PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Liu, Xiting, Liu, Yuetong, Zhang, Yitong, Li, Jia, Hu, Shi-Min |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
von: Liu, Shuhan, et al.
Veröffentlicht: (2025)
von: Liu, Shuhan, et al.
Veröffentlicht: (2025)
An Analysis of Malicious Packages in Open-Source Software in the Wild
von: Zhou, Xiaoyan, et al.
Veröffentlicht: (2024)
von: Zhou, Xiaoyan, et al.
Veröffentlicht: (2024)
AgentGuard: A Multi-Agent Framework for Robust Package Confusion Detection via Hybrid Search and Metadata-Content Fusion
von: Li, Yu, et al.
Veröffentlicht: (2026)
von: Li, Yu, et al.
Veröffentlicht: (2026)
Zero-Shot Vulnerability Detection in Low-Resource Smart Contracts Through Solidity-Only Training
von: Hu, Minghao, et al.
Veröffentlicht: (2026)
von: Hu, Minghao, et al.
Veröffentlicht: (2026)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
von: Guo, Wenbo, et al.
Veröffentlicht: (2026)
von: Guo, Wenbo, et al.
Veröffentlicht: (2026)
HighGuard: Cross-Chain Business Logic Monitoring of Smart Contracts
von: Eshghie, Mojtaba, et al.
Veröffentlicht: (2023)
von: Eshghie, Mojtaba, et al.
Veröffentlicht: (2023)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
von: Guo, Wenbo, et al.
Veröffentlicht: (2026)
von: Guo, Wenbo, et al.
Veröffentlicht: (2026)
Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
von: Nie, Yuqing, et al.
Veröffentlicht: (2024)
von: Nie, Yuqing, et al.
Veröffentlicht: (2024)
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
von: Rosso, Martin, et al.
Veröffentlicht: (2025)
von: Rosso, Martin, et al.
Veröffentlicht: (2025)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
von: Zhou, Xiaoyan, et al.
Veröffentlicht: (2024)
von: Zhou, Xiaoyan, et al.
Veröffentlicht: (2024)
zkCraft: Prompt-Guided LLM as a Zero-Shot Mutation Pattern Oracle for TCCT-Powered ZK Fuzzing
von: Fu, Rong, et al.
Veröffentlicht: (2026)
von: Fu, Rong, et al.
Veröffentlicht: (2026)
Tactics, Techniques, and Procedures (TTPs) in Interpreted Malware: A Zero-Shot Generation with Large Language Models
von: Zhang, Ying, et al.
Veröffentlicht: (2024)
von: Zhang, Ying, et al.
Veröffentlicht: (2024)
Semantic Consensus Decoding: Backdoor Defense for Verilog Code Generation
von: Yang, Guang, et al.
Veröffentlicht: (2026)
von: Yang, Guang, et al.
Veröffentlicht: (2026)
Securing the Software Package Supply Chain for Critical Systems
von: Murali, Ritwik, et al.
Veröffentlicht: (2025)
von: Murali, Ritwik, et al.
Veröffentlicht: (2025)
A Static Analysis of Popular C Packages in Linux
von: Ruohonen, Jukka, et al.
Veröffentlicht: (2024)
von: Ruohonen, Jukka, et al.
Veröffentlicht: (2024)
HALURust: Exploiting Hallucinations of Large Language Models to Detect Vulnerabilities in Rust
von: Luo, Yu, et al.
Veröffentlicht: (2025)
von: Luo, Yu, et al.
Veröffentlicht: (2025)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
von: Toda, Takaaki, et al.
Veröffentlicht: (2026)
von: Toda, Takaaki, et al.
Veröffentlicht: (2026)
Designing Robust API Monitoring Solutions
von: D'Elia, Daniele Cono, et al.
Veröffentlicht: (2020)
von: D'Elia, Daniele Cono, et al.
Veröffentlicht: (2020)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
von: Reyes, Frank, et al.
Veröffentlicht: (2024)
von: Reyes, Frank, et al.
Veröffentlicht: (2024)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
von: Pohl, Timo, et al.
Veröffentlicht: (2025)
von: Pohl, Timo, et al.
Veröffentlicht: (2025)
PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages
von: Simsek, Deniz, et al.
Veröffentlicht: (2025)
von: Simsek, Deniz, et al.
