LLM-Assisted Porting of Security-Critical C Libraries to Idiomatic Rust: A Multi-Model Empirical Study
Abstract
1. Introduction
- RQ1 (Structural safety). Do LLM-assisted Rust portings of a security-critical C library eliminate the library’s documented memory-safety vulnerability classes by construction, and does this hold consistently across models that differ in scale, architecture, and deployment mode? This question is addressed by the per-CVE verification and fuzzing results in Section 4 and revisited in Section 5.
- RQ2 (Code quality and performance). How do the correctness, idiomaticity, and runtime performance of LLM-generated portings compare to one another and to a manual expert baseline, and what factors are associated with the observed differences? This question is addressed in Section 4 and Section 5, including the self-correction analysis and the manual-versus-LLM complementarity study.
- RQ3 (Stability). How much of the observed variation in code quality and performance across models reflects genuine model-level differences, as opposed to stochastic variation inherent to a single agentic generation attempt? This question motivates the Kimi intra-model variance study and the statistical treatment described in Section 3.5 and reported in Section 4.
- RQ4 (Practice). Given the above, what verification workflow and practical guidance follow for a team planning an LLM-assisted C-to-Rust migration? This question is addressed directly in Section 5.7.
2. Related Work
2.1. Memory Safety, Rust, and Institutional Momentum
2.2. Automated and LLM-Assisted C-to-Rust Translation
2.3. Positioning of This Work
3. Materials and Methods
3.1. Target Library: cJSON
3.2. Dual-Approach Methodology
3.3. LLM Models and Experimental Setup
3.4. Verification Pipeline
3.5. Statistical Treatment
3.6. Threats to Validity
4. Results
4.1. Functional Correctness and Security
4.2. Idiomaticity
| Listing 1. Error-handling comparison for object-key lookup. |
|
4.3. Performance
4.4. Multi-Model Comparison
4.5. Intra-Model Variance Study (Kimi, )
5. Discussion
5.1. Structural Safety vs. Code Quality
5.2. Self-Correction and Test-Suite Quality
5.3. Complementarity of Manual and LLM Portings
5.4. Realistic Time Accounting
5.5. Computational and Monetary Cost
5.6. Industrial Deployment Challenges
5.7. Practical Guidance for Practitioners
5.8. Implications for Internet Infrastructure Security
6. Conclusions
Future Work
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| LLM | Large Language Model |
| CVE | Common Vulnerabilities and Exposures |
| LOC | Lines of Code |
| RAII | Resource Acquisition Is Initialization |
| FFI | Foreign Function Interface |
| API | Application Programming Interface |
| OOB | Out of Bounds |
| UB | Undefined Behavior |
| CI | Confidence Interval |
| CLI | Command-Line Interface |
Appendix A. Abridged Prompt
| Listing A1. Abridged prompt (common to all five models). |
|
References
- Microsoft Security Response Center. Trends, Challenges, and Strategic Shifts in the Software Vulnerability Landscape; Technical Report; Microsoft Corporation: Redmond, WA, USA, 2019. [Google Scholar]
- The Chromium Project. Memory Safety. 2020. Available online: https://www.chromium.org/Home/chromium-security/memory-safety/ (accessed on 22 August 2026).
- CISA. The Case for Memory Safe Roadmaps; Technical Report; CISA: Washington, DC, USA, 2023. [Google Scholar]
- Office of the National Cyber Director. Back to the Building Blocks; Technical Report; The White House: Washington, DC, USA, 2024. [Google Scholar]
- CISA; NSA. Memory Safe Languages: Reducing Vulnerabilities in Modern Software Development; Technical Report; CISA: Washington, DC, USA; NASA: Washington, DC, USA, 2025. [Google Scholar]
- DARPA. TRACTOR: Translating all C to Rust. 2024. Available online: https://www.darpa.mil/research/programs/translating-all-c-to-rust (accessed on 4 April 2026).
