Vulnerability description and repair suggestion generation method based on big language model reasoning and retrieval enhancement

By combining the inference ability and search enhancement technology of the large language model, a vulnerability knowledge base is built, and the problems of low vulnerability repair efficiency and insufficient targeting in the existing technology are solved, and a detailed vulnerability description and efficient repair suggestions are achieved quickly.

CN120145397APending Publication Date: 2025-06-13HARBIN INST OF TECH
View PDF 0 Cites 12 Cited by

Patent Information

Application Number
CN202510320737.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-13

Smart Images

  • Figure CN120145397A_ABST
    Figure CN120145397A_ABST
Patent Text Reader

Abstract

The invention discloses a big language model reasoning and retrieval enhancement-based vulnerability description and repair suggestion generation method, which comprises the following steps of: constructing a vulnerability knowledge base by integrating vulnerability databases such as CWE and CVE and an external knowledge source, providing prompt information of professional knowledge for a big language model, preprocessing a to-be-tested code by utilizing a code analysis tool, and generating a big language model reasoning and retrieval enhancement-based vulnerability description and repair suggestion. And extracting vulnerability knowledge most related to a to-be-detected code from the vulnerability knowledge base through semantic matching and code matching, generating detailed vulnerability description and repair suggestions by utilizing a large language model based on the related vulnerability knowledge obtained in the retrieval enhancement stage, and optimizing a generation result through a thinking chain technology. By combining the semantic comprehension ability, the retrieval enhancement technology and the reasoning enhancement technology of the large language model, detailed and targeted vulnerability description and repair suggestions can be quickly generated, the vulnerability repair efficiency is remarkably improved, and the method can be flexibly applied to existing vulnerability detection tools and is suitable for various programming languages and vulnerability types.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for describing software vulnerabilities and generating repair suggestions, and more particularly to a method for generating vulnerability descriptions and repair suggestions based on large language model (LLM) inference and retrieval enhancement. Background Art

[0002] In modern software development, the security of software systems is of utmost importance, and vulnerability repair is a crucial link in ensuring system security. Although significant progress has been made in vulnerability detection technology, which can efficiently identify potential vulnerabilities in software, vulnerability repair remains a complex and time-consuming process. After obtaining the vulnerability detection results, developers often need to spend a lot of time and effort analyzing the causes of the vulnerabilities, evaluating their potential impacts, and formulating reasonable repair strategies. This process places high demands on the experience and technical level of developers. Especially for less experienced developers, vulnerability repair can be a daunting task.

[0003] Existing vulnerability detection tools (such as static analysis tools and dynamic analysis tools) can provide basic information such as the location, type, and severity of vulnerabilities. However, these tools usually lack in-depth analysis of the causes of vulnerabilities, the scope of impact, and repair methods. For example, a SQL injection vulnerability may be caused by developers' failure to adequately validate and filter user input, while a buffer overflow vulnerability may be due to a lack of sufficient boundary checks in the code. The causes of these vulnerabilities are often related to details overlooked by developers during coding. Without in-depth analysis and understanding, it is difficult for developers to determine how to effectively fix them. Therefore, after receiving a vulnerability warning, developers often need to spend a large amount of additional time and effort analyzing the underlying causes of the vulnerability and finding appropriate repair solutions. This process is particularly difficult for less experienced developers. Due to a lack of sufficient vulnerability analysis and repair experience, they may not be able to accurately understand the causes of the vulnerability and may even take incorrect repair measures, resulting in the vulnerability not being completely resolved or new problems being introduced. For example, some developers may simply fix a SQL injection vulnerability by adding input validation but overlook other potential injection points, thus leaving the vulnerability still existing. Similarly, for a buffer overflow vulnerability, developers may add boundary checks but fail to correctly handle all possible boundary cases, making the vulnerability still exploitable. In addition, the existing vulnerability repair process also has the problem of low efficiency. Since the repair suggestions provided by vulnerability detection tools are often too general or lack pertinence, developers need to spend a lot of time consulting relevant documents, referring to cases, or discussing with other developers to formulate a reasonable repair strategy. This inefficient repair process not only extends the vulnerability repair time window, increasing the time the system is exposed to security risks, but may also lead to delays or errors during the repair process, further increasing the system's security risks.

