Skip to content
Search
paperAugust 2026Unreviewed

Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair

Benjamin Agyekum, Fabio Santos

Abstract

Background: Iterative feedback loops are the dominant paradigm for improving LLM-generated Infrastructure-as-Code (IaC): validators such as Checkov and terraform validate feed error signals back for successive repair attempts. Prior work reports cumulative-best metrics, which are non-decreasing by construction, so the raw per-iteration security trajectory has never been examined for IaC. Aims: We study security regression (a previously-passing CIS Benchmark check that fails after a repair iterat

Categories

Cite

@misc{agyekum2026does,
  title = {{Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair}},
  author = {Benjamin Agyekum and Fabio Santos},
  year = {2026},
  month = aug,
  eprint = {2608.13404},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.13404}
}