Veröffentlicht: (2025)
LLM-enabled Applications Require System-Level Threat Monitoring
von: Zhang, Yedi, et al.
Veröffentlicht: (2026)
von: Zhang, Yedi, et al.
Veröffentlicht: (2026)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
von: Schorlemmer, Taylor R, et al.
Veröffentlicht: (2024)
von: Schorlemmer, Taylor R, et al.
Veröffentlicht: (2024)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
von: Ruohonen, Jukka, et al.
Veröffentlicht: (2025)
von: Ruohonen, Jukka, et al.
Veröffentlicht: (2025)
Basic Legibility Protocols Improve Trusted Monitoring
von: Sreevatsa, Ashwin, et al.
Veröffentlicht: (2026)
von: Sreevatsa, Ashwin, et al.
Veröffentlicht: (2026)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
von: Rahman, Imranur, et al.
Veröffentlicht: (2024)
von: Rahman, Imranur, et al.
Veröffentlicht: (2024)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
von: Swierzy, Ben, et al.
Veröffentlicht: (2025)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
von: Jiang, Wenxin, et al.
Veröffentlicht: (2025)
von: Jiang, Wenxin, et al.
Veröffentlicht: (2025)
Hackers or Hallucinators? A Comprehensive Analysis of LLM-Based Automated Penetration Testing
von: Peng, Jiaren, et al.
Veröffentlicht: (2026)
von: Peng, Jiaren, et al.
Veröffentlicht: (2026)
We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
von: Spracklen, Joseph, et al.
Veröffentlicht: (2024)
von: Spracklen, Joseph, et al.
Veröffentlicht: (2024)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
von: Zhang, Junan, et al.
Veröffentlicht: (2023)
von: Zhang, Junan, et al.
Veröffentlicht: (2023)
VulInstruct: Teaching LLMs Root-Cause Reasoning for Vulnerability Detection via Security Specifications
von: Zhu, Hao, et al.
Veröffentlicht: (2025)
von: Zhu, Hao, et al.
Veröffentlicht: (2025)
Learning to Triage Taint Flows Reported by Dynamic Program Analysis in Node.js Packages
von: Ni, Ronghao, et al.
Veröffentlicht: (2025)
von: Ni, Ronghao, et al.
Veröffentlicht: (2025)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
von: Ryan, Ahmed, et al.
Veröffentlicht: (2026)
von: Ryan, Ahmed, et al.
Veröffentlicht: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
von: Mehedi, Sk Tanzir, et al.
Veröffentlicht: (2025)
von: Mehedi, Sk Tanzir, et al.
Veröffentlicht: (2025)
ZTaint-Havoc: From Havoc Mode to Zero-Execution Fuzzing-Driven Taint Inference
von: Xie, Yuchong, et al.
Veröffentlicht: (2025)
von: Xie, Yuchong, et al.
Veröffentlicht: (2025)
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection
von: Weng, Shihao, et al.
Veröffentlicht: (2026)
von: Weng, Shihao, et al.
Veröffentlicht: (2026)
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
von: Wen, Xin-Cheng, et al.
Veröffentlicht: (2024)
Smart Contract Fuzzing Towards Profitable Vulnerabilities
von: Kong, Ziqiao, et al.
Veröffentlicht: (2025)
von: Kong, Ziqiao, et al.
Veröffentlicht: (2025)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
von: Ni, Ronghao, et al.
Veröffentlicht: (2026)
von: Ni, Ronghao, et al.
Veröffentlicht: (2026)
Ähnliche Einträge
-
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
von: Liu, Shuhan, et al.
Veröffentlicht: (2025) -
An Analysis of Malicious Packages in Open-Source Software in the Wild
von: Zhou, Xiaoyan, et al.
Veröffentlicht: (2024) -
AgentGuard: A Multi-Agent Framework for Robust Package Confusion Detection via Hybrid Search and Metadata-Content Fusion
von: Li, Yu, et al.
Veröffentlicht: (2026) -
Zero-Shot Vulnerability Detection in Low-Resource Smart Contracts Through Solidity-Only Training
von: Hu, Minghao, et al.
Veröffentlicht: (2026) -
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
von: Guo, Wenbo, et al.
Veröffentlicht: (2026)