[0004] To address the above issues, in recent years, researchers have begun to explore the use of artificial intelligence technologies, especially natural language processing (NLP) technologies, to assist in generating vulnerability repair suggestions. As a natural language processing technology based on deep learning, large language models have powerful semantic understanding and natural language generation capabilities. These models can generate richer and more detailed vulnerability descriptions based on the characteristics of the vulnerability, context information, and prompt information, and propose practical repair suggestions. For example, by analyzing the context information of a vulnerability, a large language model can infer the potential causes of the vulnerability and generate targeted repair suggestions to help developers understand and fix the vulnerability more quickly.

[0005] However, although large language models perform well in vulnerability description and repair suggestion generation, their performance is still subject to some limitations. First, the generation results of large language models often depend on the quality and coverage of their training data. If certain types of vulnerability cases are lacking in the training data, the model may not be able to accurately generate relevant repair suggestions. Second, the reasoning ability of large language models is limited and it is difficult to capture complex logical relationships, especially when the causes and repair logics of vulnerabilities may exhibit different forms in different contexts. Therefore, how to design an inference mechanism that enables the model to accurately capture these logical relationships and generate targeted repair suggestions remains an urgent problem to be solved. In addition, Retrieval-Augmented Generation (RAG) has also been introduced into the task of vulnerability repair suggestion generation. Retrieval-Augmented Generation improves the accuracy and practicality of the generated content by retrieving relevant information from an external knowledge base and combining it with the model's generation results. However, existing Retrieval-Augmented Generation technologies still face some challenges in practical applications. For example, the information extracted from the vulnerability database may be redundant or irrelevant to some extent. How to design an efficient retrieval algorithm to ensure that the extracted information is highly relevant to the current vulnerability description and repair suggestions remains a key issue. Summary of the Invention

[0006] To solve the problems of low efficiency and insufficient pertinence in generating vulnerability repair suggestions in the prior art, the present invention provides a method for generating vulnerability descriptions and repair suggestions based on large language model reasoning and retrieval augmentation. For the vulnerable code detected by the vulnerability detection tool, the goal of the present invention is to generate detailed and accurate vulnerability descriptions and repair suggestions by combining the semantic understanding ability of the large language model and the retrieval augmentation technology, so as to assist developers in quickly understanding the causes of vulnerabilities and formulating efficient repair strategies. Specifically, this method uses the natural language generation ability of the large language model, combines reasoning augmentation technology and retrieval augmentation technology, extracts context information related to vulnerabilities from a global perspective, and generates targeted repair suggestions. The present invention can be flexibly applied to existing vulnerability detection tools and is applicable to various programming languages and vulnerability types.

[0007] The purpose of the present invention is achieved through the following technical solutions:

[0008] A method for generating vulnerability descriptions and repair suggestions based on large language model reasoning and retrieval augmentation, comprising the following steps:

[0009] Step 1: Construction of vulnerability knowledge base:

[0010] Build a structured vulnerability knowledge base to provide prompt information of professional knowledge for large language models. The vulnerability knowledge base includes the definition, classification, semantic description, repair suggestions, and relevant context information of vulnerabilities. The specific steps are as follows:

[0011] Step 11: Integrate the CWE and CVE databases, extract the definitions, types, and their relevant information of vulnerabilities, and form a vulnerability classification system;

[0012] Step 12: Extract vulnerability codes and corresponding repair patches from external knowledge sources to enrich the content of the vulnerability knowledge base;

[0013] Step 13: Use large language models to generate function semantic descriptions for vulnerability example codes, and generate repair suggestions in combination with repair cases in the external knowledge base;

[0014] Step 14: Structurally store the vulnerability definitions, classifications, semantic descriptions, repair suggestions, and relevant context information, and use code parsing tools to generate code property graphs of vulnerability example codes;

[0015] Step 2: Retrieval enhancement stage:

[0016] Use the initial screening and fine ranking models to calculate the similarity between the semantic description of the code to be tested and the semantic descriptions of the vulnerability example codes in the vulnerability knowledge base, and screen out the vulnerability examples semantically related to the code to be tested. The specific steps are as follows:

[0017] Step 21: Preprocess the code to be tested: Preprocess the input code to be tested, including the generation of function semantic descriptions and the extraction of code property graphs;

