Papers by Mihai Christodorescu
When "Correct" Is Not Safe: Can We Trust Functionally Correct Patches Generated by Code Agents? (2026.acl-long)
Copied to clipboard
Yibo Peng, James Song, Lei Li, Xinyu Yang, Mihai Christodorescu, Ravi Mangal, Corina S. Pasareanu, Haizhong Zheng, Beidi Chen
| Challenge: | Code agents are increasingly trusted to autonomously fix bugs on platforms such as GitHub, yet their security evaluation focuses on functional correctness. |
| Approach: | They propose to attack functionally correct yet vulnerable (FCV) patches by combining multi-turn reasoning with tool invocation and environment interaction. |
| Outcome: | The proposed FCV-Attack achieves an attack success rate of 40.7% on GPT-5 Mini + OpenHands. |
SACTOR: LLM-Driven Correct and Idiomatic C to Rust Translation with Static Analysis and FFI-Based Verification (2026.acl-long)
Copied to clipboard
Tianyang Zhou, Ziyi Zhang, Haowen Lin, Somesh Jha, Mihai Christodorescu, Kirill Levchenko, Varun Chandrasekaran
| Challenge: | Large language models (LLMs) have shown promise in producing idiomatic translations, but offer no correctness guarantees. |
| Approach: | They propose a C-to-Rust translation tool that uses an initial "unidiomatic" translation followed by an "idiomatic refinement" they evaluate SACTOR on 200 programs from two datasets and two more complex scenarios . |
| Outcome: | The proposed tool delivers high end-to-end correctness and produces safe, idiomatic Rust with up to 7 fewer Clippy warnings. |