Skip to main content

IoT Software Vulnerability Detection Techniques through Large Language Model

  • Conference paper
  • First Online:
Formal Methods and Software Engineering (ICFEM 2023)

Part of the book series: Lecture Notes in Computer Science ((LNCS,volume 14308))

Included in the following conference series:

Abstract

The explosion of IoT usage provides efficiency and convenience in various fields including daily life, business and information technology. However, there are potential risks in large-scale IoT systems and vulnerability detection plays a significant role in the application of IoT. Besides, traditional approaches like routine security audits are expensive. Thus, substitution methods with lower costs are needed to achieve IoT system vulnerability detection. LLMs, as new tools, show exceptional natural language processing capabilities, meanwhile, static code analysis offers low-cost software analysis avenues. The paper aims at the combination of LLMs and static code analysis, implemented by prompt engineering, which not only expands the application of LLMs but also provides a probability of accomplishing cost-effective IoT vulnerability software detection.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 49.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 64.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

References

  1. Sözer, H.: Integrated static code analysis and runtime verification. Softw.: Pract. Exp. 45(10), 1359–1373 (2014). https://doi.org/10.1002/spe.2287

  2. Spataro, J.: Introducing Microsoft 365 Copilot – your copilot for work - The Official Microsoft Blog. The Official Microsoft Blog (2023). https://blogs.microsoft.com/blog/2023/03/16/introducing-microsoft-365-copilot-your-copilot-for-work/

  3. Mehdi, Y.: Reinventing search with a new AI-powered Microsoft Bing and Edge, your copilot for the web - The Official Microsoft Blog. The Official Microsoft Blog (2023). https://blogs.microsoft.com/blog/2023/02/07/reinventing-search-with-a-new-ai-powered-microsoft-bing-and-edge-your-copilot-for-the-web/

  4. Vaswani, A., et al: Attention is All you Need. arXiv (Cornell University), 30, 5998–6008 (2017). https://arxiv.org/pdf/1706.03762v5

  5. Merritt, R.: What Is a Transformer Model? | NVIDIA Blogs. NVIDIA Blog (2022). https://blogs.nvidia.com/blog/2022/03/25/what-is-a-transformer-model/

  6. Bowman, Samuel R.: Eight Things to Know about Large Language Models (2023). arXiv:2304.00612

  7. Nanda, N., Chan, L., Lieberum, T., Smith, J. L., Steinhardt, J.: Progress measures for grokking via mechanistic interpretability. arXiv (Cornell University) (2023). https://doi.org/10.48550/arxiv.2301.05217

  8. Yao, S., et al.: ReAct: Synergizing Reasoning and Acting in Language Models (2022). https://doi.org/10.48550/arxiv.2210.03629

  9. Liu, Y., et al.: Prompt Injection attack against LLM-integrated Applications (2023). https://doi.org/10.48550/arxiv.2306.05499

  10. Cheung, K.S.: Real estate insights unleashing the potential of ChatGPT in property valuation reports: the “Red Book” compliance Chain-of-thought (CoT) prompt engineering. J. Property Invest. Finance (2023). https://doi.org/10.1108/JPIF-06-2023-0053

    Article  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Yilin Yang .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2023 The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd.

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Yang, Y. (2023). IoT Software Vulnerability Detection Techniques through Large Language Model. In: Li, Y., Tahar, S. (eds) Formal Methods and Software Engineering. ICFEM 2023. Lecture Notes in Computer Science, vol 14308. Springer, Singapore. https://doi.org/10.1007/978-981-99-7584-6_21

Download citation

  • DOI: https://doi.org/10.1007/978-981-99-7584-6_21

  • Published:

  • Publisher Name: Springer, Singapore

  • Print ISBN: 978-981-99-7583-9

  • Online ISBN: 978-981-99-7584-6

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy