PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 18, 2026ACM Transactions on Software Engineering and Methodology6 citations

A Systematic Literature Review on Detecting Software Vulnerabilities with Large Language Models

View Full Paper
SKSabrina KaniewskiFSFabian SchmidtMEMarkus Enzweiler

Key Points

  • This review aims to clarify the current landscape of software vulnerability detection using large language models (LLMs) and identify gaps in the research.
  • Conducted a systematic literature review (SLR) of 263 studies published from January 2020 to November 2025.
  • Categorized studies based on task formulation, input representation, system architecture, and techniques used.
  • Analyzed datasets for characteristics, vulnerability coverage, and diversity.
  • Developed a fine-grained taxonomy of approaches for software vulnerability detection using LLMs.
  • Identified key limitations in the current research landscape, such as fragmentation and diversity of datasets.
  • Provided a comprehensive overview to improve transparency and guide future research in LLM-based software vulnerability detection.

Abstract

The increasing adoption of Large Language Models (LLMs) in software engineering has sparked interest in their use for software vulnerability detection. However, the rapid development of this field has resulted in a fragmented research landscape, with diverse studies that are difficult to compare due to differences in, e.g., system designs and dataset usage. This fragmentation makes it difficult to obtain a clear overview of the state-of-the-art or compare and categorize studies meaningfully. In this work, we present a comprehensive systematic literature review (SLR) of LLM-based software vulnerability detection. We analyze 263 studies published between January 2020 and November 2025, categorizing them by task formulation, input representation, system architecture, and techniques. Further, we analyze the datasets used, including their characteristics, vulnerability coverage, and diversity. We present a fine-grained taxonomy of vulnerability detection approaches, identify key limitations, and outline actionable future research opportunities. By providing a structured overview of the field, this review improves transparency and serves as a practical guide for researchers and practitioners aiming to conduct more comparable and reproducible research. We publicly release all artifacts and maintain a living repository of LLM-based software vulnerability detection studies at https://github.com/hs-esslingen-it-security/Awesome-LLM4SVD .

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Kaniewski et al. (2026) studied this question.

synapsesocial.com/papers/6a0aad2a5ba8ef6d83b70a7ahttps://doi.org/10.1145/3815425
Ask AI
Helpful
Bookmark
Share
View Full Paper