<div class="csl-bib-body">
<div class="csl-entry">Przymus, P., Happe, A., & Cito, J. (2026). Adversarial Bug Reports as a Security Risk in Language Model-Based Automated Program Repair. In <i>MSR ’26: Proceedings of the 23rd International Conference on Mining Software Repositories</i> (pp. 212–223). Association for Computing Machinery. https://doi.org/10.1145/3793302.3793352</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/230702
-
dc.description.abstract
Large Language Model (LLM) - based Automated Program Repair (APR) systems are increasingly integrated into modern software development workflows, offering automated patches in response to natural language bug reports. However, this reliance on untrusted user input introduces a novel and underexplored attack surface. In this paper, we investigate the security risks posed by adversarial bug reports - realistic-looking issue submissions crafted to mislead APR systems into producing insecure or harmful code changes. We develop a comprehensive threat model and conduct an empirical study to evaluate the vulnerability of APR systems to such attacks. Our demonstration comprises 51 adversarial bug reports generated across a spectrum of strategies, ranging from manual curation to fully automated pipelines. We test these against a leading LLM-based APR system and assess both pre-repair defenses (e.g., LlamaGuard variants, PromptGuard variants, Granite-Guardian, and custom LLM filters) and post-repair detectors (GitHub Copilot, CodeQL). Our findings show that current defenses are insufficient: 90% of crafted bug reports triggered attacker-aligned patches. The best pre-repair filter blocked only 47%, while post-repair analysis - often requiring human oversight - was effective in just 58% of cases. To support scalable security testing, we introduce a prototype framework for automating the generation of adversarial bug reports. Our analysis exposes a structural asymmetry: generating adversarial inputs is inexpensive, while detecting or mitigating them remains costly and error-prone. We conclude with recommendations for improving the robustness of APR systems against adversarial misuse and highlight directions for future work on secure APR.
en
dc.language.iso
en
-
dc.subject
APR
en
dc.subject
attack
en
dc.subject
automated program repair
en
dc.subject
Large Language Models
en
dc.subject
LLM
en
dc.subject
security
en
dc.subject
SWE-Agent
en
dc.subject
SWE-Bench
en
dc.title
Adversarial Bug Reports as a Security Risk in Language Model-Based Automated Program Repair
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.contributor.affiliation
Nicolaus Copernicus University, Poland
-
dc.contributor.affiliation
TU Wien, Austria
-
dc.relation.isbn
979-8-4007-2474-9
-
dc.description.startpage
212
-
dc.description.endpage
223
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
MSR '26: Proceedings of the 23rd International Conference on Mining Software Repositories
-
tuw.peerreviewed
true
-
tuw.relation.publisher
Association for Computing Machinery
-
tuw.relation.publisherplace
New York, USA
-
tuw.researchTopic.id
I4
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.value
100
-
tuw.publication.orgunit
E194-01 - Forschungsbereich Software Engineering
-
tuw.publisher.doi
10.1145/3793302.3793352
-
dc.description.numberOfPages
12
-
tuw.author.orcid
0000-0001-9548-2388
-
tuw.author.orcid
0009-0000-2484-0109
-
tuw.event.name
MSR '26: 23rd International Conference on Mining Software Repositories
en
tuw.event.startdate
13-04-2026
-
tuw.event.enddate
14-04-2026
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
Rio de Janeiro
-
tuw.event.country
BR
-
tuw.event.presenter
Przymus, Piotr
-
wb.sciencebranch
Informatik
-
wb.sciencebranch
Wirtschaftswissenschaften
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.oefos
5020
-
wb.sciencebranch.value
90
-
wb.sciencebranch.value
10
-
item.openairetype
conference paper
-
item.cerifentitytype
Publications
-
item.fulltext
no Fulltext
-
item.languageiso639-1
en
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.grantfulltext
none
-
crisitem.author.dept
Nicolaus Copernicus University, Poland
-
crisitem.author.dept
E185 - Institut für Computersprachen
-
crisitem.author.dept
E194-01 - Forschungsbereich Software Engineering
-
crisitem.author.orcid
0000-0001-9548-2388
-
crisitem.author.parentorg
E180 - Fakultät für Informatik
-
crisitem.author.parentorg
E194 - Institut für Information Systems Engineering