Mutation-based Evaluation of Cryptographic API Misuse Detectors
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | Ami, Amit Seal, Marsden, Scott, Moran, Kevin, Poshyvanyk, Denys, Nadkarni, Adwait |
|---|---|
| Format: | Preprint |
| Publié: |
2021
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
Documents similaires
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
par: Ami, Amit Seal, et autres
Publié: (2023)
par: Ami, Amit Seal, et autres
Publié: (2023)
Evaluating Cryptographic API Misuse Detectors for Go
par: Andersson, Vivi, et autres
Publié: (2026)
par: Andersson, Vivi, et autres
Publié: (2026)
Generating API Parameter Security Rules with LLM for API Misuse Detection
par: Liu, Jinghua, et autres
Publié: (2024)
par: Liu, Jinghua, et autres
Publié: (2024)
From base cases to backdoors: An Empirical Study of Unnatural Crypto-API Misuse
par: Olaiya, Victor, et autres
Publié: (2025)
par: Olaiya, Victor, et autres
Publié: (2025)
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
par: Lu, Tianhe, et autres
Publié: (2026)
par: Lu, Tianhe, et autres
Publié: (2026)
Understanding Privacy Risks in Code Models Through Training Dynamics: A Causal Approach
par: Yang, Hua, et autres
Publié: (2025)
par: Yang, Hua, et autres
Publié: (2025)
An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code
par: Elsayed, Mohamed, et autres
Publié: (2026)
par: Elsayed, Mohamed, et autres
Publié: (2026)
Detecting Misuse of Security APIs: A Systematic Review
par: Mousavi, Zahra, et autres
Publié: (2023)
par: Mousavi, Zahra, et autres
Publié: (2023)
How Do Semantically Equivalent Code Transformations Impact Membership Inference on LLMs for Code?
par: Yang, Hua, et autres
Publié: (2025)
par: Yang, Hua, et autres
Publié: (2025)
LibScan: Smart Contract Library Misuse Detection with Iterative Feedback and Static Verification
par: Wang, Yishun, et autres
Publié: (2026)
par: Wang, Yishun, et autres
Publié: (2026)
Demystifying and Detecting Cryptographic Defects in Ethereum Smart Contracts
par: Zhang, Jiashuo, et autres
Publié: (2024)
par: Zhang, Jiashuo, et autres
Publié: (2024)
Towards Efficient Verification of Constant-Time Cryptographic Implementations
par: Cai, Luwei, et autres
Publié: (2024)
par: Cai, Luwei, et autres
Publié: (2024)
Testing Practices, Challenges, and Developer Perspectives in Open-Source IoT Platforms
par: Rodriguez-Cardenas, Daniel, et autres
Publié: (2025)
par: Rodriguez-Cardenas, Daniel, et autres
Publié: (2025)
Architecture-Derived CBOMs for Cryptographic Migration: A Security-Aware Architecture Tradeoff Method
par: Hirsch, Eduard, et autres
Publié: (2026)
par: Hirsch, Eduard, et autres
Publié: (2026)
BIDO: An Out-Of-Distribution Resistant Image-based Malware Detector
par: Wang, Wei, et autres
Publié: (2025)
par: Wang, Wei, et autres
Publié: (2025)
When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum Infrastructure
par: Ma, Jie, et autres
Publié: (2026)
par: Ma, Jie, et autres
Publié: (2026)
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
par: Firouzi, Ehsan, et autres
Publié: (2024)
par: Firouzi, Ehsan, et autres
Publié: (2024)
Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
par: Sahin, Omur, et autres
Publié: (2026)
par: Sahin, Omur, et autres
Publié: (2026)
GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
par: Tsai, Omar, et autres
Publié: (2025)
par: Tsai, Omar, et autres
Publié: (2025)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
par: Rahman, Imranur, et autres
Publié: (2024)
par: Rahman, Imranur, et autres
Publié: (2024)
BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
par: Yang, Yanjing, et autres
Publié: (2025)
