{"id":"https://openalex.org/W7167719581","doi":"https://doi.org/10.1145/3786582.3786847","title":"Not All Input Helps: What Information Should We Feed to LLMs for Vulnerability Repair?","display_name":"Not All Input Helps: What Information Should We Feed to LLMs for Vulnerability Repair?","publication_year":2026,"publication_date":"2026-04-12","ids":{"openalex":"https://openalex.org/W7167719581","doi":"https://doi.org/10.1145/3786582.3786847"},"language":null,"primary_location":{"id":"doi:10.1145/3786582.3786847","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3786582.3786847","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the IEEE/ACM 48th International Conference on Software Engineering","raw_type":"proceedings-article"},"type":"conference-paper","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3786582.3786847","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5140256751","display_name":"Dongwook Choi","orcid":"https://orcid.org/0009-0003-6733-5737"},"institutions":[{"id":"https://openalex.org/I848706","display_name":"Sungkyunkwan University","ror":"https://ror.org/04q78tk20","country_code":"KR","type":"education","lineage":["https://openalex.org/I848706"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Dongwook Choi","raw_affiliation_strings":["Department of Computer Science and Engineering, Sungkyunkwan University, Suwon, Republic of Korea"],"raw_orcid":"https://orcid.org/0009-0003-6733-5737","affiliations":[{"raw_affiliation_string":"Department of Computer Science and Engineering, Sungkyunkwan University, Suwon, Republic of Korea","institution_ids":["https://openalex.org/I848706"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5015550942","display_name":"Eunseok Lee","orcid":"https://orcid.org/0000-0002-6557-8087"},"institutions":[{"id":"https://openalex.org/I848706","display_name":"Sungkyunkwan University","ror":"https://ror.org/04q78tk20","country_code":"KR","type":"education","lineage":["https://openalex.org/I848706"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Eunseok Lee","raw_affiliation_strings":["College of Computing and Informatics, Sungkyunkwan University, Suwon, Republic of Korea"],"raw_orcid":"https://orcid.org/0000-0002-6557-8087","affiliations":[{"raw_affiliation_string":"College of Computing and Informatics, Sungkyunkwan University, Suwon, Republic of Korea","institution_ids":["https://openalex.org/I848706"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I848706"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.92838897,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"241","last_page":"245"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.2353000044822693,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.2353000044822693,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.18549999594688416,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.1331000030040741,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.7218999862670898},{"id":"https://openalex.org/keywords/metadata","display_name":"Metadata","score":0.6026999950408936},{"id":"https://openalex.org/keywords/redundancy","display_name":"Redundancy (engineering)","score":0.5935999751091003},{"id":"https://openalex.org/keywords/identifier","display_name":"Identifier","score":0.564300000667572},{"id":"https://openalex.org/keywords/vulnerability-assessment","display_name":"Vulnerability assessment","score":0.5376999974250793},{"id":"https://openalex.org/keywords/categorization","display_name":"Categorization","score":0.5065000057220459},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.3547999858856201}],"concepts":[{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.7218999862670898},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.628600001335144},{"id":"https://openalex.org/C93518851","wikidata":"https://www.wikidata.org/wiki/Q180160","display_name":"Metadata","level":2,"score":0.6026999950408936},{"id":"https://openalex.org/C152124472","wikidata":"https://www.wikidata.org/wiki/Q1204361","display_name":"Redundancy (engineering)","level":2,"score":0.5935999751091003},{"id":"https://openalex.org/C154504017","wikidata":"https://www.wikidata.org/wiki/Q853614","display_name":"Identifier","level":2,"score":0.564300000667572},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.5376999974250793},{"id":"https://openalex.org/C94124525","wikidata":"https://www.wikidata.org/wiki/Q912550","display_name":"Categorization","level":2,"score":0.5065000057220459},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.5056999921798706},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5049999952316284},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.3547999858856201},{"id":"https://openalex.org/C2775945657","wikidata":"https://www.wikidata.org/wiki/Q381442","display_name":"Structuring","level":2,"score":0.3492000102996826},{"id":"https://openalex.org/C12174686","wikidata":"https://www.wikidata.org/wiki/Q1058438","display_name":"Risk