SinoTechIntel Academic Portal
Open AccessDOI: 10.1631/FITEE_2500038Original Research

Large language model-enhanced probabilistic modeling for effective static analysis alarms

Xinlong PAN¹,Jianhua LI¹,Zhihong ZHOU¹,Gaolei LI¹,Xiuzhen CHEN¹,Jin MA¹,Jun WU¹,Quanhai ZHANG¹

Institute of Cyber Security and Technology, School of Computer Science, Shanghai Jiao Tong University, Shanghai 200240, China

Read Executive PreviewQuick FAQ
Large language model-enhanced probabilistic modeling for effective static analysis alarms
Graphical Abstract / Figure
Published In
Frontiers of Information Technology & Electronic Engineering
Published:January 22, 2025Edition:Vol. 32, Issue 1 • pp. 744-756Citation:Xinlong PAN et al. (2025), Frontiers of Information Technology & Electronic Engineering
Impact Factor2.7 (Q2 - Springer)
Sponsored Research Partner
Keywords & Index Terms:Static analysisBayesian inferenceLarge language modelsAlarm rankingVulnerability detectionProbabilistic modelingRule learningBinLLM

Key Takeaways & Executive Findings

  • • BinLLM integrates large language models with static analysis to learn abstract rules, improving alarm probability models and reducing false generalizations. • The framework leverages alarm paths and critical statements from static analysis to enhance the reasoning capabilities of Bayesian networks. • Experimental results on C programs show a 40.1% reduction in verification checks compared to Bingo and a 9.4% reduction compared to BayeSmith. • The approach demonstrates a synergistic paradigm where LLMs actively refine static analysis, leading to more effective alarm prioritization and reduced user intervention.
Sponsored Research Highlight

Abstract

Static analysis presents significant challenges in alarm handling, where probabilistic models and alarm prioritization are essential methods for addressing these issues. These models prioritize alarms based on user feedback, thereby alleviating the burden on users to manually inspect alarms. However, they often encounter limitations related to efficiency and issues such as false generalization. While learning-based approaches have demonstrated promise, they typically incur high training costs and are constrained by the predefined structures of existing models. Moreover, the integration of large language models (LLMs) in static analysis has yet to reach its full potential, often resulting in lower accuracy rates in vulnerability identification. To tackle these challenges, we introduce BinLLM, a novel framework that harnesses the generalization capabilities of LLMs to enhance alarm probability models through rule learning. Our approach integrates LLM-derived abstract rules into the probabilistic model, using alarm paths and critical statements from static analysis. This integration enhances the model's reasoning capabilities, improving its effectiveness in prioritizing genuine bugs while mitigating false generalizations. We evaluated BinLLM on a suite of C programs and observed 40.1% and 9.4% reduction in the number of checks required for alarm verification compared to two state-of-the-art baselines, Bingo and BayeSmith, respectively, underscoring the potential of combining LLMs with static analysis to improve alarm management.

1. Introduction

Static analysis is a powerful technique for detecting bugs in software systems, yet it faces significant challenges in managing alarms effectively (Beller et al., 2016; Christakis and Bird, 2016; Muske and Serebrenik, 2022). A key post-processing method is user-guided ranking (Shen et al., 2011; Mangal et al., 2015), which prioritizes alarms based on user feedback. Bayesian program analysis formalizes this into a probabilistic framework: alarms are ranked by inferred probabilities, and user feedback iteratively refines the model (Raghothaman et al., 2018; Heo et al., 2019; Chen TY et al., 2021; Kim et al., 2022; Zhang et al., 2024). Its effectiveness depends on the generalization ability of the Bayesian network, derived from inference graphs built using Datalog rules. More accurate rules yield stronger generalization, reducing user workload and improving alarm prioritization. However, this approach still relies on user expertise, and Datalog rules lack intelligent optimization (Muske and Serebrenik, 2022).

The integration of large language models (LLMs) into static analysis has gained attention (Chen M et al., 2021; Ma et al., 2023; Sun et al., 2024). However, challenges such as hallucinations and randomness persist (Ji et al., 2023; Touvron et al., 2023), limiting their effectiveness in vulnerability detection. The state-of-the-art methods based on LLMs have improved accuracy to 67.6% (Zhou et al., 2025), but these methods are constrained by data processing granularity, typically limited to the function or line level, which hampers their ability to detect vulnerabilities across entire libraries. Existing methods use mainly LLMs as judgment substitutes or static analysis supplements (Gao et al., 2023; Mohajer et al., 2023; Li HN et al., 2024; Li ZY et al., 2024), lacking deep integration. This suggests a paradigm shift where LLMs actively enhance static analysis for improved accuracy (Li HN et al., 2024).

To address these challenges, we propose BinLLM, a framework that leverages LLMs to refine alarm probability models through rule learning. By integrating LLM-derived rules with static analysis insights, including alarm paths and critical statements, our approach enhances reasoning capabilities and reduces user intervention, fostering a more synergistic relationship between LLMs and static analysis.

