Automating LLM Patch Porting for Developers

VIDAR is an Automated LLM Tool to secure the Android Ecosystem through intelligent patch porting automation.

Type

Capstone Project

Deliverables

CLI Interface, GUI Design, and Research Paper

Year

January - June 2025

Role

UX Designer and LLM Engineer

THE CHALLENGE


Patch-porting is critical for maintaining security in ecosystems like Android and the Linux kernel, where diverged downstream branches (e.g., Samsung, Xiaomi) complicate updates. Manual patch-porting is slow and error-prone due to codebase divergence, time-intensive adaptation, frequent conflicts, and limited tool support beyond simple git cherry-pick.


Google’s Vanir helps by detecting missing patches using static analysis and OSV data, but it stops short of applying them. Without better automation, systems remain exposed to vulnerabilities for extended periods. Extending Vanir to adapt and apply patches can deliver faster, more accurate, and scalable security updates.

HOW MIGHT WE STATEMENT

How can Google developers and Android OEMs automate security patch backporting to minimize manual effort, ensure full coverage, and keep all branches up-to-date?

HOW MIGHT WE STATEMENT


How can Google developers and Android OEMs automate security patch backporting to minimize manual effort, ensure full coverage, and keep all branches up-to-date?

This project is in-progress!

Sté comes from my name, Steven, but it’s more than that—it shapes everything I hope to do. I’m deeply connected to the word “stay.” When I sing, I want my audience to stay and listen. When I design, I create moments that invite people to stay and engage. When I create art, I hope the audience stays immersed. And when I craft fragrances, I want them to stay with those who wear them, evoking lasting memories.


Cringe, but Welcome! I hope you sté with me and enjoy my works!

2025 ® Steven Heng + iced americanos.

Sté comes from my name, Steven, but it’s more than that—it shapes everything I hope to do. I’m deeply connected to the word “stay.” When I sing, I want my audience to stay and listen. When I design, I create moments that invite people to stay and engage. When I create art, I hope the audience stays immersed. And when I craft fragrances, I want them to stay with those who wear them, evoking lasting memories.


Cringe, but Welcome! I hope you sté with me and enjoy my works!

2025 ® Steven Heng + iced americanos.

Sté comes from my name, Steven, but it’s more than that—it shapes everything I hope to do. I’m deeply connected to the word “stay.” When I sing, I want my audience to stay and listen. When I design, I create moments that invite people to stay and engage. When I create art, I hope the audience stays immersed. And when I craft fragrances, I want them to stay with those who wear them, evoking lasting memories.


Cringe, but Welcome! I hope you sté with me and enjoy my works!

2025 ® Steven Heng + iced americanos.

BILLY DUVALLE

®2024

BILLY DUVALLE

®2024

BILLY DUVALLE

®2024