- Matsakis, N.D.; Klock, F.S. The Rust language. ACM SIGAda Ada Lett. 2014, 34, 103–104. [Google Scholar] [CrossRef] [Scilit]
- Klabnik, S.; Nichols, C. The Rust Programming Language, 2nd ed.; No Starch Press: San Francisco, CA, USA, 2023. [Google Scholar]
- Jung, R.; Jourdan, J.-H.; Krebbers, R.; Dreyer, D. RustBelt: Securing the foundations of the Rust programming language. Proc. ACM Program. Lang. 2018, 2, 1–34. [Google Scholar] [CrossRef] [Scilit]
- Panter, S.K.; Eisty, N.U. Rusty Linux: Advances in Rust for Linux kernel development. In Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement 2024, Barcelona, Spain, 24–25 October 2024; pp. 496–502. [Google Scholar]
- Vander Stoep, J. Memory Safe Languages in Android 13; Google Security Blog: Mountain View, CA, USA, 2022. [Google Scholar]
- Vander Stoep, J.; Rebert, A. Eliminating Memory Safety Vulnerabilities at the Source; Google Security Blog: Mountain View, CA, USA, 2024. [Google Scholar]
- Vander Stoep, J.; Rebert, A. Rust in Android: Move Fast and Fix Things; Google Security Blog: Mountain View, CA, USA, 2025. [Google Scholar]
- Ryhl, A.; Llamas, C. A Rust implementation of Android’s Binder. In Proceedings of the Linux Plumbers Conference 2024, Vienna, Austria, 18–20 September 2024. [Google Scholar]
- Immunant and Galois. c2rust: Migrate C Code to Rust. 2024. Available online: https://github.com/immunant/c2rust (accessed on 4 April 2026).
- Emre, M.; Schroeder, R.; Dewey, K.; Hardekopf, B. Translating C to safer Rust. Proc. ACM Program. Lang. 2021, 5, 1–29. [Google Scholar] [CrossRef] [Scilit]
- Emre, M.; Boyland, P.; Parekh, A.; Schroeder, R.; Dewey, K.; Hardekopf, B. Aliasing limits on translating C to safe Rust. Proc. ACM Program. Lang. 2023, 7, 1–29. [Google Scholar] [CrossRef] [Scilit]
- Vaswani, A.; Shazeer, N.; Parmar, N.; Uszkoreit, J.; Jones, L.; Gomez, A.N.; Kaiser, L.; Polosukhin, I. Attention is all you need. In Proceedings of the 31st Annual Conference on Neural Information Processing Systems, NeurIPS 2017, Long Beach, CA, USA, 4–9 December 2017; Volume 30. [Google Scholar]
- Chen, M.; Tworek, J.; Jun, H.; Yuan, Q.; Pinto, H.P.D.O.; Kaplan, J.; Edwards, H.; Burda, Y.; Joseph, M.; Brockman, G.; et al. Evaluating large language models trained on code. arXiv 2021, arXiv:2107.03374. [Google Scholar]
- Anthropic. How AI Helps Break the Cost Barrier to COBOL Modernization. 2026. Available online: https://claude.com/blog/how-ai-helps-break-cost-barrier-cobol-modernization (accessed on 4 April 2026).
- Sumner, J.; Bun Contributors. Port Bun from Zig to Rust (PR #30412). 2026. Available online: https://github.com/oven-sh/bun/pull/30412 (accessed on 4 April 2026).
- Szekeres, L.; Payer, M.; Wei, T.; Song, D. SoK: Eternal War in Memory. In Proceedings of the IEEE Symposium on Security and Privacy, San Francisco, CA, USA, 19–22 May 2013; pp. 48–62. [Google Scholar]
- Serebryany, K.; Bruening, D.; Potapenko, A.; Vyukov, D. AddressSanitizer: A fast address sanity checker. In Proceedings of the 2012 USENIX annual technical conference (USENIX ATC 12), Boston, MA, USA, 13–15 June 2012; pp. 309–318. [Google Scholar]
- Xu, H.; Chen, Z.; Sun, M.; Zhou, Y.; Lyu, M.R. Memory-safety challenge considered solved? An in-depth study with all Rust CVEs. ACM Trans. Softw. Eng. Methodol. 2022, 31, 1–25. [Google Scholar] [CrossRef] [Scilit]
- Li, Z.; Narayanan, V.; Chen, X.; Zhang, J.; Burtsev, A. Rust for Linux: Understanding the security impact of Rust in the Linux kernel. In Proceedings of the 40th Annual Computer Security Applications Conference (ACSAC 2024), Honolulu, HI, USA, 9–13 December 2024; pp. 548–562. [Google Scholar]
