kirancodes.me
To Proof Maintenance & Beyond!

Mystique: Automated Vulnerability Patch Porting with Semantic and Syntactic-Enhanced LLM

Susheng Wu, Ruisi Wang, Yiheng Cao, Bihuan Chen, Zhuotong Zhou, Yiheng Huang, Junpeng Zhao, Xin Peng

Abstract

Branching repositories facilitates efficient software development but can also inadvertently propagate vulnerabilities. When an original branch is patched, other unfixed branches remain vulnerable unless the patch is successfully ported. However, due to inherent discrepancies between branches, many patches cannot be directly applied and require manual intervention, which is time-consuming and leads to delays in patch porting, increasing vulnerability risks. Existing automated patch porting approaches are prone to errors, as they often overlook essential semantic and syntactic context of vulnerability and fail to detect or refine faulty patches. We propose M ystique , a novel LLM-based approach to address these limitations. M ystique first slices the semantic-related statements linked to the vulnerability while ensuring syntactic correctness, allowing it to extract the signatures for both the original patched function and the target vulnerable function. M ystique then utilizes a fine-tuned LLM to generate a fixed function, which is further iteratively checked and refined to ensure successful porting. Our evaluation shows that M ystique achieved a success rate of 0.954 at function level and of 0.924 at CVE level, outperforming state-of-the-art approaches by at least 13.2% at function level and 12.3% at CVE level. Our evaluation also demonstrates M ystique ’s superior generality across various projects, bugs, and programming languages. M ystique successfully ported patches for 34 real-world vulnerable branches.

BibTeX
@article{Wu-al:FSE25,
  author    = {Susheng Wu and
               Ruisi Wang and
               Yiheng Cao and
               Bihuan Chen and
               Zhuotong Zhou and
               Yiheng Huang and
               Junpeng Zhao and
               Xin Peng},
  title     = {Mystique: Automated Vulnerability Patch Porting with Semantic and {Syntactic-Enhanced} {LLM}},
  journal   = {{PACMSE}},
  volume    = {2},
  number    = {{FSE}},
  pages     = {130--152},
  year      = {2025},
}

Related papers