Large Language Models Cannot Reliably Detect Vulnerabilities in JavaScript: The First Systematic Benchmark and Evaluation
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Fei, Qingyuan, Liu, Xin, Li, Song, Wu, Shujiang, Hou, Jianwei, Chen, Ping, Kang, Zifeng |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
von: Ferenc, Rudolf, et al.
Veröffentlicht: (2024)
von: Ferenc, Rudolf, et al.
Veröffentlicht: (2024)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
von: Xia, Yifan, et al.
Veröffentlicht: (2023)
von: Xia, Yifan, et al.
Veröffentlicht: (2023)
PatchFuzz: Patch Fuzzing for JavaScript Engines
von: Wang, Junjie, et al.
Veröffentlicht: (2025)
von: Wang, Junjie, et al.
Veröffentlicht: (2025)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
von: Moreno, José Miguel, et al.
Veröffentlicht: (2024)
von: Moreno, José Miguel, et al.
Veröffentlicht: (2024)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
von: Zhou, Dongchao, et al.
Veröffentlicht: (2025)
von: Zhou, Dongchao, et al.
Veröffentlicht: (2025)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
From Coverage to Causes: Data-Centric Fuzzing for JavaScript Engines
von: Ganguly, Kishan Kumar, et al.
Veröffentlicht: (2025)
von: Ganguly, Kishan Kumar, et al.
Veröffentlicht: (2025)
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
von: Zhang, Lingming, et al.
Veröffentlicht: (2026)
von: Zhang, Lingming, et al.
Veröffentlicht: (2026)
CASCADE: LLM-Powered JavaScript Deobfuscator at Google
von: Jiang, Shan, et al.
Veröffentlicht: (2025)
von: Jiang, Shan, et al.
Veröffentlicht: (2025)
Characterizing JavaScript Security Code Smells
von: Kambhampati, Vikas, et al.
Veröffentlicht: (2024)
von: Kambhampati, Vikas, et al.
Veröffentlicht: (2024)
Obfuscating Code Vulnerabilities against Static Analysis in JavaScript Code
von: Pagano, Francesco, et al.
Veröffentlicht: (2026)
von: Pagano, Francesco, et al.
Veröffentlicht: (2026)
JsDeObsBench: Measuring and Benchmarking LLMs for JavaScript Deobfuscation
von: Chen, Guoqiang, et al.
Veröffentlicht: (2025)
von: Chen, Guoqiang, et al.
Veröffentlicht: (2025)
A Study of Vulnerability Repair in JavaScript Programs with Large Language Models
von: Le, Tan Khang, et al.
Veröffentlicht: (2024)
von: Le, Tan Khang, et al.
Veröffentlicht: (2024)
Blocking Tracking JavaScript at the Function Granularity
von: Amjad, Abdul Haddi, et al.
Veröffentlicht: (2024)
von: Amjad, Abdul Haddi, et al.
Veröffentlicht: (2024)
Characterizing Phishing Pages by JavaScript Capabilities
von: Nahapetyan, Aleksandr, et al.
Veröffentlicht: (2025)
von: Nahapetyan, Aleksandr, et al.
Veröffentlicht: (2025)
Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
von: Robinson, Michael, et al.
Veröffentlicht: (2026)
von: Robinson, Michael, et al.
Veröffentlicht: (2026)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
von: Chen, Zirui, et al.
Veröffentlicht: (2026)
von: Chen, Zirui, et al.
Veröffentlicht: (2026)
Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs
von: Pereira, Pedro, et al.
Veröffentlicht: (2025)
von: Pereira, Pedro, et al.
Veröffentlicht: (2025)
GHunter: Universal Prototype Pollution Gadgets in JavaScript Runtimes
von: Cornelissen, Eric, et al.
Veröffentlicht: (2024)
von: Cornelissen, Eric, et al.
Veröffentlicht: (2024)
Breaking Obfuscation: Cluster-Aware Graph with LLM-Aided Recovery for Malicious JavaScript Detection
von: Liang, Zhihong, et al.
Veröffentlicht: (2025)
von: Liang, Zhihong, et al.
Veröffentlicht: (2025)
FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques
von: Pantelaios, Nikolaos, et al.
