From Trace to Line: LLM Agent for Real-World OSS Vulnerability Localization
Fuente:
arXiv
Saved in:
| Main Authors: | Xi, Haoran, Shao, Minghao, Dolan-Gavitt, Brendan, Shafique, Muhammad, Karri, Ramesh |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
ELFuzz: Efficient Input Generation via LLM-driven Synthesis Over Fuzzer Space
by: Chen, Chuyang, et al.
Published: (2025)
by: Chen, Chuyang, et al.
Published: (2025)
Fixing Security Vulnerabilities with AI in OSS-Fuzz
by: Zhang, Yuntong, et al.
Published: (2024)
by: Zhang, Yuntong, et al.
Published: (2024)
An Empirical Evaluation of LLMs for Solving Offensive Security Challenges
by: Shao, Minghao, et al.
Published: (2024)
by: Shao, Minghao, et al.
Published: (2024)
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
by: Nong, Yu, et al.
Published: (2024)
by: Nong, Yu, et al.
Published: (2024)
ContractTinker: LLM-Empowered Vulnerability Repair for Real-World Smart Contracts
by: Wang, Che, et al.
Published: (2024)
by: Wang, Che, et al.
Published: (2024)
Evaluating Large Language Models for Line-Level Vulnerability Localization
by: Zhang, Jian, et al.
Published: (2024)
by: Zhang, Jian, et al.
Published: (2024)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
by: Schott, Stefan, et al.
Published: (2026)
by: Schott, Stefan, et al.
Published: (2026)
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
by: Dang, Wenjing, et al.
Published: (2025)
by: Dang, Wenjing, et al.
Published: (2025)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
PATCHEVAL: A New Benchmark for Evaluating LLMs on Patching Real-World Vulnerabilities
by: Wei, Zichao, et al.
Published: (2025)
by: Wei, Zichao, et al.
Published: (2025)
Towards Understanding and Characterizing Vulnerabilities in Intelligent Connected Vehicles through Real-World Exploits
by: Wang, Yuelin, et al.
Published: (2026)
by: Wang, Yuelin, et al.
Published: (2026)
Zero-Shot Vulnerability Detection in Low-Resource Smart Contracts Through Solidity-Only Training
by: Hu, Minghao, et al.
Published: (2026)
by: Hu, Minghao, et al.
Published: (2026)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
by: Wu, Jiangrong, et al.
Published: (2026)
by: Wu, Jiangrong, et al.
Published: (2026)
AutoVulnPHP: LLM-Powered Two-Stage PHP Vulnerability Detection and Automated Localization
by: Wang, Zhiqiang, et al.
Published: (2026)
by: Wang, Zhiqiang, et al.
Published: (2026)
FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction
by: Sheng, Ze, et al.
Published: (2026)
by: Sheng, Ze, et al.
Published: (2026)
Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities
by: Ma, Yujie, et al.
Published: (2026)
by: Ma, Yujie, et al.
Published: (2026)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
What Makes a Good LLM Agent for Real-world Penetration Testing?
by: Deng, Gelei, et al.
Published: (2026)
by: Deng, Gelei, et al.
Published: (2026)
Multi-Agent Taint Specification Extraction for Vulnerability Detection
by: Ghebremichael, Jonah, et al.
Published: (2026)
by: Ghebremichael, Jonah, et al.
Published: (2026)
FuzzySQL: Uncovering Hidden Vulnerabilities in DBMS Special Features with LLM-Driven Fuzzing
by: Chen, Yongxin, et al.
Published: (2026)
by: Chen, Yongxin, et al.
Published: (2026)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
by: Han, Junxiao, et al.
Published: (2025)
by: Han, Junxiao, et al.
Published: (2025)
Execution-State-Aware LLM Reasoning for Automated Proof-of-Vulnerability Generation
by: Li, Haoyu, et al.
Published: (2026)
by: Li, Haoyu, et al.
Published: (2026)
From Transactions to Exploits: Automated PoC Synthesis for Real-World DeFi Attacks
by: Su, Xing, et al.
Published: (2026)
by: Su, Xing, et al.
Published: (2026)
From Generalist to Specialist: Exploring CWE-Specific Vulnerability Detection
by: Atiiq, Syafiq Al, et al.
Published: (2024)
by: Atiiq, Syafiq Al, et al.
Published: (2024)
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
Multi-Agent Collaborative Fuzzing with Continuous Reflection for Smart Contracts Vulnerability Detection
by: Chen, Jie, et al.
Published: (2025)
by: Chen, Jie, et al.
Published: (2025)
CRAKEN: Cybersecurity LLM Agent with Knowledge-Based Execution
by: Shao, Minghao, et al.
Published: (2025)
by: Shao, Minghao, et al.
Published: (2025)
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
by: Rosso, Martin, et al.
Published: (2025)
by: Rosso, Martin, et al.
Published: (2025)
LLM4CVE: Enabling Iterative Automated Vulnerability Repair with Large Language Models
by: Fakih, Mohamad, et al.
Published: (2025)
by: Fakih, Mohamad, et al.
Published: (2025)
Match & Mend: Minimally Invasive Local Reassembly for Patching N-day Vulnerabilities in ARM Binaries
by: Jänich, Sebastian, et al.
Published: (2025)
by: Jänich, Sebastian, et al.
Published: (2025)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
by: Ning, Kaiwen, et al.
Published: (2024)
by: Ning, Kaiwen, et al.
Published: (2024)
D-CIPHER: Dynamic Collaborative Intelligent Multi-Agent System with Planner and Heterogeneous Executors for Offensive Security
by: Udeshi, Meet, et al.
Published: (2025)
by: Udeshi, Meet, et al.
Published: (2025)
SecureFixAgent: A Hybrid LLM Agent for Automated Python Static Vulnerability Repair
by: Gajjar, Jugal, et al.
Published: (2025)
by: Gajjar, Jugal, et al.
Published: (2025)
CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics
by: Li, Yikun, et al.
Published: (2024)
by: Li, Yikun, et al.
Published: (2024)
PatchSeeker: Mapping NVD Records to their Vulnerability-fixing Commits with LLM Generated Commits and Embeddings
by: Nguyen, Huu Hung, et al.
Published: (2025)
by: Nguyen, Huu Hung, et al.
Published: (2025)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
by: Cheng, Yiran, et al.
Published: (2024)
by: Cheng, Yiran, et al.
Published: (2024)
How Code Representation Shapes False-Positive Dynamics in Cross-Language LLM Vulnerability Detection
by: Chen, Maofei, et al.
Published: (2026)
by: Chen, Maofei, et al.
Published: (2026)
Security Is Relative: Training-Free Vulnerability Detection via Multi-Agent Behavioral Contract Synthesis
by: Wang, Yongchao, et al.
Published: (2026)
by: Wang, Yongchao, et al.
Published: (2026)
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
by: Li, Zhen, et al.
Published: (2024)
by: Li, Zhen, et al.
Published: (2024)
Similar Items
-
ELFuzz: Efficient Input Generation via LLM-driven Synthesis Over Fuzzer Space
by: Chen, Chuyang, et al.
Published: (2025) -
Fixing Security Vulnerabilities with AI in OSS-Fuzz
by: Zhang, Yuntong, et al.
Published: (2024) -
An Empirical Evaluation of LLMs for Solving Offensive Security Challenges
by: Shao, Minghao, et al.
Published: (2024) -
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
by: Nong, Yu, et al.
Published: (2024) -
ContractTinker: LLM-Empowered Vulnerability Repair for Real-World Smart Contracts
by: Wang, Che, et al.
Published: (2024)