- Zhang, H.; David, C.; Yu, Y.; Wang, M. Ownership guided C to Rust translation. In Proceedings of the International Conference on Computer Aided Verification 2023; LNCS 13966; Springer: Cham, Switzerland, 2023; pp. 459–482. [Google Scholar]
- Nitin, V.; Krishna, R.; do Valle, L.L.; Ray, B. C2SaferRust: Transforming C projects into safer Rust. arXiv 2025, arXiv:2501.14257. [Google Scholar]
- Yang, A.Z.; Takashima, Y.; Paulsen, B.; Dodds, J.; Kroening, D. VERT: Verified equivalent Rust transpilation with LLMs. In Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering, Porto de Galinhas, Brazil, 15–19 July 2024. [Google Scholar]
- Pan, R.; Ibrahimzada, A.R.; Krishna, R.; Sankar, D.; Wassi, L.P.; Merler, M.; Sobolev, B.; Pavuluri, R.; Sinha, S.; Jabbarvand, R. Lost in translation: A study of bugs introduced by LLMs while translating code. In Proceedings of the IEEE/ACM 46th International Conference on Software Engineering 2024, Lisbon, Portugal, 14–20 April 2024. [Google Scholar]
- Eniser, H.F.; Zhang, H.; David, C.; Wang, M.; Christakis, M.; Paulsen, B.; Dodds, J.; Kroening, D. Towards translating real-world code with LLMs: A study of translating to Rust. arXiv 2024, arXiv:2405.11514. [Google Scholar]
- Li, R.; Wang, B.; Li, T.; Saxena, P.; Kundu, A. Translating C to Rust: Lessons from a user study. In Proceedings of the Network and Distributed System Security (NDSS) Symposium 2025, San Diego, CA, USA, 24–28 February 2025. [Google Scholar]
- Khatry, A.; Zhang, R.; Pan, J.; Wang, Z.; Chen, Q.; Durrett, G.; Dillig, I. CRUST-Bench: A comprehensive benchmark for C-to-safe-Rust transpilation. In Proceedings of the 2nd Conference on Language Modeling (COLM 2025), Montreal, QC, Canada, 7–10 October 2025. [Google Scholar]
- Farrukh, M.; Coskun, B.; Palit, T.; Polychronakis, M. SafeTrans: LLM-assisted transpilation from C to Rust. arXiv 2025, arXiv:2505.10708. [Google Scholar]
- Zhou, T.; Zhang, Z.; Lin, H.; Jha, S.; Christodorescu, M.; Levchenko, K.; Chandrasekaran, V. SACTOR: LLM-driven correct and idiomatic C to Rust translation. arXiv 2025, arXiv:2503.12511. [Google Scholar]
- Shiraishi, M.; Cao, Y.; Shinagawa, T. SmartC2Rust: Iterative, feedback-driven C-to-Rust translation via LLMs. In Proceedings of the IEEE/ACM International Conference on Software Engineering, Rio de Janeiro, Brazil, 12–18 April 2026. [Google Scholar]
- Wang, C.; Yu, T.; Shen, B.; Wang, J.; Chen, D.; Zhang, W.; Shi, Y.; Xie, C.; Gu, X. EvoC2Rust: A skeleton-guided framework for project-level C-to-Rust translation. In Proceedings of the IEEE/ACM 48th International Conference on Software Engineering: Software Engineering in Practice, Rio de Janeiro, Brazil, 12–18 April 2026. [Google Scholar]
- Dehghan, S.; Sun, T.; Wu, T.; Li, Z.; Jabbarv, R. Translating large-scale C repositories to idiomatic Rust. arXiv 2025, arXiv:2511.20617. [Google Scholar]
- Tadesse, B.; Nitin, V.; Salah, M.; Ray, B.; d’Amorim, M.; Assunção, W. Code quality analysis of translations from C to Rust. arXiv 2025, arXiv:2602.00840. [Google Scholar]
- Gamble, D.; Bruckner, M. cJSON: Ultralightweight JSON Parser in ANSI C. 2024. Available online: https://github.com/DaveGamble/cJSON (accessed on 4 April 2026).
- Bray, T. The JavaScript Object Notation (JSON) Data Interchange Format; Textuality: Vancouver, BC, Canada, 2017. [Google Scholar]
- Grassi, M. cJSON Buffer Over-Read Vulnerability (CVE-2016-10749). Oss-Security, 2016. Available online: https://www.openwall.com/lists/oss-security/2016/11/07/2 (accessed on 4 April 2026).