[0018] Step 22: Matching retrieval:

[0019] Step 221: Respectively obtain the embedding vectors of the semantic descriptions of the code to be tested and the vulnerability example semantic descriptions through the initial screening model, calculate the semantic matching degree using cosine similarity, and screen out the vulnerability examples semantically related to the code to be tested by setting a threshold;

[0020] Step 222: After the initial screening is completed, the remaining vulnerability code examples enter the fine ranking model. The fine ranking model concatenates the semantic description of the code to be tested with the semantic descriptions of the vulnerability examples to form a new input vector, and then sends it into the RoBERTa model to obtain a matching score. Sort the vulnerability examples according to the matching score to ensure that the most relevant vulnerability examples are ranked first;

[0021] Step 223: In the code matching stage, use the twin graph neural network and weighted graph embedding and matching mechanism to calculate the similarity between the code to be tested and the vulnerability examples;

[0022] Step 23: Retrieval results:

[0023] Integrate the results of semantic matching and code matching, and extract the vulnerability examples most relevant to the code to be tested, their vulnerability descriptions, repair suggestions, and information on vulnerability-related statements;

[0024] Step 3: Inference Enhancement Phase:

[0025] Based on the relevant vulnerability knowledge obtained in the retrieval enhancement phase, use a large language model to generate detailed vulnerability descriptions and repair suggestions. The specific steps are as follows:

[0026] Step 31: The large language model performs semantic understanding on the code to be tested;

[0027] Step 32: After completing the code semantic understanding, the large language model conducts in-depth analysis of the identified potential vulnerabilities in combination with vulnerability-related statements;

[0028] Step 33: After completing the vulnerability analysis, the large language model generates a detailed vulnerability description;

[0029] Step 34: On the basis of generating the vulnerability description, the large language model further generates targeted repair suggestions;

[0030] Step 4: Output the generated vulnerability descriptions and repair suggestions to the developer for the developer to verify and adjust the repair plan.

[0031] Compared with the prior art, the present invention has the following advantages:

[0032] (1) By combining the semantic understanding ability of the large language model, retrieval enhancement technology, and inference enhancement technology, the present invention can quickly generate detailed and targeted vulnerability descriptions and repair suggestions, significantly improving the efficiency of vulnerability repair. Compared with the prior art that only provides simple information on the vulnerability location and type, the present invention can deeply analyze the causes and impacts of vulnerabilities and provide practical repair solutions.

[0033] (2) By utilizing the inference ability of the large language model and retrieval enhancement technology, the present invention realizes the intelligence and automation of generating vulnerability descriptions and repair suggestions. Developers do not need to manually analyze the deep causes of vulnerabilities, and the system can automatically generate detailed repair suggestions, reducing the technical threshold for vulnerability repair.

[0034] (3) The retrieval enhancement technology and inference enhancement mechanism of the present invention have high scalability and can continuously improve the generation effect with the update of the vulnerability knowledge base and the optimization of model training. Description of the Drawings

[0035] Figure 1 is the overall framework diagram of the method for generating vulnerability descriptions and repair suggestions based on large language model inference and retrieval enhancement of the present invention.

[0036] Figure 2 It is the prompt information for code semantic understanding in the inference enhancement step.

[0037] Figure 3 It is the prompt information for code vulnerability analysis in the inference enhancement step.

[0038] Figure 4 It is the prompt information for vulnerability description generation in the inference enhancement step.

[0039] Figure 5 It is the prompt information for the stage of generating repair suggestions in the inference enhancement step.

[0040] Figure 6 It is the example code and its vulnerability description.

[0041] Figure 7 It is the vulnerability description generated only using the large language model.

[0042] Figure 8 It is the repair suggestion generated only using the large language model.

[0043] Figure 9 It is the vulnerability description generated by the large language model after using the method of the present invention.

[0044] Figure 10 It is the repair suggestion generated by the large language model after using the method of the present invention. Detailed implementation manners

[0045] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings, but it is not limited thereto. Any modification or equivalent replacement of the technical solution of the present invention without departing from the spirit and scope of the technical solution of the present invention shall be covered by the protection scope of the present invention.

