acceptodds
Under review as a conference paper at ICLR 2027

PurpAgent: Integrating Security Reasoning into Coding Agents

Abstract

Large language model (LLM) agents increasingly automate software development, yet functionally correct implementations can still introduce security vulnerabilities. Integrating security review into these agents requires feedback that supports successful repair within a limited execution budget. In this paper, we introduce PurpAgent Harness, the first scaffold that seamlessly integrates secure coding and security review. Its key idea is to translate repository evidence into explicit security obligations that guide verification and repair in the original coding trajectory, without requiring a separate standalone security-analysis phase. We further develop PurpAgent 27B by applying mutual supervised fine-tuning (mutual SFT) on synthesized coding and security-review trajectories, equipping a single model to perform both agent roles natively. On SusVibes, PurpAgent Harness improves the joint functional and security pass rate (SecPass) by 2.15–14.49 percentage points over mini-SWE-agent across seven LLM backends, while maintaining or improving the functional pass rate (FuncPass) in general. Within the same harness, PurpAgent 27B achieves 36.60% FuncPass and 17.70% SecPass, improving over its base model by 11.33 and 6.95 percentage points, respectively, and leading open-source models of comparable size on both metrics. Third-party red-teaming further shows that PurpAgent Harness increases the proportion of Secure Apps from 35.0% to 55.0% with PurpAgent 27B, demonstrating improved robustness against adaptive exploitation attempts.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.