Hunk-Constrained DPO: Segment-Level Optimization for Secure and Correct LLM Code Generation

Large Language Models (LLMs) have been widely applied in code generation tasks like code completion and automated development, demonstrating significant potential for improving coding efficiency. However, research has shown that LLM-generated code frequently contains security vulnerabilities, raising concerns about its reliability in production environments. To address these security issues, various mitigation approaches have been proposed, but these methods typically impact the LLM’s ability to generate functionally correct code, which may limit their practical application in real-world development environments. In this work, we address this problem through a key observation: security patches and functional bug fixes in real-world software exhibit structural similarities as small, localized modifications. This shared characteristic suggests that a unified learning model could address both objectives jointly. Building on this insight, we introduce HPO (Hunk-Constrained Direct Preference Optimization), a training framework that unifies security hardening and functional correction. Our framework features two key technical components: a novel segment-weighted preference optimization objective to focus learning on repair logic, and an automated data synthesis pipeline to provide high-quality training data. Experiments across multiple models and programming languages demonstrate that HPO achieves substantial security improvements—up to 28 percentage points—while preserving or enhancing functional correctness.

Authors

Institutions

Publication Details

Journal
ACM Transactions on Software Engineering and Methodology
Published
2026-09-15
DOI
https://doi.org/10.1145/3816250
Primary Topic
Advanced Malware Detection Techniques
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Hunk-Constrained DPO: Segment-Level Optimization for Secure and Correct LLM Code Generation

Xin Yin, Chao Ni, Xinrui Li, Qianshuo Huang
ACM Transactions on Software Engineering and Methodology
Advanced Malware Detection Techniques
article

Hunk-Constrained DPO: Segment-Level Optimization for Secure and Correct LLM Code Generation

Xin Yin, Chao Ni, Xinrui Li, Qianshuo Huang
article en

Abstract

Large Language Models (LLMs) have been widely applied in code generation tasks like code completion and automated development, demonstrating significant potential for improving coding efficiency. However, research has shown that LLM-generated code frequently contains security vulnerabilities, raising concerns about its reliability in production environments. To address these security issues, various mitigation approaches have been proposed, but these methods typically impact the LLM’s ability to generate functionally correct code, which may limit their practical application in real-world development environments. In this work, we address this problem through a key observation: security patches and functional bug fixes in real-world software exhibit structural similarities as small, localized modifications. This shared characteristic suggests that a unified learning model could address both objectives jointly. Building on this insight, we introduce HPO (Hunk-Constrained Direct Preference Optimization), a training framework that unifies security hardening and functional correction. Our framework features two key technical components: a novel segment-weighted preference optimization objective to focus learning on repair logic, and an automated data synthesis pipeline to provide high-quality training data. Experiments across multiple models and programming languages demonstrate that HPO achieves substantial security improvements—up to 28 percentage points—while preserving or enhancing functional correctness.

ACM Transactions on Software Engineering and Methodology
Zhejiang University (CN)
Industry, innovation and infrastructure
Openalex Percentile: Top 10%
Advanced Malware Detection Techniques
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Hunk-Constrained DPO: Segment-Level Optimization for Secure and Correct LLM Code Generation — Xin Yin, Chao Ni, et al. · ACM Transactions on Software Engineering and Methodology (2026) | TGRS Research Map | TGRS