[0046] The present invention provides a method for generating vulnerability descriptions and repair suggestions based on large language model inference and retrieval enhancement. First, by integrating vulnerability databases such as CWE and CVE and external knowledge sources, a structured vulnerability knowledge base is constructed to provide prompt information of professional knowledge for the large language model. Then, a code parsing tool is used to preprocess the code to be tested, and the most relevant vulnerability knowledge is extracted from the vulnerability knowledge base through semantic matching and code matching. Finally, based on the relevant vulnerability knowledge obtained in the retrieval enhancement stage, the large language model is used to generate detailed vulnerability descriptions and repair suggestions, and the generation results are optimized through the chain of thought technology. As Figure 1 shown, it specifically includes the following steps:

[0047] Step 1: Construction of the vulnerability knowledge base:

[0048] Build a structured vulnerability knowledge base to provide prompt information of professional knowledge for large language models. The vulnerability knowledge base includes the definition, classification, semantic description, repair suggestions, and relevant context information of vulnerabilities. The specific steps are as follows:

[0049] Step 11: Integrate the CWE (Common Weakness Enumeration) and CVE (Common Vulnerabilities and Exposures) databases, extract the definitions, types, and related information of vulnerabilities, and form a vulnerability classification system.

[0050] Step 12: Extract vulnerability codes and corresponding repair patches from external knowledge sources such as vulnerability reports, open-source code libraries, and vulnerability datasets provided by relevant papers on vulnerabilities to enrich the content of the vulnerability knowledge base.

[0051] Step 13: Use large language models to generate function semantic descriptions for vulnerability example codes, and generate repair suggestions in combination with repair cases in external knowledge bases.

[0052] Step 14: Structurally store the vulnerability definitions, classifications, semantic descriptions, repair suggestions, and relevant context information, and use code parsing tools (such as Joern) to generate code property graphs of vulnerability example codes for the subsequent retrieval enhancement stage.

[0053] Step 2: Retrieval enhancement stage:

[0054] Use the initial screening and refined ranking models to calculate the similarity between the semantic description of the code to be tested and the semantic descriptions of vulnerability example codes in the vulnerability knowledge base, and screen out vulnerability examples semantically related to the code to be tested. The specific steps are as follows:

[0055] Step 21: Preprocessing of the code to be tested: Preprocess the input code to be tested, which mainly includes two parts: generation of function semantic descriptions and extraction of code property graphs. The specific steps are as follows:

[0056] Step 211: Generation of function semantic descriptions: Use advanced large language models (such as GPT-4o) to generate function semantic descriptions for the code to be tested, with the aim of expressing the functions and logics of the code to be tested in natural language for subsequent matching retrieval with the function semantic descriptions of other vulnerability code examples in the vulnerability knowledge base.

[0057] Step 212: Extraction of code property graph: By using the code parsing tool Joern to extract the code property graph (Yamaguchi F, Golde N, Arp D, Rieck K. Modeling and discovering vulnerabilities with code property graphs. In 2014 IEEE symposium on security and privacy 2014 May 18 (pp. 590 - 604). IEEE.), the code property graph can display the control flow and data flow of the code, better reflecting the structure and execution path of the code.

[0058] Step 22: Matching and retrieval:

[0059] Step 221: Preliminary screening using the primary screening model. At this stage, the present invention sets a threshold, and only the vulnerability code examples with a semantic matching degree exceeding this threshold can be retained. The primary screening model uses the fine-tuned RoBERTa. By respectively obtaining the embedding vectors of the semantic descriptions of the code to be tested and the vulnerability examples, the semantic matching degree is calculated using cosine similarity. This can quickly screen out the vulnerability examples that are semantically related to the code to be tested. Since the embedding vectors of the semantic descriptions of the vulnerability examples can be calculated and stored in the vulnerability knowledge base in advance, the calculation efficiency of the primary screening model is relatively high, which is suitable for large-scale screening of all examples in the knowledge base.

[0060] Step 222: After the primary screening is completed, the remaining vulnerability code examples will enter the refined ranking model for ranking. The refined ranking model is also based on the fine-tuned RoBERTa, but its training method is different from that of the primary screening model. The refined ranking model concatenates the semantic descriptions of the code to be tested and the vulnerability examples to form a new input vector, and then sends it into the RoBERTa model to obtain the matching score. Finally, the vulnerability examples are ranked according to the matching score to ensure that the most relevant vulnerability examples are ranked in the front. Since the concatenated vector needs to be re-input for each score calculation, the calculation efficiency of the refined ranking model is relatively low, but it is suitable for ranking a small number of samples retained after the primary screening.

