{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T12:22:12Z","timestamp":1783513332945,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,12]],"date-time":"2026-04-12T00:00:00Z","timestamp":1775952000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,12]]},"DOI":"10.1145\/3786582.3786847","type":"proceedings-article","created":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T11:52:47Z","timestamp":1783511567000},"page":"241-245","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Not All Input Helps: What Information Should We Feed to LLMs for Vulnerability Repair?"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0003-6733-5737","authenticated-orcid":false,"given":"Dongwook","family":"Choi","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Sungkyunkwan University, Suwon, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-6557-8087","authenticated-orcid":false,"given":"Eunseok","family":"Lee","sequence":"additional","affiliation":[{"name":"College of Computing and Informatics, Sungkyunkwan University, Suwon, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,8]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"Baleegh Ahmad Shailja Thakur Benjamin Tan Ramesh Karri and Hammond Pearce. 2023. Fixing hardware security bugs with large language models. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2302.01215 (2023)."},{"key":"e_1_3_3_2_3_2","unstructured":"Berkay Berabi Alexey Gronskiy Veselin Raychev Gishor Sivanrupan Victor Chibotaru and Martin Vechev. 2024. Deepcode AI fix: Fixing security vulnerabilities with large language models. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2402.13291 (2024)."},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"crossref","unstructured":"Guru Bhandari Nikola Gavric and Andrii Shalaginov. 2025. Generating vulnerability security fixes with Code Language Models. Information and Software Technology (2025) 107786.","DOI":"10.1016\/j.infsof.2025.107786"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3475960.3475985"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"crossref","unstructured":"Zimin Chen Steve Kommrusch and Martin Monperrus. 2022. Neural transfer learning for repairing security vulnerabilities in c code. IEEE Transactions on Software Engineering 49 1 (2022) 147\u2013165.","DOI":"10.1109\/TSE.2022.3147265"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"crossref","unstructured":"Jianlei Chi Yu Qu Ting Liu Qinghua Zheng and Heng Yin. 2022. Seqtrans: automatic vulnerability fix via sequence to sequence learning. IEEE Transactions on Software Engineering 49 2 (2022) 564\u2013585.","DOI":"10.1109\/TSE.2022.3156637"},{"key":"e_1_3_3_2_8_2","unstructured":"Dongwook Choi. 2026. Github - Not All Input Helps: What Information Should We Feed to LLMs for Vulnerability Repair? https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/dwchoi95\/BILVR.git."},{"key":"e_1_3_3_2_9_2","volume-title":"2024 Vulnerability Statistics Report (9 ed.)","year":"2024","unstructured":"Edgescan. 2024. 2024 Vulnerability Statistics Report (9 ed.). Industry report. Edgescan. https:\/\/2.zoppoz.workers.dev:443\/https\/www.edgescan.com\/wp-content\/uploads\/2025\/04\/2024-Vulnerability-Statistics-Report.pdf"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"crossref","first-page":"592","DOI":"10.1109\/DSD67783.2025.00087","volume-title":"2025 28th Euromicro Conference on Digital System Design (DSD)","author":"Fakih Mohamad","year":"2025","unstructured":"Mohamad Fakih, Rahul Dharmaji, Halima Bouzidi, Gustavo\u00a0Quiros Araya, Oluwatosin Ogundare, Mst\u00a0Ayesha Siddika, and Mohammad\u00a0Abdullah Al\u00a0Faruque. 2025. Llm4cve: Enabling iterative automated vulnerability repair with large language models. In 2025 28th Euromicro Conference on Digital System Design (DSD). IEEE, 592\u2013599."