Guided Reasoning with Actionable Security Principles for Secure Code Generation
Abstract
Large Language Models generate code that is frequently insecure, and existing defenses are vulnerability-centric: they teach models what not to do, by fine-tuning on vulnerable and fixed code pairs, by retrieving records of past vulnerabilities, or by revising drafts under static analyzer feedback. Such defenses depend on curated vulnerability data, generalize poorly to weaknesses absent from it, and are often impractical for proprietary models. We take a principle-centric direction instead: rather than describing past vulnerabilities, we condition generation on prescriptive Secure Coding Principles that state how secure code should be written. We present GRASP, which organizes 214 such principles into a directed acyclic graph capturing specialization and prerequisite dependencies, and traverses it at inference time, selecting the principles relevant to a task and applying them in dependency order while pruning branches that do not arise. GRASP requires no training, no weight access and no analyzer in the generation loop, so it applies to proprietary and open-weight models alike. Across five models we raise the Security Rate from 0.46–0.55 at baseline to 0.70–0.84, outperform zero-shot, planning-based, retrieval-augmented and analyzer-guided prompting on secure-pass@k on our dataset, and improve robustness on unseen vulnerabilities, measured on real CVEs disclosed after the evaluated models' training cutoffs.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.