- Wei, J.; Wang, X.; Schuurmans, D.; Bosma, M.; Ichter, B.; Xia, F.; Chi, E.H.; Le, Q.V.; Zhou, D. Chain-of-thought prompting elicits reasoning in large language models. Adv. Neural Inf. Process. Syst. 2022, 35, 24824–24837. [Google Scholar] [CrossRef] [Scilit]
- Jung, R.; Kimock, B.; Poveda, C.; Muñoz, E.S.; Scherer, O.; Wang, Q. Miri: Practical undefined behavior detection for Rust. In Proceedings of the ACM on Programming Languages, Rennes, France, 12–13 January 2026; Volume 10. [Google Scholar]
- Rust-Fuzz Contributors. Cargo-Fuzz: Command Line Helpers for Fuzzing. 2024. Available online: https://github.com/rust-fuzz/cargo-fuzz (accessed on 4 April 2026).
- Fioraldi, A.; Maier, D.; Eißfeldt, H.; Heuse, M. AFL++: Combining incremental steps of fuzzing research. In Proceedings of the 14th USENIX Workshop on Offensive Technologies (USENIX WOOT), Virtual, 11 August 2020. [Google Scholar]
- Anthropic. Claude Mythos Preview. 2026. Available online: https://red.anthropic.com/2026/mythos-preview/ (accessed on 4 April 2026).
- Stenberg, D. Mythos Finds a Curl Vulnerability. 2026. Available online: https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/ (accessed on 4 April 2026).




| Approach | Correct. | Idiom. | Scale | Security | Multi-Model | Open |
|---|---|---|---|---|---|---|
| c2rust [15] | High | Low | High | No | N/A | Yes |
| VERT [28] | Verified | Med. | Low | No | No | Yes |
| SafeTrans [33] | 80% | High | Med. | Implicit | No | No |
| SACTOR [34] | 84–93% | High | Med. | FFI-based | Yes | Yes |
| SmartC2Rust [35] | 100% | High | Med. | Implicit | No | Yes |
| Rustine [37] | 87% | High | Project | No | No | Yes |
| This work | Verified | High | Med. | Explicit | Yes (5 + N = 5) | Yes |
| Vulnerability Class | Count | Example CVE | Rust Prevention |
|---|---|---|---|
| Buffer overflow/OOB write | 4 | 2016-4303 | Bounds checking on Vec/slice |
| Buffer over-read | 3 | 2016-10749 | &str has known length; no raw pointers |
| Use-after-free | 1 | 2018-1000217 | Ownership: single owner, no aliasing |
| Double free | 1 | 2018-1000216 | Ownership: no explicit free() |
| NULL pointer dereference | 4 | 2019-1010239 | Option<T>; exhaustive pattern matching |
| Memory leak | 1 | 2018-1000215 | RAII: automatic Drop |
| Model | Interface | Context | Deploy | Date | Runs |
|---|---|---|---|---|---|
| Claude Opus 4.6 | Claude Code v2.1 | 200 K | Cloud | Feb 2026 | 1 |
| Gemini 3 Pro Preview | Gemini CLI v0.29.5 | 1 M | Cloud | Feb 2026 | 1 |
| Qwen3.5-27B | OpenCode + Ollama | 64 K | Local | Mar 2026 | 1 |
| GPT-5.4 (Codex) | Codex CLI v0.120.0 | n/a | Cloud | Apr 2026 | 1 |
| Kimi K2.7-Code | OpenCode + Moonshot | n/a | Cloud | Jun 2026 | 5 |
| CVE-ID | Class | CVSS | Rust Mechanism | Man. | Cl. | Gem. | Qw. | Cdx. | Kimi |
|---|---|---|---|---|---|---|---|---|---|
| 2016-4303 | Heap overflow | 9.8 | Hex valid. in parse_hex4 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2016-10749 | Buffer over-read | 9.8 | Bounds check, no raw ptr | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2018-1000215 | Memory leak | 7.5 | RAII: String/Vec, Drop | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2018-1000216 | Double free | 8.8 | Ownership: no free() | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2018-1000217 | Use-after-free | 9.8 | &str + to_string() | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2019-1010239 | NULL deref | 7.5 | Option<&T>, no null | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2019-11834/35 | OOB in Minify | 9.8 | Bounds on bytes.len() | N/P | ✓ | N/P | N/P | ✓ | ✓ |
