From Reviewers' Lens: Understanding Bug Bounty Report Invalid Reasons with LLMs
Fuente:
arXiv
Saved in:
| Main Authors: | Zheng, Jiangrui, Zhou, Yingming, Ahmad, Ali Abdullah, Yao, Hanqing, Liu, Xueqing |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Can Highlighting Help GitHub Maintainers Track Security Fixes?
by: Liu, Xueqing, et al.
Published: (2024)
by: Liu, Xueqing, et al.
Published: (2024)
A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
by: Ayala, Jessy, et al.
Published: (2024)
by: Ayala, Jessy, et al.
Published: (2024)
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
by: Ayala, Jessy, et al.
Published: (2025)
by: Ayala, Jessy, et al.
Published: (2025)
Incentives and Outcomes in Bug Bounties
by: Wang, Serena, et al.
Published: (2025)
by: Wang, Serena, et al.
Published: (2025)
Fast and Accurate Silent Vulnerability Fix Retrieval
by: Liu, Xueqing, et al.
Published: (2025)
by: Liu, Xueqing, et al.
Published: (2025)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
by: Han, Junxiao, et al.
Published: (2025)
by: Han, Junxiao, et al.
Published: (2025)
SEDAC: A CVAE-Based Data Augmentation Method for Security Bug Report Identification
by: Liao, Y., et al.
Published: (2024)
by: Liao, Y., et al.
Published: (2024)
SmartPoC: Generating Executable and Validated PoCs for Smart Contract Bug Reports
by: Chen, Longfei, et al.
Published: (2025)
by: Chen, Longfei, et al.
Published: (2025)
Fixing 7,400 Bugs for 1$: Cheap Crash-Site Program Repair
by: Zheng, Han, et al.
Published: (2025)
by: Zheng, Han, et al.
Published: (2025)
PROMFUZZ: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart Contracts
by: Lin, Xingshuang, et al.
Published: (2025)
by: Lin, Xingshuang, et al.
Published: (2025)
Hunting CUDA Bugs at Scale with cuFuzz
by: ziad, Mohamed Tarek Ibn, et al.
Published: (2026)
by: ziad, Mohamed Tarek Ibn, et al.
Published: (2026)
Do Fine-Tuned LLMs Understand Vulnerabilities? An Investigation into the Semantic Trap
by: Huang, Feiyang, et al.
Published: (2026)
by: Huang, Feiyang, et al.
Published: (2026)
Automatic Detection of Reference Counting Bugs in Linux Kernel Drivers
by: Hattori, Joe, et al.
Published: (2026)
by: Hattori, Joe, et al.
Published: (2026)
Exposing Go's Hidden Bugs: A Novel Concolic Framework
by: Gorna, Karolina, et al.
Published: (2025)
by: Gorna, Karolina, et al.
Published: (2025)
LineBreaker: Finding Token-Inconsistency Bugs with Large Language Models
by: Chen, Hongbo, et al.
Published: (2024)
by: Chen, Hongbo, et al.
Published: (2024)
HyperPUT: Generating Synthetic Faulty Programs to Challenge Bug-Finding Tools
by: Felici, Riccardo, et al.
Published: (2022)
by: Felici, Riccardo, et al.
Published: (2022)
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
by: Asmita, et al.
Published: (2024)
by: Asmita, et al.
Published: (2024)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
by: Huang, Yiheng, et al.
Published: (2026)
by: Huang, Yiheng, et al.
Published: (2026)
MirrorFuzz: Leveraging LLM and Shared Bugs for Deep Learning Framework APIs Fuzzing
by: Ou, Shiwen, et al.
Published: (2025)
by: Ou, Shiwen, et al.
Published: (2025)
Using LLMs for Security Advisory Investigations: How Far Are We?
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
VulInstruct: Teaching LLMs Root-Cause Reasoning for Vulnerability Detection via Security Specifications
by: Zhu, Hao, et al.
Published: (2025)
by: Zhu, Hao, et al.
Published: (2025)
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
by: Ryan, Ahmed, et al.
Published: (2026)
by: Ryan, Ahmed, et al.
Published: (2026)
Understanding the Supply Chain and Risks of Large Language Model Applications
by: Ma, Yujie, et al.
Published: (2025)
by: Ma, Yujie, et al.
Published: (2025)
Automated TEE Adaptation with LLMs: Identifying, Transforming, and Porting Sensitive Functions in Programs
by: Han, Ruidong, et al.
Published: (2025)
by: Han, Ruidong, et al.
Published: (2025)
UBfuzz: Finding Bugs in Sanitizer Implementations
by: Li, Shaohua, et al.
Published: (2024)
by: Li, Shaohua, et al.
Published: (2024)
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023)
by: Mousavi, Zahra, et al.
Published: (2023)
SecDOAR: A Software Reference Architecture for Security Data Orchestration, Analysis and Reporting
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
SolPhishHunter: Towards Detecting and Understanding Phishing on Solana
by: Li, Ziwei, et al.
Published: (2025)
by: Li, Ziwei, et al.
Published: (2025)
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
by: Wu, Jiangrong, et al.
Published: (2026)
by: Wu, Jiangrong, et al.
Published: (2026)
PrediQL: Automated Testing of GraphQL APIs with LLMs
by: Liu, Shaolun, et al.
Published: (2025)
by: Liu, Shaolun, et al.
Published: (2025)
Arguzz: Testing zkVMs for Soundness and Completeness Bugs
by: Hochrainer, Christoph, et al.
Published: (2025)
by: Hochrainer, Christoph, et al.
Published: (2025)
Unsupervised Binary Code Translation with Application to Code Similarity Detection and Vulnerability Discovery
by: Ahmad, Iftakhar, et al.
Published: (2024)
by: Ahmad, Iftakhar, et al.
Published: (2024)
LSPFuzz: Hunting Bugs in Language Servers
by: Zhu, Hengcheng, et al.
Published: (2025)
by: Zhu, Hengcheng, et al.
Published: (2025)
Do Privacy Policies Match with the Logs? An Empirical Study of Privacy Disclosure in Android Application Logs
by: Chen, Zhiyuan, et al.
Published: (2026)
by: Chen, Zhiyuan, et al.
Published: (2026)
PATCHEVAL: A New Benchmark for Evaluating LLMs on Patching Real-World Vulnerabilities
by: Wei, Zichao, et al.
Published: (2025)
by: Wei, Zichao, et al.
Published: (2025)
Reentrancy Detection in the Age of LLMs
by: Ressi, Dalila, et al.
Published: (2026)
by: Ressi, Dalila, et al.
Published: (2026)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Semantics-Aligned, Curriculum-Driven, and Reasoning-Enhanced Vulnerability Repair Framework
by: Yang, Chengran, et al.
Published: (2025)
by: Yang, Chengran, et al.
Published: (2025)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
Similar Items
-
Can Highlighting Help GitHub Maintainers Track Security Fixes?
by: Liu, Xueqing, et al.
Published: (2024) -
A Deep Dive Into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
by: Ayala, Jessy, et al.
Published: (2024) -
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
by: Ayala, Jessy, et al.
Published: (2025) -
Incentives and Outcomes in Bug Bounties
by: Wang, Serena, et al.
Published: (2025) -
Fast and Accurate Silent Vulnerability Fix Retrieval
by: Liu, Xueqing, et al.
Published: (2025)