LLMPort: Cross-file Patch Porting via Task Decomposition and Self-correction
Bofei Chen, Lei Zhang, Peng Deng, Nan Wang, Haoyu Xu, Mingda Guo, Yuan Zhang, Min Yang
摘要
Security patch porting aims to adapt patches developed for one software version so they can be used in another version. This approach is crucial for maintaining the security of software systems over time. However, existing works often rely on predefined rules to understand patches, limiting their generalizability and portability. Additionally, they are ineffective when porting complex patches that involve numerous modified code lines across multiple files, which is common in real-world software, especially Java applications. To overcome these obstacles, we propose a novel patch porting framework, called LLMPORT. First, LLMPORT breaks down the complex patch porting task into distinct subtasks, each containing an atomic code unit from the original patch. This enhances the LLMs' focus. Second, for each subtask, LLMPORT extracts the minimal patch-related code context and constructs a prompt with task-specific domain knowledge to guide the LLM in porting the patch code to the target version. Third, LLMPORT implements a progressive self-correction system to automatically assess the correctness of the generated patch, and identify and correct error subtasks based on LLMs' selfcorrection capabilities. We evaluate LLMPORT for porting Java language patches on a large-scale dataset, including 1,992 unique patch file pairs, and it successfully ports 91.92% of them. To assess the portability of LLMPORT, we also evaluate its capability to port C language patches. The results show that it outperforms state-of-the-art approaches, including TSBPORT and FixMorph. LLMPORT also discovers five 0-day vulnerabilities due to incomplete patches and the developers received and merged the new patches generated by LLMPORT into the official code branches.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Large Language Models Can Be Easily Distracted by Irrelevant ContextFreda Shi, Xinyun Chen, Kanishka Misra, Nathan Scales 等ICML 2023 · 被引用 970 次
- Decomposed Prompting: A Modular Approach for Solving Complex TasksTushar Khot, Harsh Trivedi, Matthew Finlayson, Yao Fu 等ICLR 2023 · 被引用 94 次
- Facilitating Vulnerability Assessment through PoC MigrationJiarun Dai, Yuan Zhang, Hailong Xu, Haiming Lyu 等CCS 2021 · 被引用 26 次
- Automated patch backporting in Linux (experience paper)Ridwan Shariffdeen, Xiang Gao, Gregory J. Duck, Shin Hwei Tan 等ISSTA 2021 · 被引用 23 次
- PatchScope: Memory Object Centric Patch DiffingLei Zhao, Yuncong Zhu, Jiang Ming, Yichen Zhang 等CCS 2020 · 被引用 21 次
相关 Paper
- PatchPorter: LLM-Driven Security Patch Porting via Version Tracing and Context Selection for NPMZeliang Yu, Ming Wen, Zichao Wei, Yulun Wu 等ISSTA 2026 · 被引用 1 次
- PortGPT: Towards Automated Backporting Using Large Language ModelsZhaoyang Li, Zheng Yu, Jingyi Song, Meng Xu 等S&P 2026 · 被引用 2 次
- BackportBench: A Multilingual Benchmark for Automated Patch BackportingZhiqing Zhong, Jiaming Huang, Pinjia HeFSE 2026 · 被引用 1 次
- Automating Zero-Shot Patch Porting for Hard ForksShengyi Pan, You Wang, Zhongxin Liu, Xing Hu 等ISSTA 2024 · 被引用 5 次
- Mystique: Automated Vulnerability Patch Porting with Semantic and Syntactic-Enhanced LLMSusheng Wu, Ruisi Wang, Yiheng Cao, Bihuan Chen 等FSE 2025 · 被引用 2 次