Veröffentlicht: (2024)
von: Pantelaios, Nikolaos, et al.
Veröffentlicht: (2024)
An Empirical Study of JavaScript Inclusion Security Issues in Chrome Extensions
von: Guan, Chong
Veröffentlicht: (2025)
von: Guan, Chong
Veröffentlicht: (2025)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
von: Schott, Stefan, et al.
Veröffentlicht: (2026)
von: Schott, Stefan, et al.
Veröffentlicht: (2026)
Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
von: Ali, Mir Masood, et al.
Veröffentlicht: (2024)
von: Ali, Mir Masood, et al.
Veröffentlicht: (2024)
VulDetectBench: Evaluating the Deep Capability of Vulnerability Detection with Large Language Models
von: Liu, Yu, et al.
Veröffentlicht: (2024)
von: Liu, Yu, et al.
Veröffentlicht: (2024)
VulEval: Towards Repository-Level Evaluation of Software Vulnerability Detection
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
AI-Based Software Vulnerability Detection: A Systematic Literature Review
von: Shimmi, Samiha, et al.
Veröffentlicht: (2025)
von: Shimmi, Samiha, et al.
Veröffentlicht: (2025)
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
PATCHEVAL: A New Benchmark for Evaluating LLMs on Patching Real-World Vulnerabilities
von: Wei, Zichao, et al.
Veröffentlicht: (2025)
von: Wei, Zichao, et al.
Veröffentlicht: (2025)
Evaluating Large Language Models for Line-Level Vulnerability Localization
von: Zhang, Jian, et al.
Veröffentlicht: (2024)
von: Zhang, Jian, et al.
Veröffentlicht: (2024)
When Labels Are Scarce: A Systematic Mapping of Label-Efficient Code Vulnerability Detection
von: Khalal, Noor, et al.
Veröffentlicht: (2026)
von: Khalal, Noor, et al.
Veröffentlicht: (2026)
DLAP: A Deep Learning Augmented Large Language Model Prompting Framework for Software Vulnerability Detection
von: Yang, Yanjing, et al.
Veröffentlicht: (2024)
von: Yang, Yanjing, et al.
Veröffentlicht: (2024)
HALURust: Exploiting Hallucinations of Large Language Models to Detect Vulnerabilities in Rust
von: Luo, Yu, et al.
Veröffentlicht: (2025)
von: Luo, Yu, et al.
Veröffentlicht: (2025)
A Ground-Truth-Based Evaluation of Vulnerability Detection Across Multiple Ecosystems
von: Mandl, Peter, et al.
Veröffentlicht: (2026)
von: Mandl, Peter, et al.
Veröffentlicht: (2026)
Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects
von: Schott, Stefan, et al.
Veröffentlicht: (2025)
von: Schott, Stefan, et al.
Veröffentlicht: (2025)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
von: Yang, Guan-Yan, et al.
Veröffentlicht: (2025)
von: Yang, Guan-Yan, et al.
Veröffentlicht: (2025)
Harnessing Large Language Models for Software Vulnerability Detection: A Comprehensive Benchmarking Study
von: Tamberg, Karl, et al.
Veröffentlicht: (2024)
von: Tamberg, Karl, et al.
Veröffentlicht: (2024)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
von: Han, Junxiao, et al.
Veröffentlicht: (2025)
von: Han, Junxiao, et al.
Veröffentlicht: (2025)
SCALE: Constructing Structured Natural Language Comment Trees for Software Vulnerability Detection
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
Triggering and Detecting Exploitable Library Vulnerability from the Client by Directed Greybox Fuzzing
von: Zhao, Yukai, et al.
Veröffentlicht: (2026)
von: Zhao, Yukai, et al.
Veröffentlicht: (2026)
Ähnliche Einträge
-
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
von: Ferenc, Rudolf, et al.
Veröffentlicht: (2024) -
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
von: Xia, Yifan, et al.
Veröffentlicht: (2023) -
PatchFuzz: Patch Fuzzing for JavaScript Engines
von: Wang, Junjie, et al.
Veröffentlicht: (2025) -
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
von: Moreno, José Miguel, et al.
Veröffentlicht: (2024) -
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
von: Zhou, Dongchao, et al.
Veröffentlicht: (2025)