YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group
Fuente:
arXiv
Saved in:
| Main Authors: | Wang, Yayi, Wang, Shenao, Zhao, Jian, Shi, Shaosen, Li, Ting, Cheng, Yan, Bian, Lizhong, Yu, Kan, Zhao, Yanjie, Wang, Haoyu |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware Tracing
by: Zhang, Yiyu, et al.
Published: (2024)
by: Zhang, Yiyu, et al.
Published: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026)
by: Liu, Yue, et al.
Published: (2026)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
Harnessing the Power of LLM to Support Binary Taint Analysis
by: Liu, Puzhuo, et al.
Published: (2023)
by: Liu, Puzhuo, et al.
Published: (2023)
MiniScope: Automated UI Exploration and Privacy Inconsistency Detection of MiniApps via Two-phase Iterative Hybrid Analysis
by: Wang, Shenao, et al.
Published: (2024)
by: Wang, Shenao, et al.
Published: (2024)
Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
CKGFuzzer: LLM-Based Fuzz Driver Generation Enhanced By Code Knowledge Graph
by: Xu, Hanxiang, et al.
Published: (2024)
by: Xu, Hanxiang, et al.
Published: (2024)
SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain
by: Wang, Shenao, et al.
Published: (2025)
by: Wang, Shenao, et al.
Published: (2025)
Multi-Agent Taint Specification Extraction for Vulnerability Detection
by: Ghebremichael, Jonah, et al.
Published: (2026)
by: Ghebremichael, Jonah, et al.
Published: (2026)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
by: Xiang, Jiahui, et al.
Published: (2024)
by: Xiang, Jiahui, et al.
Published: (2024)
Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app Ecosystems
by: Zhang, Miao, et al.
Published: (2025)
by: Zhang, Miao, et al.
Published: (2025)
Seeing is (Not) Believing: Practical Phishing Attacks Targeting Social Media Sharing Cards
by: Huang, Wangchenlu, et al.
Published: (2024)
by: Huang, Wangchenlu, et al.
Published: (2024)
ZTaint-Havoc: From Havoc Mode to Zero-Execution Fuzzing-Driven Taint Inference
by: Xie, Yuchong, et al.
Published: (2025)
by: Xie, Yuchong, et al.
Published: (2025)
Dynamic Taint Tracking using Partial Instrumentation for Java Applications
by: Thakur, Manoj RameshChandra
Published: (2024)
by: Thakur, Manoj RameshChandra
Published: (2024)
Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
by: Pan, Shidong, et al.
Published: (2024)
by: Pan, Shidong, et al.
Published: (2024)
Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-Procedural Path-Sensitive Taint Analysis
by: Ji, Yuchen, et al.
Published: (2025)
by: Ji, Yuchen, et al.
Published: (2025)
AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality Apps
by: Kim, John Y., et al.
Published: (2025)
by: Kim, John Y., et al.
Published: (2025)
SMCP: Secure Model Context Protocol
by: Hou, Xinyi, et al.
Published: (2026)
by: Hou, Xinyi, et al.
Published: (2026)
Taint Analysis for Graph APIs Focusing on Broken Access Control
by: Lambers, Leen, et al.
Published: (2025)
by: Lambers, Leen, et al.
Published: (2025)
Learning to Triage Taint Flows Reported by Dynamic Program Analysis in Node.js Packages
by: Ni, Ronghao, et al.
Published: (2025)
by: Ni, Ronghao, et al.
Published: (2025)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
by: Ni, Ronghao, et al.
Published: (2026)
by: Ni, Ronghao, et al.
Published: (2026)
SeeWasm: An Efficient and Fully-Functional Symbolic Execution Engine for WebAssembly Binaries
by: He, Ningyu, et al.
Published: (2024)
by: He, Ningyu, et al.
Published: (2024)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
by: Nie, Yuqing, et al.
Published: (2024)
by: Nie, Yuqing, et al.
Published: (2024)
Detecting Data Poisoning in Code Generation LLMs via Black-Box, Vulnerability-Oriented Scanning
by: Yan, Shenao, et al.
Published: (2026)
by: Yan, Shenao, et al.
Published: (2026)
An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection
by: Yan, Shenao, et al.
Published: (2024)
by: Yan, Shenao, et al.
Published: (2024)
KVerus: Scalable and Resilient Formal Verification Proof Generation for Rust Code
by: Liu, Yuwei, et al.
Published: (2026)
by: Liu, Yuwei, et al.
Published: (2026)
Beyond Fidelity: Explaining Vulnerability Localization of Learning-based Detectors
by: Cheng, Baijun, et al.
Published: (2024)
by: Cheng, Baijun, et al.
Published: (2024)
LeakGuard: Detecting Memory Leaks Accurately and Scalably
by: Liang, Hongliang, et al.
Published: (2025)
by: Liang, Hongliang, et al.
Published: (2025)
Execution-State-Aware LLM Reasoning for Automated Proof-of-Vulnerability Generation
by: Li, Haoyu, et al.
Published: (2026)
by: Li, Haoyu, et al.
Published: (2026)
Directed Greybox Fuzzing via Large Language Model
by: Xu, Hanxiang, et al.
Published: (2025)
by: Xu, Hanxiang, et al.
Published: (2025)
SCAFFOLD-CEGIS: Preventing Latent Security Degradation in LLM-Driven Iterative Code Refinement
by: Chen, Yi, et al.
Published: (2026)
by: Chen, Yi, et al.
Published: (2026)
Scheduzz: Constraint-based Fuzz Driver Generation with Dual Scheduling
by: Li, Yan, et al.
Published: (2025)
by: Li, Yan, et al.
Published: (2025)
SCRUTINEER: Detecting Logic-Level Usage Violations of Reusable Components in Smart Contracts
by: Lin, Xingshuang, et al.
Published: (2025)
by: Lin, Xingshuang, et al.
Published: (2025)
Large Language Models for Cyber Security: A Systematic Literature Review
by: Xu, Hanxiang, et al.
Published: (2024)
by: Xu, Hanxiang, et al.
Published: (2024)
Similar Items
-
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026) -
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024) -
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024) -
HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware Tracing
by: Zhang, Yiyu, et al.
Published: (2024) -
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)