🤖 AI Summary
This study addresses the limitations of experience-dependent prompt design and the lack of systematic insights into failure mechanisms in large language model (LLM) vulnerability analysis. To overcome these challenges, this work proposes a failure-driven prompt optimization paradigm that systematically analyzes recurring failure patterns—such as false positives and reasoning errors—in the DVJA dataset to reconstruct targeted prompting strategies. Furthermore, it introduces a novel evidence-based evaluation framework grounded in specific failure cases, superseding conventional comparisons based on aggregated metrics. The proposed approach is validated on the Juliet test suite, demonstrating cross-model generalizability by significantly enhancing the reliability of LLM-based vulnerability detection while distilling reusable prompt engineering design principles.
📝 Abstract
Large Language Models have emerged as promising tools for software vulnerability analysis, but their effectiveness depends heavily on prompt design. Existing research primarily compares prompting strategies using aggregate performance metrics, providing limited insight into why models fail or how prompts can be improved systematically. We propose Failure-Driven Prompt Refinement (FDPR), a methodology that analyzes recurring model failures to guide evidence-based prompt refinement. Using the Damn Vulnerable Java Application (DVJA), we identify recurring failure modes, including false positives, false negatives, unsupported reasoning, and CWE misclassification, and translate them into targeted prompt refinements. We then evaluate the resulting prompt on the Juliet Test Suite and perform cross-model validation to assess generalizability. The results show that failure-driven refinement improves the reliability of LLM-based vulnerability analysis while yielding reusable prompt design principles. More broadly, this work demonstrates that recurring model failures provide a principled foundation for prompt engineering, enabling the systematic development of more reliable LLM-based vulnerability analysis systems.