ICASSP 2025accepted0 citations

RefleXGen: The unexamined code is not worth using

Bin Wang, Hui Li, Aofan Liu, BoTao Yang, Ao Yang, YiLu Zhong, Weixiang Huang, Runhuai Huang

Abstract

Security in code generation remains a pivotal challenge when applying large language models (LLMs). This paper introduces RefleXGen, an innovative method that significantly enhances code security by integrating Retrieval-Augmented Generation (RAG) techniques with guided self-reflection mechanisms inherent in LLMs. Unlike traditional approaches that rely on fine-tuning LLMs or developing specialized secure code datasets—processes that can be resource-intensive—RefleXGen iteratively optimizes the code generation process through self-assessment and reflection without the need for extensive resources. Within this framework, the model continuously accumulates and refines its knowledge base, thereby progressively improving the security of the generated code. Experimental results demonstrate that RefleXGen substantially enhances code security across multiple models, achieving a 13.6% improvement with GPT-3.5 Turbo, a 6.7% improvement with GPT-4o, a 4.5% improvement with CodeQwen, and a 5.8% improvement with Gemini.

BibTeX
@inproceedings{icassp2025_reflexgentheunex,
  title = {RefleXGen: The unexamined code is not worth using},
  author = {Bin Wang and Hui Li and Aofan Liu and BoTao Yang and Ao Yang and YiLu Zhong and Weixiang Huang and Runhuai Huang and Weimin Zeng and Yanping Zhang},
  booktitle = {ICASSP 2025},
  year = {2025}
}
RefleXGen: The unexamined code is not worth using · ICASSP 2025