Saved in:
Bibliographic Details
Main Authors: Li, Penghui, Yao, Songchen, Korich, Josef Sarfati, Luo, Changhua, Yu, Jianjia, Cao, Yinzhi, Yang, Junfeng
Format: Preprint
Published: 2025
Subjects:
Online Access:https://arxiv.org/abs/2504.16057
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915935463407616
author Li, Penghui
Yao, Songchen
Korich, Josef Sarfati
Luo, Changhua
Yu, Jianjia
Cao, Yinzhi
Yang, Junfeng
author_facet Li, Penghui
Yao, Songchen
Korich, Josef Sarfati
Luo, Changhua
Yu, Jianjia
Cao, Yinzhi
Yang, Junfeng
contents In this work, we present MoCQ, a neuro-symbolic static analysis framework that leverages large language models (LLMs) to automatically generate vulnerability detection patterns. This approach combines the precision and scalability of pattern-based static analysis with the semantic understanding and automation capabilities of LLMs. MoCQ extracts the domain-specific languages for expressing vulnerability patterns and employs an iterative refinement loop with trace-driven symbolic validation that provides precise feedback for pattern correction. We evaluated MoCQ on 12 vulnerability types across four languages (C/C++, Java, PHP, JavaScript). MoCQ achieves detection performance comparable to expert-developed patterns while requiring only hours of generation versus weeks of manual effort. Notably, MoCQ uncovered 46 new vulnerability patterns that security experts had missed and discovered 25 previously unknown vulnerabilities in real-world applications. MoCQ also outperforms prior approaches with stronger analysis capabilities and broader applicability.
format Preprint
id arxiv_https___arxiv_org_abs_2504_16057
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Neuro-symbolic Static Analysis with LLM-generated Vulnerability Patterns
Li, Penghui
Yao, Songchen
Korich, Josef Sarfati
Luo, Changhua
Yu, Jianjia
Cao, Yinzhi
Yang, Junfeng
Cryptography and Security
In this work, we present MoCQ, a neuro-symbolic static analysis framework that leverages large language models (LLMs) to automatically generate vulnerability detection patterns. This approach combines the precision and scalability of pattern-based static analysis with the semantic understanding and automation capabilities of LLMs. MoCQ extracts the domain-specific languages for expressing vulnerability patterns and employs an iterative refinement loop with trace-driven symbolic validation that provides precise feedback for pattern correction. We evaluated MoCQ on 12 vulnerability types across four languages (C/C++, Java, PHP, JavaScript). MoCQ achieves detection performance comparable to expert-developed patterns while requiring only hours of generation versus weeks of manual effort. Notably, MoCQ uncovered 46 new vulnerability patterns that security experts had missed and discovered 25 previously unknown vulnerabilities in real-world applications. MoCQ also outperforms prior approaches with stronger analysis capabilities and broader applicability.
title Neuro-symbolic Static Analysis with LLM-generated Vulnerability Patterns
topic Cryptography and Security
url https://arxiv.org/abs/2504.16057