PatchPorter: LLM-Driven Security Patch Porting via Version Tracing and Context Selection for NPM
Zeliang Yu, Ming Wen, Zichao Wei, Yulun Wu, Deqing Zou, Hai Jin
摘要
Third-Party Libraries are widely used in modern software development, yet their vulnerabilities pose serious security risks. This issue is particularly severe in the NPM ecosystem, where high-risk 1-day vulnerabilities can remain unpatched for extended periods. Although upgrading to the latest patched version is commonly recommended, it often causes major compatibility issues. Patch porting offers an effective solution to this challenge. However, existing patch porting methods are mainly designed for C and have two limitations when applied to NPM. First, they can be brittle in precisely localizing fix locations when substantial semantic gaps exist across versions. Second, they rely on either excessive or insufficient context for patch adaptation, which may introduce redundant information and increase the risk of hallucination. This paper introduces PatchPorter, a method for single-branch security patch porting in NPM that builds on Large Language Models (LLMs). PatchPorter addresses these limitations through two modules. The localization module leverages LLM semantic understanding and code evolution analysis over version histories maintained by version control systems to identify fix locations. The context selection module analyzes patch dependencies to select minimal yet sufficient context around the localized fix location. The selected context is used as input for the LLM to generate the patch. We construct a dataset of 112 NPM vulnerabilities with Proof- of-Concepts for dynamic validation. Experimental results show that PatchPorter significantly surpasses other methods in accuracy, achieving a 26.23% improvement over the best-performing baseline and a 70.59% increase on the most difficult tasks. Its ability to handle various vulnerability types highlights its practical value. Additional results confirm that both of its main modules also outperform alternative approaches.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- LLMPort: Cross-file Patch Porting via Task Decomposition and Self-correctionBofei Chen, Lei Zhang, Peng Deng, Nan Wang 等ASE 2025
- BackportBench: A Multilingual Benchmark for Automated Patch BackportingZhiqing Zhong, Jiaming Huang, Pinjia HeFSE 2026 · 被引用 1 次
- Mystique: Automated Vulnerability Patch Porting with Semantic and Syntactic-Enhanced LLMSusheng Wu, Ruisi Wang, Yiheng Cao, Bihuan Chen 等FSE 2025 · 被引用 2 次
- LLMBisect: Breaking Barriers in Bug Bisection with A Comparative Analysis PipelineZheng Zhang, Haonan Li, Xingyu Li, Hang Zhang 等NDSS 2026 · 被引用 1 次
- Maltracker: A Fine-Grained NPM Malware Tracker Copiloted by LLM-Enhanced DatasetZeliang Yu, Ming Wen, Xiaochen Guo, Hai JinISSTA 2024 · 被引用 16 次
