acceptodds
Under review as a conference paper at ICLR 2027

EviRepair: Evidence-Driven Agents for Reliable Vulnerability Repair

Abstract

Recent advances in large language models (LLMs) have enabled agent-based approaches for repository-level automated vulnerability repair (AVR), showing promising repair capabilities. However, an important issue has received limited attention: **how can we ensure that the evidence generated during the repair process is reliable enough to support accurate vulnerability understanding and patch generation**? In this paper, we propose EviRepair, an evidence-driven multi-agent framework for repository-level AVR. EviRepair introduces evidence review into the repair process by enabling agents to collaboratively collect vulnerability evidence, verify evidence consistency, and construct a reviewed vulnerability model for patch synthesis and validation. Extensive experiments on PatchEval and SecBench benchmarks with multiple agent frameworks and LLMs demonstrate that EviRepair consistently outperforms existing agent-based baselines, achieving average improvements of 16.37% and 40.33% in resolved rates on PatchEval and SecBench, respectively. Codes are available at https://anonymous.4open.science/r/EviRepair-BBB2/.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.