SinoTechIntel Interactive Document Reader
Page 1–5 of Preview
100%
Download Full PDF

Loading authentic research manuscript (Pages 1–5)...

Sponsored Research Partner
Cite This Research Paper
Xinlong PAN, Jianhua LI, Zhihong ZHOU, Gaolei LI, Xiuzhen CHEN, Jin MA, Jun WU, Quanhai ZHANG (2025). Large language model-enhanced probabilistic modeling for effective static analysis alarms. Frontiers of Information Technology & Electronic Engineering. https://doi.org/10.1631/FITEE_2500038
SinoTechIntel Academic & Legal Disclaimer

Research & Educational Purpose Only:The translations, structured abstracts, analytical annotations, and data reports provided by SinoTechIntel are intended exclusively for academic research, internal corporate R&D, and educational benchmarking. They do not constitute formal engineering, chemical safety, legal, or professional advice.

Copyright & Intellectual Property Notice: Original copyright of the underlying source articles and experimental data remains with the respective authors, institutions, and original publishing journals. SinoTechIntel claims intellectual property only over its proprietary translations, analytical syntheses, and AEO structured enhancements in accordance with international fair use and academic citation principles.

Frequently Asked Questions

What is BinLLM?

BinLLM is a novel framework that integrates large language models with static analysis to enhance alarm probability models through rule learning. It uses LLM-derived abstract rules, combined with alarm paths and critical statements from static analysis, to improve the prioritization of genuine bugs while mitigating false generalizations.

How does BinLLM reduce user workload in alarm verification?

BinLLM reduces the number of checks required for alarm verification by 40.1% compared to the Bingo baseline and 9.4% compared to the BayeSmith baseline, as demonstrated in experiments on C programs. This reduction alleviates the burden on users to manually inspect alarms.

What are the limitations of existing LLM-based static analysis methods?

Existing methods often suffer from hallucinations and randomness, and they are typically constrained by data processing granularity at the function or line level. This limits their effectiveness in detecting vulnerabilities across entire libraries. They also tend to use LLMs merely as judgment substitutes or supplements rather than deeply integrating them into the analysis.

What role do Datalog rules play in the BinLLM framework?

Datalog rules are used to construct the initial Bayesian network in the static analyzer. BinLLM refines these rules using LLM-derived abstract rules, which enhances the generalization ability of the alarm probability model and improves overall alarm prioritization.

In what programming language was BinLLM evaluated?

BinLLM was evaluated on a suite of C programs, demonstrating its effectiveness in improving alarm management through the combination of LLMs and static analysis.

Recommended Scientific Literature & Research Partners

Related Technical Papers & Translations

Research Paper
Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption

Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption

To address the challenges of high energy consumption and prominent costs in the traditional three-columns distillation process for cellulosic fuel ethanol, a distillation—molecular sieve coupling separation process is proposed. This process integrates a three-column (crude distillation column, first distillation column, second distillation column) system with a 3A molecular sieve adsorption deep dehydration unit. A thermal coupling network is constructed via differential pressure design (steam from medium/high-pressure columns as mutual heat sources, reboiler liquid waste heat for feed preheating), and molecular sieve adsorption conditions are optimized. The study first performs a thermodynamic consistency test on the ethanol—water system, determines optimal non-random two-liquid (NRTL) model binary interaction parameters via experimental data regression for Aspen Plus simulation. Aiming at minimum total annual cost (TAC), Aspen Plus is used to optimize process parameters (theoretical tray number, feed location, reflux ratio, side-draw position, etc.). Economic analysis shows this process reduces CO2 emission costs by 27.56%, TAC by 15.58% (to 5.123 × 106 USD·a-1), and increases ethanol purity to >99.6%, providing an effective solution for green, efficient separation.

Read Abstract & PDF
Research Paper
A cohesion loss model for determining residual strength of deep bedded sandstone

A cohesion loss model for determining residual strength of deep bedded sandstone

Rock residual strength, as an important input parameter, plays an indispensable role in proposing the reasonable and scientific scheme about stope design, underground tunnel excavation and stability evaluation of deep chambers. Therefore, previous residual strength models of rocks established were reviewed. And corresponding related problems were stated. Subsequently, starting from the effects of bedding and whole life-cycle evolution process, series of triaxial mechanical tests of deep bedded s

Read Abstract & PDF
Research Paper
Federated model with contrastive learning and adaptive control variates for human activity recognition

Federated model with contrastive learning and adaptive control variates for human activity recognition

Recent attention to privacy issues demands a communication-safe method for training human activity recognition (HAR) models on client activity data. Federated learning (FL) has become a compelling technique to facilitate model training between the server and clients while preserving data privacy. However, classical FL methods often assume independent and identically distributed (IID) data among clients. This assumption does not hold true in practical scenarios. Human activity in real-world scena

Read Abstract & PDF