REVIEW 6 cited by
A Contemporary Survey of Large Language Model Assisted Program Analysis
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
The increasing complexity of software systems has driven significant advancements in program analysis, as traditional methods unable to meet the demands of modern software development. To address these limitations, deep learning techniques, particularly Large Language Models (LLMs), have gained attention due to their context-aware capabilities in code comprehension. Recognizing the potential of LLMs, researchers have extensively explored their application in program analysis since their introduction. Despite existing surveys on LLM applications in cybersecurity, comprehensive reviews specifically addressing their role in program analysis remain scarce. In this survey, we systematically review the application of LLMs in program analysis, categorizing the existing work into static analysis, dynamic analysis, and hybrid approaches. Moreover, by examining and synthesizing recent studies, we identify future directions and challenges in the field. This survey aims to demonstrate the potential of LLMs in advancing program analysis practices and offer actionable insights for security researchers seeking to enhance detection frameworks or develop domain-specific models.
Forward citations
Cited by 6 Pith papers
-
Mystra: Declarative Dynamic Taint Analysis via Shadow Virtual Machine
A Shadow Virtual Machine plus declarative Mystra rules delivers portable multi-level DTA for JS/Python with 95.5% recall and 1.85× overhead on Node.js.
-
Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection
A jointly optimized gradient-mask plus band-aid patch reportedly bypasses visible-infrared fused face detectors with >90% attack success in both digital and physical settings.
-
ATLAS: Multi-View Code Representation Tool for C and C++ Source Programs
ATLAS claims no-build aligned AST/CFG/DFG extraction for C/C++ at 96.8%/91.7% CFG correctness, and a 34.7-point LLM line-coverage lift when fed its CFG paths.
-
LLM as an Execution Estimator: Recovering Missing Dependency for Practical Time-travelling Debugging
RecovSlicing recovers dynamic data dependencies from partially recorded execution traces by using a language model to reconstruct missed variable values and aliases.
-
Empirical Evaluation of Concept Drift in ML-Based Android Malware Detection
Concept drift consistently lowers Android malware detection accuracy across nine machine learning and deep learning algorithms and two large language models, on two datasets.
-
Detecting Vulnerability-Inducing Commits via Multi-Stage Reasoning with LLM-Based Agents
A multi-agent, multi-stage LLM framework (VIC-RAGENT) outperforms direct prompting, CoT, and CodeAgent baselines on F1-score for detecting vulnerability-inducing commits on the V-SZZ dataset.
Discussion (0). Continue with ORCID to comment.