COMPASS: Predicting the Relationship of Multiple Patches for Vulnerabilities with LLMs

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge that complex inter-patch relationships in multi-patch vulnerabilities hinder the correct adoption of fixes. We propose an automated relationship inference approach leveraging large language models. Specifically, this work introduces a novel taxonomy comprising six categories of patch relationships and designs a four-stage pipeline coupled with a hierarchical prompting mechanism to enable automatic vulnerability relationship prediction, consistency verification, and visual graph generation. Evaluated on a benchmark of 300 CVEs, our method achieves an accuracy of 85.04%, significantly outperforming existing state-of-the-art approaches. Furthermore, we release an online query platform to facilitate reuse within the open-source community and assist developers in informed decision-making.
📝 Abstract
Modern software heavily relies on code reuse, so upstream vulnerability fixes do not automatically propagate to downstream codebases. Downstream maintainers must manually adopt patches to eliminate known risks. In practice, a single vulnerability often corresponds to multiple patches, which greatly complicates downstream patch adoption because different patch relationships imply different adoption strategies. To address this challenge, we first manually inspect large-scale multi-patch vulnerabilities (about 1K) in the real world and interview experienced developers, summarizing six typical types of patch relationships, i.e., Merge, Mirror, Better Solution, Fixing-of-Fixing, Collaboration, and Separation. Based on these observations, we propose COMPASS, an automated approach that predicts the relationships of multiple vulnerability patches with large language models. Given a CVE as input, COMPASS follows a four-phase pipeline that (i) identifies the patch group and pre-scans explicit relationships, (ii) performs individual patch analysis, (iii) infers relationship instances via a hierarchy-guided prompt, and (iv) validates completeness and consistency of the inferred results. As output, COMPASS reports the predicted relationships within the patch group and visualizes them as a relationship graph. We evaluate COMPASS on a benchmark of 300 multi-patch CVEs and compare it against mainstream learning-based and LLM baselines. Results show that our method achieves strong and consistent prediction effectiveness and outperforms SOTA by 85.04% on average. We publicly release an online querying website to support community reuse of patch relationships knowledge: https://patch-relation.com.
Problem

Research questions and friction points this paper is trying to address.

vulnerability patches
patch relationship
multi-patch vulnerabilities
code reuse
patch adoption
Innovation

Methods, ideas, or system contributions that make the work stand out.

Large Language Models
Vulnerability Patches
Patch Relationship Prediction
Hierarchy-Guided Prompting
Multi-Patch Vulnerabilities
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Y
Yi Song
School of Cyber Science and Engineering, Wuhan University, Wuhan, China
D
Dongchen Xie
School of Cyber Science and Engineering, Wuhan University, Wuhan, China
Xiaoyuan Xie
Xiaoyuan Xie
Wuhan University
software testingprogram slicing and analysisdebugging and fault-localizationsearch-based software engineeringevolutionar
He Zhang
He Zhang
School of Computer Science, Wuhan University, Wuhan, China
L
Lin Xu
School of Cyber Science and Engineering, Wuhan University, Wuhan, China
C
Chunying Zhou
School of Computer Science, Wuhan University, Wuhan, China
Zhi Jin
Zhi Jin
Sun Yat-Sen University, Associate Professor