},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"crossref","unstructured":"Michael Fu Van Nguyen Chakkrit Tantithamthavorn Dinh Phung and Trung Le. 2024. Vision transformer inspired automated vulnerability repair. ACM Transactions on Software Engineering and Methodology 33 3 (2024) 1\u201329.","DOI":"10.1145\/3632746"},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"crossref","unstructured":"Michael Fu Chakkrit Tantithamthavorn Trung Le Yuki Kume Van Nguyen Dinh Phung and John Grundy. 2024. Aibughunter: A practical tool for predicting classifying and repairing software vulnerabilities. Empirical Software Engineering 29 1 (2024) 4.","DOI":"10.1007\/s10664-023-10346-3"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC60848.2023.00085"},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"crossref","unstructured":"Xinyi Hou Yanjie Zhao Yue Liu Zhou Yang Kailong Wang Li Li Xiapu Luo David Lo John Grundy and Haoyu Wang. 2024. Large language models for software engineering: A systematic literature review. ACM Transactions on Software Engineering and Methodology 33 8 (2024) 1\u201379.","DOI":"10.1145\/3695988"},{"key":"e_1_3_3_2_17_2","unstructured":"Nafis\u00a0Tanveer Islam Mohammad\u00a0Bahrami Karkevandi and Peyman Najafirad. 2024. Code security vulnerability repair using reinforcement learning with large language models. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2401.07031 (2024)."},{"key":"e_1_3_3_2_18_2","unstructured":"Nafis\u00a0Tanveer Islam Joseph Khoury Andrew Seong Mohammad\u00a0Bahrami Karkevandi Gonzalo De La\u00a0Torre Parra Elias Bou-Harb and Peyman Najafirad. 2024. Llm-powered code vulnerability repair with reinforcement learning and semantic reward. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2401.03374 (2024)."},{"key":"e_1_3_3_2_19_2","first-page":"4401","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Kim Youngjoon","year":"2025","unstructured":"Youngjoon Kim, Sunguk Shin, Hyoungshick Kim, and Jiwon Yoon. 2025. Logs In, Patches Out: Automated Vulnerability Repair via { Tree-of-Thought}{ LLM} Analysis. In 34th USENIX Security Symposium (USENIX Security 25). 4401\u20134419."},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1145\/3664646.3664770","volume-title":"Proceedings of the 1st ACM International Conference on AI-Powered Software","author":"Kulsum Ummay","year":"2024","unstructured":"Ummay Kulsum, Haotian Zhu, Bowen Xu, and Marcelo d\u2019Amorim. 2024. A case study of llm for automated vulnerability repair: Assessing impact of reasoning and patch validation feedback. In Proceedings of the 1st ACM International Conference on AI-Powered Software. 103\u2013111."},{"key":"e_1_3_3_2_21_2","unstructured":"Yu Nong Mohammed Aldeen Long Cheng Hongxin Hu Feng Chen and Haipeng Cai. 2024. Chain-of-thought prompting of large language models for discovering and fixing software vulnerabilities. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2402.17230 (2024)."},{"key":"e_1_3_3_2_22_2","first-page":"4481","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Nong Yu","year":"2025","unstructured":"Yu Nong, Haoran Yang, Long Cheng, Hongxin Hu, and Haipeng Cai. 2025. { APPATCH} : Automated adaptive prompting large language models for { Real-World} software vulnerability patching. In 34th USENIX Security Symposium (USENIX Security 25). 4481\u20134500."},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"crossref","unstructured":"Rupam Patir Qiqing Huang Keyan Guo Wanda Guo Guofei Gu Haipeng Cai and Hongxin Hu. 2025. Towards LLM-Assisted Vulnerability Detection and Repair for Open-Source 5G UE Implementations. (2025).","DOI":"10.14722\/futureg.2025.23021"},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179324"},{"key":"e_1_3_3_2_25_2","unstructured":"Shuo Ren Daya Guo Shuai Lu Long Zhou Shujie Liu Duyu Tang Neel Sundaresan Ming Zhou Ambrosio Blanco and Shuai Ma. 2020. Codebleu: a method for automatic evaluation of code synthesis. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2009.10297 (2020)."},{"key":"e_1_3_3_2_26_2","unstructured":"VulnCheck. 2024. Danger is still lurking in the NVD backlog. https:\/\/2.zoppoz.workers.dev:443\/https\/vulncheck.com\/blog\/nvd-backlog-exploitation-lurking. Accessed: 16 December 2024."