Ensuring timely and accurate security patches is crucial for maintaining software integrity in the face of evolving vulnerabilities. This paper presents a comprehensive study on developing and applying advanced AI and deep learning models for improving security patch management. It examines the challenges in automated program repair for complex security vulnerabilities and explores the use of large language models (LLMs) to focus repair efforts on relevant code sections. Deep learning methods for vulnerability detection are also analyzed, including a new dataset of over 18,000 vulnerable functions from security-related commits. The study also reviews machine learning and deep learning applications for detecting vulnerabilities in Internet of Things (IoT) devices, addressing current limitations such as high false-positive rates and generalization difficulties. Promising research directions, such as source code-specific pre-training models, are identified to enhance the future performance of AI-driven vulnerability detection systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Deep Learning Techniques for Enhancing the Efficiency of Security Patch Development

  • Zeinab Shahbazi,
  • Meshkat Mesbah

摘要

Ensuring timely and accurate security patches is crucial for maintaining software integrity in the face of evolving vulnerabilities. This paper presents a comprehensive study on developing and applying advanced AI and deep learning models for improving security patch management. It examines the challenges in automated program repair for complex security vulnerabilities and explores the use of large language models (LLMs) to focus repair efforts on relevant code sections. Deep learning methods for vulnerability detection are also analyzed, including a new dataset of over 18,000 vulnerable functions from security-related commits. The study also reviews machine learning and deep learning applications for detecting vulnerabilities in Internet of Things (IoT) devices, addressing current limitations such as high false-positive rates and generalization difficulties. Promising research directions, such as source code-specific pre-training models, are identified to enhance the future performance of AI-driven vulnerability detection systems.