QASecClaw: A Multi-Agent LLM Approach for False Positive Reduction in Static Application Security Testing
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Ameen, Mohd Ruhul, Alam, Md Takrim Ul, Islam, Akif |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Prompt Control-Flow Integrity: A Priority-Aware Runtime Defense Against Prompt Injection in LLM Systems
von: Alam, Md Takrim Ul, et al.
Veröffentlicht: (2026)
von: Alam, Md Takrim Ul, et al.
Veröffentlicht: (2026)
LLM-Driven Adaptive Source-Sink Identification and False Positive Mitigation for Static Analysis
von: Lin, Shiyin
Veröffentlicht: (2025)
von: Lin, Shiyin
Veröffentlicht: (2025)
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
von: Ami, Amit Seal, et al.
Veröffentlicht: (2023)
von: Ami, Amit Seal, et al.
Veröffentlicht: (2023)
FuzzSlice: Pruning False Positives in Static Analysis Warnings Through Function-Level Fuzzing
von: Murali, Aniruddhan, et al.
Veröffentlicht: (2024)
von: Murali, Aniruddhan, et al.
Veröffentlicht: (2024)
A Multi-Agent LLM Defense Pipeline Against Prompt Injection Attacks
von: Hossain, S M Asif, et al.
Veröffentlicht: (2025)
von: Hossain, S M Asif, et al.
Veröffentlicht: (2025)
An Extensive Comparison of Static Application Security Testing Tools
von: Esposito, Matteo, et al.
Veröffentlicht: (2024)
von: Esposito, Matteo, et al.
Veröffentlicht: (2024)
How Code Representation Shapes False-Positive Dynamics in Cross-Language LLM Vulnerability Detection
von: Chen, Maofei, et al.
Veröffentlicht: (2026)
von: Chen, Maofei, et al.
Veröffentlicht: (2026)
SecureFixAgent: A Hybrid LLM Agent for Automated Python Static Vulnerability Repair
von: Gajjar, Jugal, et al.
Veröffentlicht: (2025)
von: Gajjar, Jugal, et al.
Veröffentlicht: (2025)
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
von: Dong, Ben, et al.
Veröffentlicht: (2026)
von: Dong, Ben, et al.
Veröffentlicht: (2026)
How Secure is Secure Code Generation? Adversarial Prompts Put LLM Defenses to the Test
von: Tessa, Melissa, et al.
Veröffentlicht: (2026)
von: Tessa, Melissa, et al.
Veröffentlicht: (2026)
IRIS: LLM-Assisted Static Analysis for Detecting Security Vulnerabilities
von: Li, Ziyang, et al.
Veröffentlicht: (2024)
von: Li, Ziyang, et al.
Veröffentlicht: (2024)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
von: Marquer, Yoann, et al.
Veröffentlicht: (2026)
von: Marquer, Yoann, et al.
Veröffentlicht: (2026)
Verbatim Data Transcription Failures in LLM Code Generation: A State-Tracking Stress Test
von: Haque, Mohd Ariful, et al.
Veröffentlicht: (2026)
von: Haque, Mohd Ariful, et al.
Veröffentlicht: (2026)
SmartShift: A Secure and Efficient Approach to Smart Contract Migration
von: Hossain, Tahrim, et al.
Veröffentlicht: (2025)
von: Hossain, Tahrim, et al.
Veröffentlicht: (2025)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
von: Han, Junxiao, et al.
Veröffentlicht: (2025)
von: Han, Junxiao, et al.
Veröffentlicht: (2025)
UEFI Vulnerability Signature Generation using Static and Symbolic Analysis
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2024)
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2024)
Guiding Symbolic Execution with Static Analysis and LLMs for Vulnerability Discovery
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2026)
von: Shafiuzzaman, Md, et al.
Veröffentlicht: (2026)
Toward an Android Static Analysis Approach for Data Protection
von: Khedkar, Mugdha, et al.
Veröffentlicht: (2024)
von: Khedkar, Mugdha, et al.
Veröffentlicht: (2024)
Security Testing of RESTful APIs With Test Case Mutation
von: Salva, Sebastien, et al.
Veröffentlicht: (2024)
von: Salva, Sebastien, et al.
Veröffentlicht: (2024)
What Makes a Good LLM Agent for Real-world Penetration Testing?
von: Deng, Gelei, et al.
Veröffentlicht: (2026)
von: Deng, Gelei, et al.
Veröffentlicht: (2026)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
von: Cusick, James J.
Veröffentlicht: (2025)
von: Cusick, James J.
Veröffentlicht: (2025)
Many Tools, Few Exploitable Vulnerabilities: A Survey of 246 Static Code Analyzers for Security
von: Hermann, Kevin, et al.