| 2023-26819 | Stack overflow | 2.9 | No fixed buffer; parse::<f64>() | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2023-50471 | NULL deref | 7.5 | Exhaustive match on enum | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2023-50472 | NULL deref | 7.5 | Non-object → false | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2023-53154 | Heap over-read | 5.5 | &str has known length | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 2024-31755 | NULL deref | 7.6 | &str cannot be NULL | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Operation | Manual | Claude | Gemini | Qwen | Codex | Kimi |
|---|---|---|---|---|---|---|
| Parse | 0.98× | 0.99× | 1.25× | 1.29× | 0.90× | 0.94× |
| Print formatted | 0.95× | 0.67× | 0.83× | 1.50× | 0.74× | 0.76× |
| Print compact | 0.94× | 0.67× | 0.82× | 1.18× | 0.66× | 0.75× |
| Dimension | Manual | Claude | Gemini | Qwen | Codex | Kimi |
|---|---|---|---|---|---|---|
| Generation time | ∼8 h | ∼10 min | ∼25 min | ∼2 h | ∼15 min | ∼17 min |
| LOC | n/a | 2216 | 782 | 1345 | 1546 | 1399 |
| Tests generated | n/a | 95 | 6 | 53 | 20 | 26 |
| Divergences (final) | n/a | 8 | 18+ | 12+ | 16 | 13 |
| Self-corrections | n/a | 5 | 0 | 4 | 3 | 5 |
| Residual bugs | n/a † | 0 | 9 | 8 | 3 | 3 |
| Parse/C | 0.98× | 0.99× | 1.25× | 1.29× | 0.90× | 0.94× |
| Print fmt/C | 0.95× | 0.67× | 0.83× | 1.50× | 0.74× | 0.76× |
| CVEs eliminated | 11/11 | 13/13 | 11/11 | 11/11 | 13/13 | 13/13 |
| unsafe blocks | 0 | 0 | 0 | 0 | 0 | 0 |
| Diff. fuzz vs. C | n/a † | 0/235 M | 3 (imm.) | 2 (imm.) | 2 (imm.) | imm. |
| Run | LOC | Tests | CVE | Unsafe | Miri | Parse | Bugs | |
|---|---|---|---|---|---|---|---|---|
| 1 | 1399 | 26 | 14/14 | 0 | 0 | 0.94× | 0.76× | 3 |
| 2 | 1366 | 41 | 14/14 | 0 | 0 | 0.95× | 0.91× | 3 |
| 3 | 1431 | 32 | 14/14 | 0 | 0 | 0.79× | 0.86× | 3 |
| 4 | 1544 | 31 | 14/14 | 0 | 0 | 0.94× | 0.86× | 4 |
| 5 | 1318 | 27 | 14/14 | 0 | 0 | 0.87× | 0.90× | 2 |
| Range | 1318–1544 | 26–41 | 14/14 | 0 | 0 | 0.79–0.95× | 0.76–0.91× | 2–4 |
| Mean ± 95% CI | 1412 ± 106 | 31.4 ± 7.4 | 14/14 (all) | 0 (all) | 0 (all) | 0.90 ± 0.09 | 0.86 ± 0.07 | 3.0 ± 0.9 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Parrillo, M.; Grassi, M.; Laura, L. LLM-Assisted Porting of Security-Critical C Libraries to Idiomatic Rust: A Multi-Model Empirical Study. Future Internet 2026, 18, 471. https://doi.org/10.3390/fi18090471
Parrillo M, Grassi M, Laura L. LLM-Assisted Porting of Security-Critical C Libraries to Idiomatic Rust: A Multi-Model Empirical Study. Future Internet. 2026; 18(9):471. https://doi.org/10.3390/fi18090471
Chicago/Turabian StyleParrillo, Marco, Marco Grassi, and Luigi Laura. 2026. "LLM-Assisted Porting of Security-Critical C Libraries to Idiomatic Rust: A Multi-Model Empirical Study" Future Internet 18, no. 9: 471. https://doi.org/10.3390/fi18090471
APA StyleParrillo, M., Grassi, M., & Laura, L. (2026). LLM-Assisted Porting of Security-Critical C Libraries to Idiomatic Rust: A Multi-Model Empirical Study. Future Internet, 18(9), 471. https://doi.org/10.3390/fi18090471

