasks, even for UltraEdit, the best-performing editing method in our evaluation. To mitigate this side effect, we propose SafeEdit, a post-edit refinement method that combines functional tuning with edit-aware regularization. Across eight target LLMs, SafeEdit improves Pass@1 over UltraEdit by +11.73/+13.70/+15.50 percentage points at 𝑇 = 0.1/0.4/0.8, while largely preserving security. Compared with CoSec, it achieves relative security-ratio gains of +7.54%-12.04%. Additional evaluation on CodeGuard+ confirms that SafeEdit improves joint secure-and-correct generation. Importantly, SafeEdit and CoSec are complementary: combining them can improve security under stochastic decoding while maintaining strong functional correctness. Finally, we analyze efficiency and key design factors, showing that model editing is more efficient than CoSec and sensitive to editing depth, parameter location, and injected context. Overall, our work provides evidence-backed guidance for applying model editing to secure code generation.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext eaf477cb-cc4f-4b64-b1f2-3f3767b5bb56

Builds on25

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines