The experimental results demonstrate that while static analyzers provide deterministic rigor, LLMs offer the semantic depth necessary to filter out irrelevant alerts and understand program logic.
The increasing integration of large language models (LLMs) into systems introduces new attack surfaces that extend beyond traditional software vulnerabilities. While LLMs are commonly protected by prompt-level security mechanisms, recent researches show that these controls can be bypassed through carefully crafted inpu...
Tamás Girászi, Natália Papp, Norbert Oláh et al.· Proceedings of the 13th Inte...· 0 citations
A security assessment on 75 FastAPI backends generated by three contemporary LLMs revealed a disconnect between functional correctness and secure logic, which is interpreted as a review-risk pattern, which is called the human-in-the-loop paradox.
Abdul Ali Khan, S. Rauti, T. Mäkilä· IEEE Access· 0 citations
JavaScript powers approximately 98.8% of all websites, making vulnerabilities in its code a significant security risk, yet existing detection approaches such as Static Application Security Testing (SAST) tools often fail to identify many real-world vulnerabilities when applied to isolated code snippets. This paper pres...
Manit Kaushik, Ishir Bhardwaj, Pranav Gupta et al.· 0 citations
Experimental results show that AST-based structural features substantially improve recall compared with the TF-IDF baseline, while the combined TF-IDF and AST representation maintains this improved performance.
Vani Pasupula, M. N. V. Manikanth, Nagaraju Vassey· International Journal of Cre...· 0 citations
Investigating Behavior Trees (BTs) as an alternative intermediate representation for LLM-based vulnerability detection suggests that BTs can provide a compact and useful structured representation for vulnerability detection with quantized, locally deployable LLMs.
Variability-aware analysis plays an important role in early defect detection by identifying inconsistencies between variability requirements and their implementation in code. Such analysis is especially needed when developing configurable software and product lines. While many variability-aware parsers have been develo...
Chin Khor, Robyn R. Lutz, Amir Niaraki· Companion Proceedings of the...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.