AI struggles to patch vulns without adult supervision
Left alone, autonomous fixes often fail to fully remediate flaws
Researchers at 1Password's Off-by-1 Labs found that AI models, such as ChatGPT 5.5 and Claude Opus 4.8, struggle to generate accurate security patches without human oversight. Across six recent CVEs, they produced 6,080 patches using two frontier models, with an average success rate of just 26.0 percent. Of these, 20.1 percent fixed the issue but altered application behavior, while 2.3 percent introduced new security problems.
A staggering 49.3 percent failed to fix the vulnerability and 2.2 percent introduced new exploits. The researchers propose the acronym FLAWED (Fix-Like Artifacts With Embedded Defects) to describe these automated LLM patches. Their study suggests a net-negative value for fully LLM-generated, non-human-reviewed patches, emphasizing the importance of human review.
The success rate of LLM-generated patches improves to 65.0 percent when they receive correct initial guidance but drops to 50.4 percent with no guidance. If given incorrect guidance, the fix-success rate plummets to around 15.2 percent. Human developers, on the other hand, tend to be better at identifying misleading information while reasoning through vulnerable code.
The researchers released a patch evaluation harness called FLAWED, which organizations can use to assess the effectiveness of their security fixes. While AI-generated patches are inexpensive, the cost-benefit analysis should consider the need for expert supervision to make LLM-assisted patching useful.
Written by urgent.news from The Register's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- AI struggles to patch vulns without adult supervision theregister.com