[0061] Step 223: In the code matching stage, the present invention mainly calculates the similarity between the code to be tested and the vulnerability examples by using the Siamese graph neural network and the weighted graph embedding and matching mechanism. The specific steps are as follows:

[0062] Step 2231: For any statement node v of the code property graph i , use CodeBERT to generate its initial feature vector representation, denoted as x i .

[0063] Step 2232: Obtain the node hidden vector representation using a siamese graph neural network. The specific calculation formula is as follows:

[0064]

[0065] where and are the hidden vector representations of node v i after passing through the (l - 1)-th and l-th layers of siamese-GNN respectively; is the hidden vector representation of node v j , v j is a neighbor of v i , and there is an edge from v j to v i ; f is the propagation function of the Siamese-GNN model, which is used to collect information from neighbor nodes to update the state of the current node; z is the output function, which is used to calculate the final output feature vector o i of node v i . For different types of Siamese-GNN, the calculation methods of f and z are different. The present invention is a general method and does not limit the type of Siamese-GNN. Therefore, only the general formula is given here.

[0066] Step 2233: After obtaining the code property graph statement node representations of the code to be tested and the vulnerability example, further calculate their final vector representations using a weighted graph embedding mechanism, and calculate the similarity between the code to be tested and the vulnerability example. The specific steps are as follows:

[0067] Step 22331: For the known vulnerability example code, first calculate the weights based on its graph structure to highlight the vulnerability information. Specifically, the present invention calculates the data dependence weight and the control dependence weight, denoted by α and β respectively. For the data dependence weight, select the vulnerability node as the root node and assign it a weight of α r . If there is a node connected to the root node by at least k data dependence edges, then the data dependence weight of this node is α i =α r ·(L α ) k , where L α ∈(0,1) is the attenuation coefficient, which controls the attenuation rate of the data dependence weight. For the control dependence weight, also select as the root node, and the initial weight is β r . Assume that the node If it can be connected to the root node through at least k control dependence edges, its control dependence weight is β i = β r ·(L β ) k , where Lβ ∈ (0, 1) is the decay factor of the control dependence weight.

[0068] Through α i and β i , the weight of the node can be obtained, and the calculation formula is as follows:

[0069]

[0070] Among them, is the weight of the node , W S is the weight matrix of the node set V S , and n s is the number of statement nodes in the vulnerability example code.

[0071] Then, the final vector representation of the vulnerability example code can be obtained by combining the weight and the node representation matrix, and the calculation formula is as follows:

[0072] σ(·) = MaxPool(Relu(Conv(·)))

[0073] z s = AVG(MLP(σ(W S *O S )))

[0074] Among them, σ(·) is defined as a one-dimensional convolutional layer Conv with max pooling MasPool, Relu is the activation function, AVG is the average pooling, MLP represents the multi-layer perceptron, O S is the set of output feature vectors of the nodes, and z s is the final vector representation of the vulnerability example code.

[0075] Step 22332: For the code to be tested, the present invention uses the known vulnerability information and node attention mechanism in the vulnerability example to assign weights. Specifically, for any node in the code to be tested, the previously obtained z s and output vector are concatenated and input into the linear layer to calculate attention score, and then this score is used to assign weights. Finally, the final vector representation of the code to be tested is obtained in the same way as the vulnerability example, and the calculation formula is as follows:

[0076]

[0077] z f = AVG(MLP(σ(W F * O F )))

[0078] Among them, is the weight of node Linear is a fully connected layer, W F is the weight matrix of node set V F n f is the number of statement nodes in the code to be tested, z f is the final vector representation of the code to be tested.

[0079] Step 22333: Calculate the code similarity Code_similarity between the vulnerability example code and the code to be tested using cosine similarity. The calculation formula is as follows:

[0080]

[0081] Sort the retrieval results according to Code_similarity.

[0082] Step 23: Retrieval results:

[0083] Integrate the results of semantic matching and code matching, and extract information such as the vulnerability example most relevant to the code to be tested, its vulnerability description, repair suggestions, and vulnerability-related statements for the subsequent inference enhancement stage.