par: Yang, Yanjing, et autres
Publié: (2025)
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
par: Zhang, Fangyuan, et autres
Publié: (2024)
par: Zhang, Fangyuan, et autres
Publié: (2024)
Security Testing of RESTful APIs With Test Case Mutation
par: Salva, Sebastien, et autres
Publié: (2024)
par: Salva, Sebastien, et autres
Publié: (2024)
Compositional Jailbreaking: An Empirical Analysis of Mutator Chain Interactions in Aligned LLMs
par: Bugnot, Reinelle Jan, et autres
Publié: (2026)
par: Bugnot, Reinelle Jan, et autres
Publié: (2026)
Fine-Tuning LLMs for Code Mutation: A New Era of Cyber Threats
par: Setak, Mohammad, et autres
Publié: (2024)
par: Setak, Mohammad, et autres
Publié: (2024)
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
par: Li, Zhen, et autres
Publié: (2024)
par: Li, Zhen, et autres
Publié: (2024)
Designing Robust API Monitoring Solutions
par: D'Elia, Daniele Cono, et autres
Publié: (2020)
par: D'Elia, Daniele Cono, et autres
Publié: (2020)
zkCraft: Prompt-Guided LLM as a Zero-Shot Mutation Pattern Oracle for TCCT-Powered ZK Fuzzing
par: Fu, Rong, et autres
Publié: (2026)
par: Fu, Rong, et autres
Publié: (2026)
Evaluating and Improving the Robustness of Security Attack Detectors Generated by LLMs
par: Pasini, Samuele, et autres
Publié: (2024)
par: Pasini, Samuele, et autres
Publié: (2024)
Beyond Fidelity: Explaining Vulnerability Localization of Learning-based Detectors
par: Cheng, Baijun, et autres
Publié: (2024)
par: Cheng, Baijun, et autres
Publié: (2024)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
par: Han, Junxiao, et autres
Publié: (2025)
par: Han, Junxiao, et autres
Publié: (2025)
Many Tools, Few Exploitable Vulnerabilities: A Survey of 246 Static Code Analyzers for Security
par: Hermann, Kevin, et autres
Publié: (2026)
par: Hermann, Kevin, et autres
Publié: (2026)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
par: Li, Zhihao, et autres
Publié: (2025)
par: Li, Zhihao, et autres
Publié: (2025)
Vulnerability Detection in Popular Programming Languages with Language Models
par: Atiiq, Syafiq Al, et autres
Publié: (2024)
par: Atiiq, Syafiq Al, et autres
Publié: (2024)
Analysis of Commit Signing on Github
par: Shittu, Abubakar Sadiq, et autres
Publié: (2026)
par: Shittu, Abubakar Sadiq, et autres
Publié: (2026)
Automatically Detecting Checked-In Secrets in Android Apps: How Far Are We?
par: Li, Kevin, et autres
Publié: (2024)
par: Li, Kevin, et autres
Publié: (2024)
How Far are App Secrets from Being Stolen? A Case Study on Android
par: Wei, Lili, et autres
Publié: (2025)
par: Wei, Lili, et autres
Publié: (2025)
An Exploratory Study on the Engineering of Security Features
par: Hermann, Kevin, et autres
Publié: (2025)
par: Hermann, Kevin, et autres
Publié: (2025)
From Generalist to Specialist: Exploring CWE-Specific Vulnerability Detection
par: Atiiq, Syafiq Al, et autres
Publié: (2024)
par: Atiiq, Syafiq Al, et autres
Publié: (2024)
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
par: Asmita, et autres
Publié: (2024)
par: Asmita, et autres
Publié: (2024)
Documents similaires
-
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
par: Ami, Amit Seal, et autres
Publié: (2023) -
Evaluating Cryptographic API Misuse Detectors for Go
par: Andersson, Vivi, et autres
Publié: (2026) -
Generating API Parameter Security Rules with LLM for API Misuse Detection
par: Liu, Jinghua, et autres
Publié: (2024) -
From base cases to backdoors: An Empirical Study of Unnatural Crypto-API Misuse
par: Olaiya, Victor, et autres
Publié: (2025) -
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
par: Lu, Tianhe, et autres
Publié: (2026)