August 2026Unreviewed
Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair
Benjamin Agyekum, Fabio Santos
Abstract
Background: Iterative feedback loops are the dominant paradigm for improving LLM-generated Infrastructure-as-Code (IaC): validators such as Checkov and terraform validate feed error signals back for successive repair attempts. Prior work reports cumulative-best metrics, which are non-decreasing by construction, so the raw per-iteration security trajectory has never been examined for IaC. Aims: We study security regression (a previously-passing CIS Benchmark check that fails after a repair iterat
Categories
Cite
@misc{agyekum2026does,
title = {{Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair}},
author = {Benjamin Agyekum and Fabio Santos},
year = {2026},
month = aug,
eprint = {2608.13404},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.13404}
}