Skip to main navigation Skip to search Skip to main content

APILOT: Improving the Security and Usability of LLM Code Suggestions via Outdated API Mitigation

  • Weiheng Bai
  • , Keyang Xuan
  • , Pengxiang Huang
  • , Qiushi Wu
  • , Jianing Wen
  • , Jingjing Wu
  • , Kangjie Lu

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

With the rapid development of large language models (LLMs), their applications have expanded into diverse fields, such as code assistance. However, the substantial size of LLMs makes their training highly resource- and time-consuming, which leads to lengthy retraining and delayed updating. Consequently, LLMs trained based on old data may generate outdated results. This becomes extremely critical in the scenario of avoiding vulnerabilities. New vulnerabilities are discovered every day. Without updating their knowledge, LLMs may inadvertently generate code that includes these newly discovered vulnerabilities. Current strategies, such as prompt engineering and fine-tuning, do not effectively address this issue. Prompt engineering fails to equip LLMs with comprehensive, up-to-date knowledge, while fine-tuning remains prohibitively resource-intensive and time-consuming. To address this issue, we study the problem of LLM recommending outdated APIs and propose a new solution, named APILOT, which maintains a real-time, quickly updatable dataset of outdated APIs. Additionally, APILOT utilizes pre-constructed cache prediction and augmented generation methods that leverage this dataset to navigate LLMs in generating secure, version-aware code. We conducted a comprehensive empirical evaluation of APILOT across seventeen state-of-the-art large language models (LLMs), including both open-source and commercial systems. The results demonstrate that APILOT reduces outdated API recommendations by an average of 75%, with some models achieving up to 100% mitigation in specific large language models. Notably, these improvements are achieved with minimal performance overhead. Interestingly, while enhancing security, APILOT also improves the usability of LLM -generated code by an average of 37%, with gains reaching up to 85.6% in certain large language models. Importantly, these improvements are achieved without compromising code functionality, as measured by ICE-SCORE evaluations across diverse prompts and LLMs. This demonstrates APILOT's dual benefit─it not only reduces the risk of outdated API usage but also enhances the practical utility and deployability of generated code. Together, these results highlight APILOT 's potential to improve both security and developer experience in real-world AI-assisted programming environments.

Original languageEnglish (US)
Title of host publicationProceedings - 2025 Annual Computer Security Applications Conference, ACSAC 2025
PublisherAssociation for Computing Machinery
Pages1193-1208
Number of pages16
ISBN (Electronic)9798331594145
DOIs
StatePublished - 2025
Event41st Annual Computer Security Applications Conference, ACSAC 2025 - Honolulu, United States
Duration: Dec 8 2025Dec 12 2025

Publication series

NameProceedings - Annual Computer Security Applications Conference, ACSAC
ISSN (Print)1063-9527

Conference

Conference41st Annual Computer Security Applications Conference, ACSAC 2025
Country/TerritoryUnited States
CityHonolulu
Period12/8/2512/12/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Fingerprint

Dive into the research topics of 'APILOT: Improving the Security and Usability of LLM Code Suggestions via Outdated API Mitigation'. Together they form a unique fingerprint.

Cite this