Improving Source Code Security: A Novel Approach Using Spectrum of Prompts and Automated State Machine

Cláudio Augusto Silveira Lélis, Cesar Augusto Cavalheiro Marcondes, Kevin Fealey · 2025

As software security becomes increasingly vital, automating source code vulnerability remediation is essential for enhancing system reliability. This research presents an integrated framework that combines large language models (LLMs) with a patch-compile-test state machine (PCT-SM) to generate accurate, functional code repairs with minimal human intervention. The solution is organized into three stages: the Editing Plan to identify necessary code edits; the Patch Plan to generate unified patches; and the Verification Plan to rigorously validate repairs through PCT-SM. Moreover, the process is refined by the Spectrum of Prompts (SoP) technique, which iteratively optimizes prompt variations to improve remediation effectiveness. Experimental evaluations indicate that our approach yields higher remediation success rates and more robust testing performance compared to conventional methods, with the SoP component exhibiting prominent repair outcomes.

Read the paper · More papers on PaperTik