assessment","level":2,"score":0.3452000021934509},{"id":"https://openalex.org/C172776598","wikidata":"https://www.wikidata.org/wiki/Q7943570","display_name":"Vulnerability management","level":4,"score":0.3343000113964081},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.3197999894618988},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.3005000054836273},{"id":"https://openalex.org/C180198813","wikidata":"https://www.wikidata.org/wiki/Q121182","display_name":"Information system","level":2,"score":0.26089999079704285},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.257999986410141}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3786582.3786847","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3786582.3786847","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the IEEE/ACM 48th International Conference on Software Engineering","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3786582.3786847","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3786582.3786847","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the IEEE/ACM 48th International Conference on Software Engineering","raw_type":"proceedings-article"},"sustainable_development_goals":[{"score":0.43642228841781616,"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":21,"referenced_works":["https://openalex.org/W3091588759","https://openalex.org/W3094130708","https://openalex.org/W3156480510","https://openalex.org/W3183469243","https://openalex.org/W4297902814","https://openalex.org/W4308641648","https://openalex.org/W4366771352","https://openalex.org/W4378942602","https://openalex.org/W4385187279","https://openalex.org/W4386231786","https://openalex.org/W4388638461","https://openalex.org/W4388826738","https://openalex.org/W4393406994","https://openalex.org/W4400484609","https://openalex.org/W4402665833","https://openalex.org/W4403537098","https://openalex.org/W4405543707","https://openalex.org/W4410815357","https://openalex.org/W4412567570","https://openalex.org/W4413462356","https://openalex.org/W4417169356"],"related_works":[],"abstract_inverted_index":{"Software":[0],"vulnerabilities":[1],"pose":[2],"significant":[3],"security":[4],"risks,":[5],"and":[6,71,73,89,102,142],"timely":[7],"repair":[8,49,97,115],"is":[9],"essential":[10],"for":[11,140],"mitigating":[12],"potential":[13],"exploits.":[14],"Large":[15],"Language":[16],"Models":[17],"(LLMs)":[18],"have":[19],"shown":[20],"promise":[21],"in":[22,90],"automating":[23],"vulnerability":[24,48,96,149],"repair,":[25],"but":[26],"their":[27],"effectiveness":[28],"heavily":[29],"depends":[30],"on":[31,46,133],"the":[32,40,58,93,125],"input":[33,44,59,110,144],"information":[34,60,145],"provided.":[35],"This":[36],"paper":[37],"systematically":[38],"investigates":[39],"impact":[41],"of":[42,95],"different":[43],"types":[45,111],"LLM-based":[47,148],"performance.":[50],"We":[51],"surveyed":[52],"26":[53],"recent":[54],"studies":[55],"to":[56,114,128,146],"categorize":[57],"used,":[61],"including":[62],"vulnerable":[63,66],"code":[64],"snippets,":[65],"line":[67],"markers,":[68],"CVE/CWE":[69],"identifiers":[70],"descriptions,":[72],"additional":[74],"metadata":[75],"such":[76],"as":[77],"patch":[78],"context.":[79],"Through":[80],"extensive":[81],"experiments,":[82],"we":[83,136],"analyzed":[84],"how":[85],"these":[86],"inputs,":[87],"individually":[88],"combination,":[91],"influence":[92],"accuracy":[94],"across":[98],"various":[99],"LLM":[100],"architectures":[101],"datasets.":[103],"Our":[104],"findings":[105],"reveal":[106],"that":[107,123],"not":[108],"all":[109],"contribute":[112],"positively":[113],"performance;":[116],"some":[117],"may":[118],"introduce":[119],"noise":[120],"or":[121],"redundancy":[122],"hinders":[124],"model\u2019s":[126],"ability":[127],"generate":[129],"effective":[130],"patches.":[131],"Based":[132],"our":[134],"analysis,":[135],"provide":[137],"practical":[138],"guidelines":[139],"selecting":[141],"structuring":[143],"optimize":[147],"repair.":[150]},"counts_by_year":[],"updated_date":"2026-07-29T14:22:42.915294","created_date":"2026-07-09T00:00:00"}