},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3691620.3695349"},{"key":"e_1_3_3_2_28_2","unstructured":"Ruoke Wang Zongjie Li Chaozheng Wang Yang Xiao and Cuiyun Gao. 2024. Navrepair: Node-type aware c\/c++ code vulnerability repair. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2405.04994 (2024)."},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"crossref","unstructured":"Ying Wei Lili Bo Xiaoxue Wu Yue Li Zhenlei Ye Xiaobing Sun and Bin Li. 2023. VulRep: vulnerability repair based on inducing commits and fixing commits. EURASIP Journal on Wireless Communications and Networking 2023 1 (2023) 34.","DOI":"10.1186\/s13638-023-02242-7"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598135"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"crossref","unstructured":"Lyuye Zhang Kaixuan Li Kairan Sun Daoyuan Wu Ye Liu Haoye Tian and Yang Liu. 2025. ACF ix: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts. IEEE Transactions on Software Engineering (2025).","DOI":"10.1109\/TSE.2025.3590108"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"crossref","unstructured":"Quanjun Zhang Chunrong Fang Bowen Yu Weisong Sun Tongke Zhang and Zhenyu Chen. 2023. Pre-trained model-based automated software vulnerability repair: How far are we? IEEE Transactions on Dependable and Secure Computing 21 4 (2023) 2507\u20132525.","DOI":"10.1109\/TDSC.2023.3308897"},{"key":"e_1_3_3_2_33_2","unstructured":"Zibin Zheng Kaiwen Ning Yanlin Wang Jingwen Zhang Dewu Zheng Mingxi Ye and Jiachi Chen. 2023. A survey of large language models for code: Evolution benchmarking and future trends. arXiv preprint arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/arXiv.org\/abs\/2311.10372 (2023)."},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"crossref","unstructured":"Xin Zhou Sicong Cao Xiaobing Sun and David Lo. 2025. Large language model for vulnerability detection and repair: Literature review and the road ahead. ACM Transactions on Software Engineering and Methodology 34 5 (2025) 1\u201331.","DOI":"10.1145\/3708522"},{"key":"e_1_3_3_2_35_2","unstructured":"Xin Zhou Sicong Cao Xiaobing Sun and David Lo. 2025. Large language model for vulnerability detection and repair: Literature review and the road ahead. https:\/\/2.zoppoz.workers.dev:443\/https\/docs.google.com\/document\/d\/18-UrkfH35CNMGRjjsDYZGK6L1aC9wP3GsKCtrIekcUQ\/edit?tab=t.0 Keywords."},{"key":"e_1_3_3_2_36_2","first-page":"1","volume-title":"Proceedings of the IEEE\/ACM 46th international conference on software engineering","author":"Zhou Xin","year":"2024","unstructured":"Xin Zhou, Kisub Kim, Bowen Xu, DongGyun Han, and David Lo. 2024. Out of sight, out of mind: Better automatic vulnerability repair by broadening input ranges and sources. In Proceedings of the IEEE\/ACM 46th international conference on software engineering. 1\u201313."},{"key":"e_1_3_3_2_37_2","doi-asserted-by":"crossref","unstructured":"Zhou Zhou Lili Bo Xiaoxue Wu Xiaobing Sun Tao Zhang Bin Li Jiale Zhang and Sicong Cao. 2022. SPVF: security property assisted vulnerability fixing via attention-based models. Empirical Software Engineering 27 7 (2022) 171.","DOI":"10.1007\/s10664-022-10216-4"}],"event":{"name":"ICSE-NIER '26: 2026 IEEE\/ACM 48th International Conference on Software Engineering","location":"Rio de Janeiro Brazil","acronym":"ICSE-NIER '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the IEEE\/ACM 48th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3786582.3786847","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T11:53:58Z","timestamp":1783511638000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3786582.3786847"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":36,"alternative-id":["10.1145\/3786582.3786847","10.1145\/3786582"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3786582.3786847","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-07-08","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}