[0084] Step 3: Inference enhancement stage:

[0085] Based on the relevant vulnerability knowledge obtained in the retrieval enhancement stage, use a large language model to generate detailed vulnerability descriptions and repair suggestions. The specific steps are as follows:

[0086] Step 31: In the first step of the inference enhancement stage, the large language model needs to conduct in-depth semantic understanding of the code to be tested. This process is not just a superficial analysis of the code, but requires combining context information and vulnerability detection results to comprehensively understand the function and potential risks of the code. At the same time, it can also try to let the large language model itself locate potential security issues. The prompt information designed in this invention at this stage is as Figure 2 shown, where [CODE] is replaceable content, and the code to be tested needs to be provided here.

[0087] Step 32: After completing the code semantic understanding, if the vulnerability detection tool used has the ability to locate vulnerability statements, it can provide feedback on the vulnerability location result of the large language model in the previous step to further optimize the large language model's understanding of the code under test. In addition, the large language model can also conduct in-depth analysis of the identified potential vulnerabilities in combination with the vulnerability-related statements. Therefore, the prompt information constructed at this stage of the present invention is as Figure 3 shown. Among them, [STATEMENTS] is replaceable content, and the vulnerability-related statements located by the vulnerability detection tool can be provided here.

[0088] Step 33: After completing the vulnerability analysis, the large language model needs to generate a detailed vulnerability description. This process not only includes summarizing the basic information of the vulnerability but also needs to combine the retrieved relevant information to ensure the comprehensiveness and accuracy of the description. The prompt information constructed at this stage of the present invention is as Figure 4 shown. Among them, [EXAMPLE CODE] and [EXAMPLE DESCRIPTION] are replaceable content. According to the sorting result of retrieval enhancement, the vulnerability example and its vulnerability description that are most semantically relevant to the code under test and have the highest code matching degree are provided here.

[0089] Step 34: On the basis of generating the vulnerability description, the large language model can further generate targeted repair suggestions. This process also depends on the in-depth understanding and analysis of the vulnerability. The prompt information constructed at this stage of the present invention is as Figure 5 shown. Among them, [EXAMPLE CODE] and [FIX RECOMMENDATION] are replaceable content. According to the sorting result of retrieval enhancement, the vulnerability example and its repair suggestions that are most semantically relevant to the code under test and have the highest code matching degree are provided here.

[0090] Step 4: Output the generated vulnerability description and repair suggestions to the developer for the developer to verify and adjust the repair plan.

[0091] Example:

[0092] Taking the Figure 6 shown code vulnerability as an example, the statements marked with "-" in front are the vulnerability statements, and the statements marked with "+" are the patch statements for fixing the vulnerability. This code snippet shows the part of the ion_ioctl function that processes the ION_IOC_FREE command and also includes a reference vulnerability description. Specifically, the root cause of the vulnerability is that when the ION_IOC_FREE is called concurrently, multiple threads may access the same ion_handle instance simultaneously, resulting in a use-after-free vulnerability. When the method of the present invention is not used, the vulnerability description and repair suggestions generated by the large language model are asFigure 7 and Figure 8 As shown. From this result, the descriptions generated only using large language models mainly focus on a large number of potential problems in the code, such as improper error handling, memory leaks, insufficient user input validation, etc. Although the descriptions are relatively comprehensive, they fail to accurately identify the core problem of the use-after-free vulnerability. The descriptions are too general and lack an analysis of the specific mechanism of the vulnerability, resulting in a large deviation between the generated vulnerability descriptions and the actual situation. Furthermore, using only large language models to provide repair suggestions for this code also fails to accurately propose specific repair measures for the core problem of the use-after-free vulnerability. After using the method of the present invention, the vulnerability descriptions and repair suggestions generated by the model are as shown in Figure 9 and Figure 10 As shown. From this result, it can be seen that the descriptions generated by the model not only accurately identify the concurrent access problem of the vulnerability, but also detail the specific mechanism and potential impact of the use-after-free vulnerability. The description points out that the ion_handle handle may still be accessed after being released, resulting in memory corruption or security vulnerabilities. In addition, the model also details specific repair measures. The suggestion states that access to the ion_handle instance should be synchronized through reference counting and mutexes to ensure that the handle is not used by other threads before being released. In addition, the suggestion also emphasizes the importance of verifying the status of the handle before operating on it and proposes a strategy for delaying the release of the handle to allow ongoing operations to complete. These measures significantly reduce the risk of the use-after-free vulnerability and enhance the overall security of the ION driver. The method of the present invention combines the advantages of retrieval enhancement and inference enhancement, and the generated descriptions are both accurate and detailed, enabling developers to have a clear understanding of the vulnerability and repair suggestions.

