Hunk-Constrained DPO: Segment-Level Optimization for Secure and Correct LLM Code Generation
Large Language Models (LLMs) have been widely applied in code generation tasks like code completion and automated development, demonstrating significant potential for improving coding efficiency. However, research has shown that LLM-generated code frequently contains security vulnerabilities, raising concerns about its reliability in production environments. To address these security issues, various mitigation approaches have been proposed, but these methods typically impact the LLM’s ability to generate functionally correct code, which may limit their practical application in real-world development environments. In this work, we address this problem through a key observation: security patches and functional bug fixes in real-world software exhibit structural similarities as small, localized modifications. This shared characteristic suggests that a unified learning model could address both objectives jointly. Building on this insight, we introduce HPO (Hunk-Constrained Direct Preference Optimization), a training framework that unifies security hardening and functional correction. Our framework features two key technical components: a novel segment-weighted preference optimization objective to focus learning on repair logic, and an automated data synthesis pipeline to provide high-quality training data. Experiments across multiple models and programming languages demonstrate that HPO achieves substantial security improvements—up to 28 percentage points—while preserving or enhancing functional correctness.
Authors
- Xin Yin (ORCID: https://orcid.org/0009-0005-3396-0571)
- Chao Ni (ORCID: https://orcid.org/0000-0002-2906-0598)
- Xinrui Li (ORCID: https://orcid.org/0009-0002-4730-5277)
- Qianshuo Huang (ORCID: https://orcid.org/0009-0006-8549-0062)
Institutions
- Zhejiang University (CN)
Publication Details
- Journal
- ACM Transactions on Software Engineering and Methodology
- Published
- 2026-09-15
- DOI
- https://doi.org/10.1145/3816250
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00