{
  "$schema": "https://themachinepress.com/schemas/story-v1.schema.json",
  "schema_version": "1.0.0",
  "document_type": "machine_press_story",
  "story": {
    "story_id": "mp-2026-09-23-004",
    "source_story_id": "tmp-story-code-repair-metrics-failure",
    "edition_id": "mp-2026-09-23-morning-0076",
    "edition_url": "https://themachinepress.com/edition/2026-09-23",
    "position": 4,
    "story_type": "dispatch",
    "section": "safety-security",
    "editorial_classification": "editorial",
    "headline": "Compiling Was a Bad Score for Vulnerability Repair",
    "slug": "compiling-was-a-bad-score-for-vulnerability-repair",
    "dek": "Harness artifacts and compiler flags moved the metric without proving a security fix.",
    "summary": "Harness artifacts and compiler flags moved the metric without proving a security fix.",
    "body_text": "A study of 203 vulnerable C and C++ functions found compile rate to be an unreliable proxy for LLM vulnerability repair. About 64% of compile failures were not attributed to the model, and a compiler-standard flag changed compile rates by 1.8 to 2.7 times on identical patches. A compiler-feedback loop also rewarded deletions and placeholders while similarity to human fixes fell. The authors propose a change-aware screen as a cheap filter, not a substitute for execution-grounded security evaluation.",
    "why_it_matters": "Harness artifacts and compiler flags moved the metric without proving a security fix.",
    "limitations": [
      "About 64% of compile failures were not attributed to the model, and a compiler-standard flag changed compile rates by 1.8 to 2.7 times on identical patches.",
      "The authors propose a change-aware screen as a cheap filter, not a substitute for execution-grounded security evaluation."
    ],
    "importance": 9,
    "canonical_url": "https://themachinepress.com/story/mp-2026-09-23-004/compiling-was-a-bad-score-for-vulnerability-repair",
    "json_url": "https://themachinepress.com/story/mp-2026-09-23-004.json",
    "first_published_at": "2026-09-23T09:00:00.000-04:00",
    "modified_at": "2026-09-23T09:00:00.000-04:00",
    "content_status": "new",
    "is_carryover": false,
    "carryover_reason": null,
    "key_claims": [
      {
        "claim_id": "claim-mp-2026-09-23-004-001",
        "text": "Harness artifacts and compiler flags moved the metric without proving a security fix.",
        "source_ids": [
          "source-2026-09-23-004"
        ],
        "qualification": "About 64% of compile failures were not attributed to the model, and a compiler-standard flag changed compile rates by 1.8 to 2.7 times on identical patches."
      }
    ],
    "source_ids": [
      "source-2026-09-23-004"
    ],
    "tags": [
      "vulnerability repair",
      "evaluation",
      "code models"
    ],
    "image_url": null,
    "corrections": []
  },
  "sources": [
    {
      "source_id": "source-2026-09-23-004",
      "title": "arXiv preprint 2609.26749",
      "publisher": "arXiv",
      "url": "https://arxiv.org/abs/2609.26749",
      "canonical_url": "https://arxiv.org/abs/2609.26749",
      "source_type": "primary_research",
      "is_primary_source": true,
      "published_at": "2026-09-22T13:32:05.000-04:00",
      "accessed_at": "2026-09-23T08:22:43.661-04:00",
      "supports_claim_ids": [
        "claim-mp-2026-09-23-004-001"
      ]
    }
  ],
  "corrections": [],
  "publisher": {
    "name": "The Machine Press",
    "url": "https://themachinepress.com",
    "description": "A daily newspaper for the age of artificial intelligence."
  },
  "cite_this_report": {
    "title": "Compiling Was a Bad Score for Vulnerability Repair",
    "publisher": "The Machine Press",
    "published_at": "2026-09-23T09:00:00.000-04:00",
    "canonical_url": "https://themachinepress.com/story/mp-2026-09-23-004/compiling-was-a-bad-score-for-vulnerability-repair"
  }
}