Claims

1. A vulnerability description and repair suggestion generation method based on large language model reasoning and retrieval enhancement, characterized in that The method comprises the following steps: Step 1: Vulnerability knowledge base construction: Build a structured vulnerability knowledge base to provide professional knowledge prompt information for the large language model. The vulnerability knowledge base includes vulnerability definitions, classifications, semantic descriptions, repair suggestions, and related contextual information. Step 2: Retrieval enhancement phase: Using the preliminary screening and refined sorting models, the similarity between the semantic description of the code to be tested and the semantic description of the vulnerability sample code in the vulnerability knowledge base is calculated to screen out vulnerability samples that are semantically related to the code to be tested. Step 3: Reasoning enhancement phase: Based on the relevant vulnerability knowledge obtained in the retrieval enhancement phase, a large language model is used to generate detailed vulnerability descriptions and repair suggestions; Step 4: Output the generated vulnerability description and repair suggestions to the developer, allowing the developer to verify and adjust the repair plan.

2. The vulnerability description and repair suggestion generation method based on large language model reasoning and retrieval enhancement according to claim 1 is characterized in that The specific steps of step 1 are as follows: Step 11: Integrate the CWE and CVE databases, extract the definition, type and related information of the vulnerability, and form a vulnerability classification system; Step 12: Extract vulnerability codes and corresponding repair patches from external knowledge sources to enrich the content of the vulnerability knowledge base; Step 13: Use the large language model to generate function semantic descriptions for the vulnerability sample code, and generate repair suggestions based on the repair cases in the external knowledge base; Step 14: The vulnerability definition, classification, semantic description, repair suggestion and related context information are stored in a structured manner, and a code property graph of the vulnerability sample code is generated using a code parsing tool.

3. The vulnerability description and repair suggestion generation method based on large language model reasoning and retrieval enhancement according to claim 1 is characterized in that The specific steps of step 2 are as follows: Step 21: Preprocessing of the code to be tested: preprocessing the input code to be tested, including generating function semantic description and extracting code attribute graph; Step 22: Matching search: Step 221: Obtain the embedding vectors of the semantic description of the code to be tested and the semantic description of the vulnerability example through the preliminary screening model, calculate the semantic matching degree by using cosine similarity, and screen out the vulnerability examples that are semantically related to the code to be tested by setting a threshold; Step 222: After the initial screening is completed, the remaining vulnerability code examples enter the refined ranking model, which concatenates the semantic description of the code to be tested with the semantic description of the vulnerability example to form a new input vector, which is then sent to the RoBERTa model to obtain a matching score. The vulnerability examples are sorted according to the matching score to ensure that the most relevant vulnerability examples are ranked first; Step 223: In the code matching phase, the similarity between the code to be tested and the vulnerability example is calculated using the twin graph neural network and the weighted graph embedding and matching mechanism; Step 23: Retrieve Results: Integrate the results of semantic matching and code matching to extract the vulnerability examples most relevant to the code to be tested, as well as their vulnerability descriptions, repair suggestions, and vulnerability-related statement information.

4. The method for generating vulnerability description and repair suggestions based on large language model reasoning and retrieval enhancement according to claim 3 is characterized in that The specific steps of step 21 are as follows: Step 211: Generate function semantic description: Generate function semantic description for the code to be tested by using the large language model, and express the function and logic of the code to be tested in the form of natural language, so as to match and retrieve the function semantic description of other vulnerability code examples in the vulnerability knowledge base later; Step 212: Extraction of code property graph: Extract the code property graph by using the code parsing tool Joern.