Veröffentlicht: (2026)
von: Hermann, Kevin, et al.
Veröffentlicht: (2026)
LLM Security Guard for Code
von: Kavian, Arya, et al.
Veröffentlicht: (2024)
von: Kavian, Arya, et al.
Veröffentlicht: (2024)
DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
von: Ma, Chengyan, et al.
Veröffentlicht: (2025)
von: Ma, Chengyan, et al.
Veröffentlicht: (2025)
Who Tests the Testers? Systematic Enumeration and Coverage Audit of LLM Agent Tool Call Safety
von: Chen, Xuan, et al.
Veröffentlicht: (2026)
von: Chen, Xuan, et al.
Veröffentlicht: (2026)
CrossInspector: A Static Analysis Approach for Cross-Contract Vulnerability Detection
von: Chen, Xiao
Veröffentlicht: (2024)
von: Chen, Xiao
Veröffentlicht: (2024)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
von: Seth, Aishwarya, et al.
Veröffentlicht: (2023)
von: Seth, Aishwarya, et al.
Veröffentlicht: (2023)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
von: Cheng, Yiran, et al.
Veröffentlicht: (2024)
von: Cheng, Yiran, et al.
Veröffentlicht: (2024)
Argus: Reorchestrating Static Analysis via a Multi-Agent Ensemble for Full-Chain Security Vulnerability Detection
von: Liang, Zi, et al.
Veröffentlicht: (2026)
von: Liang, Zi, et al.
Veröffentlicht: (2026)
Detecting Misuse of Security APIs: A Systematic Review
von: Mousavi, Zahra, et al.
Veröffentlicht: (2023)
von: Mousavi, Zahra, et al.
Veröffentlicht: (2023)
ClawWorm: Self-Propagating Attacks Across LLM Agent Ecosystems
von: Zhang, Yihao, et al.
Veröffentlicht: (2026)
von: Zhang, Yihao, et al.
Veröffentlicht: (2026)
A Survey of Web Application Security Tutorials
von: Chembakottu, Bhagya, et al.
Veröffentlicht: (2026)
von: Chembakottu, Bhagya, et al.
Veröffentlicht: (2026)
AIM: Automated Input Set Minimization for Metamorphic Security Testing
von: Chaleshtari, Nazanin Bayati, et al.
Veröffentlicht: (2024)
von: Chaleshtari, Nazanin Bayati, et al.
Veröffentlicht: (2024)
QLCoder: A Query Synthesizer For Static Analysis of Security Vulnerabilities
von: Wang, Claire, et al.
Veröffentlicht: (2025)
von: Wang, Claire, et al.
Veröffentlicht: (2025)
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
von: Kanchi, Shravya, et al.
Veröffentlicht: (2026)
von: Kanchi, Shravya, et al.
Veröffentlicht: (2026)
An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code
von: Elsayed, Mohamed, et al.
Veröffentlicht: (2026)
von: Elsayed, Mohamed, et al.
Veröffentlicht: (2026)
SkillProbe: Security Auditing for Emerging Agent Skill Marketplaces via Multi-Agent Collaboration
von: Guo, Zihan, et al.
Veröffentlicht: (2026)
von: Guo, Zihan, et al.
Veröffentlicht: (2026)
GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
von: Tsai, Omar, et al.
Veröffentlicht: (2025)
von: Tsai, Omar, et al.
Veröffentlicht: (2025)
How to Compare the Security of Code Written by Humans to LLM-generated Code
von: Balebako, Rebecca, et al.
Veröffentlicht: (2026)
von: Balebako, Rebecca, et al.
Veröffentlicht: (2026)
Generating API Parameter Security Rules with LLM for API Misuse Detection
von: Liu, Jinghua, et al.
Veröffentlicht: (2024)
von: Liu, Jinghua, et al.
Veröffentlicht: (2024)
Ähnliche Einträge
-
Prompt Control-Flow Integrity: A Priority-Aware Runtime Defense Against Prompt Injection in LLM Systems
von: Alam, Md Takrim Ul, et al.
Veröffentlicht: (2026) -
LLM-Driven Adaptive Source-Sink Identification and False Positive Mitigation for Static Analysis
von: Lin, Shiyin
Veröffentlicht: (2025) -
"False negative -- that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security Testing
von: Ami, Amit Seal, et al.
Veröffentlicht: (2023) -
FuzzSlice: Pruning False Positives in Static Analysis Warnings Through Function-Level Fuzzing
von: Murali, Aniruddhan, et al.
Veröffentlicht: (2024) -
A Multi-Agent LLM Defense Pipeline Against Prompt Injection Attacks
von: Hossain, S M Asif, et al.
Veröffentlicht: (2025)