LLM-Based Agents for Software and Systems Security: Approaches, Applications, and Assessment

📅 2026-08-28
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文通过系统文献回顾,探讨了基于大型语言模型的代理在软件和系统安全中的应用、方法及评估问题,指出了现有方法的局限性和未来研究方向。
📝 Abstract
Software and systems security workflows are typically procedural: analysts inspect heterogeneous artifacts, form hypotheses, invoke tools, interpret outputs, and revise plans. Large language model (LLM)-based agents, which can plan, use tools, retain state, and revise actions across multi-step workflows, are being rapidly adopted to automate this work. Given the consequences of delegating security decisions to autonomous systems, understanding how such agents are built, used, and assessed is crucial. Yet to this date, there remains a lack of systematic understanding of what has been done and how far we are in this field: the term "agent" is applied inconsistently, applications differ sharply in risk, and assessment protocols are often incomparable. To gain a comprehensive and coherent view of this area hence inform relevant future research, this paper provides a systematic literature review of the (1) technical approaches, including agent architecture, perception, memory, reasoning and planning, action space, orchestration, and self-improvement, (2) applications, with respect to the security tasks served, and (3) assessment, including the datasets, outcome and trajectory metrics, safety measures, and baselines considered, over the peer-reviewed literature spanning the emergence of this area (2023--2026). Our synthesis reveals a field that has built agents able to act but not yet agents whose authority is bounded or whose behavior is auditable. In addition to knowledge systematization, we also extend our insights into the limitations of and challenges faced by current approach, application, and assessment designs, which shed light on potentially promising future research directions.
Problem

Research questions and friction points this paper is trying to address.

Large language model (LLM)
Software and systems security
Agent
Assessment protocols
Automation
Innovation

Methods, ideas, or system contributions that make the work stand out.

LLM-based agents
software and systems security
systematic literature review
agent architecture
assessment protocols
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
J
Jingjing Nie
University at Buffalo, SUNY, USA
Jiawei Guo
Jiawei Guo
Bupt & M-A-P
LLM MLLM
K
Krishna Meda
University at Buffalo, SUNY, USA
Haipeng Cai
Haipeng Cai
University at Buffalo, SUNY
Software SecuritySoftware EngineeringProgram Analysis