5. The method for generating vulnerability description and repair suggestions based on large language model reasoning and retrieval enhancement according to claim 3 is characterized in that The specific steps of step 223 are as follows: Step 2231: For any statement node v in the code attribute graph i , using CodeBERT to generate its initial feature vector representation, counted as x i ; Step 2232: Use the twin graph neural network to obtain the node hidden vector representation. The specific calculation formula is as follows: in, and They are node v i Hidden vector representation obtained after l-1 and l layers of siamese-GNN; is node v j The hidden vector representation of j Yes i neighbors, and from v j to v i There is an edge; f is the propagation function of the Siamese-GNN model, which is used to collect information about neighboring nodes to update the state of the current node; z is the output function used to calculate the node v i The final output feature vector o i ; Step 2233: After obtaining the code attribute graph statement node representations of the code to be tested and the vulnerability example, a weighted graph embedding mechanism is used to further calculate the final vector representations of the two, and calculate the similarity between the code to be tested and the vulnerability example.

6. The method for generating vulnerability description and repair suggestions based on large language model reasoning and retrieval enhancement according to claim 5 is characterized in that The specific steps of step 2233 are as follows: Step 22331: For the known vulnerability sample code, first, calculate the data dependency weight and control dependency weight based on its graph structure, represented by α and β respectively. For the data dependency weight, select the vulnerability node As the root node, and give it a weight of α r , if there is a node With the root node If the node is connected by at least k data dependency edges, The data dependence weight is α i =α r ·(L α ) k , where L α ∈(0,1) is the decay coefficient, which controls the decay rate of the data-dependent weight; for controlling the dependent weight, choose is the root node, with an initial weight of β r , assuming that the node can be connected to the root node through at least k control dependency edges, then its control dependency weight is β i =β r ·(L β ) k , where L β ∈(0,1) is the attenuation factor that controls the dependency weight; By alpha i and β i , get the node The weight is calculated as follows: in, Is a node The weight, W S is the node set V S The weight matrix, n s is the number of statement nodes in the vulnerability sample code; Then, the final vector representation of the vulnerability sample code is obtained by combining the weights and the node representation matrix. The calculation formula is as follows: σ(·)=MaxPool(Relu(Conv(·))) With s =AVG(MLP(σ(W S *ABOUT S ))) Where σ(·) is defined as a one-dimensional convolutional layer Conv with maximum pooling MaxPool, Relu is the activation function, AVG is average pooling, MLP represents multi-layer perceptron, O S is the set of output feature vectors of the node, z s is the final vector representation of the vulnerable sample code; Step 22332: For the code to be tested, use the known vulnerability information in the vulnerability example and the node attention mechanism to assign weights. For any node in the code to be tested, The previously obtained z s and The output vector Connect and input into the linear layer to calculate The attention score is then used as Assign weights and finally obtain the final vector representation of the code to be tested in the same way as the vulnerability example. The calculation formula is as follows: With f =AVG(MLP(σ(W F *ABOUT F ))) in, Is a node The weight of Linear is a fully connected layer, W F is the node set V F The weight matrix, n f is the number of statement nodes in the code to be tested, z f is the final vector representation of the code under test; Step 22333: Use cosine similarity to calculate the code similarity Code_similarity between the vulnerability sample code and the code to be tested. The calculation formula is as follows: Sort the search results by Code_similarity.

7. The method for generating vulnerability description and repair suggestions based on large language model reasoning and retrieval enhancement according to claim 1 is characterized in that The specific steps of step 3 are as follows: Step 31: The large language model performs semantic understanding on the code to be tested; Step 32: After completing the semantic understanding of the code, the large language model combines vulnerability-related statements to conduct in-depth analysis of the identified potential vulnerabilities; Step 33: After completing the vulnerability analysis, the large language model generates a detailed vulnerability description; Step 34: Based on the generated vulnerability description, the large language model further generates targeted repair suggestions.

Citation Information

Cited By

  • Logical vulnerability knowledge base construction method and device based on large language model, electronic equipment and storage medium

    CN120373474A

  • Method, device, electronic device and storage medium for constructing a logical vulnerability knowledge base based on a large language model

    CN120373474B

  • Code evaluation and repair method based on large model technology

    CN120541851A

  • Code repair knowledge base construction method and device, computer equipment and medium

    CN120562537A

  • Methods, apparatus, computer equipment, and media for constructing a code repair knowledge base

    CN120562537B