Skip to content

Research on a hybrid approach to detecting software code vulnerabilities using LLM in combination with SAST tools

2026 · CSDP · pp. 309-317 · 0 citations · 32 references
Computer Science

TL;DR

The experimental results demonstrate that while static analyzers provide deterministic rigor, LLMs offer the semantic depth necessary to filter out irrelevant alerts and understand program logic.

View source

Similar papers

Conference Open access 2026

LLM-Powered Automated Attacks

The increasing integration of large language models (LLMs) into systems introduces new attack surfaces that extend beyond traditional software vulnerabilities. While LLMs are commonly protected by prompt-level security mechanisms, recent researches show that these controls can be bypassed through carefully crafted inpu...

Tamás Girászi, Natália Papp, Norbert Oláh et al. · 0 citations
Review Open access 2026

Security Analysis of LLM-Generated Web API Backends

A security assessment on 75 FastAPI backends generated by three contemporary LLMs revealed a disconnect between functional correctness and secure logic, which is interpreted as a review-risk pattern, which is called the human-in-the-loop paradox.

Abdul Ali Khan, S. Rauti, T. Mäkilä · 0 citations
#artificial intelligence Preprint Sep 2026

Exploring Automated Vulnerability Identification in JavaScript Code Using Large Language Models

JavaScript powers approximately 98.8% of all websites, making vulnerabilities in its code a significant security risk, yet existing detection approaches such as Static Application Security Testing (SAST) tools often fail to identify many real-world vulnerabilities when applied to isolated code snippets. This paper pres...

Manit Kaushik, Ishir Bhardwaj, Pranav Gupta et al. · 0 citations
Open access Aug 2026

Static Code Analysis Framework for Automated Security Vulnerability Detection

Experimental results show that AST-based structural features substantially improve recall compared with the TF-IDF baseline, while the combined TF-IDF and AST representation maintains this improved performance.

Vani Pasupula, M. N. V. Manikanth, Nagaraju Vassey · 0 citations
#small language model Preprint Sep 2026

Towards Behavior Tree-Guided Vulnerability Detection with Lightweight LLMs

Investigating Behavior Trees (BTs) as an alternative intermediate representation for LLM-based vulnerability detection suggests that BTs can provide a compact and useful structured representation for vulnerability detection with quantized, locally deployable LLMs.

Enna Bašić, A. Giaretta · 0 citations
Book Open access Oct 2026

VarCHEKER: A Variability-Based Static Analyzer for Python Applications

Variability-aware analysis plays an important role in early defect detection by identifying inconsistencies between variability requirements and their implementation in code. Such analysis is especially needed when developing configurable software and product lines. While many variability-aware parsers have been develo...

Chin Khor, Robyn R. Lutz, Amir Niaraki · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.