R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
Fuente:
arXiv
Saved in:
| Main Authors: | Lu, Tianhe, Spero, Eric, Jayasundara, Sakuna Harinda, Biddle, Robert, Russello, Giovanni |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
RAGent: Retrieval-based Access Control Policy Generation
by: Jayasundara, Sakuna Harinda, et al.
Published: (2024)
by: Jayasundara, Sakuna Harinda, et al.
Published: (2024)
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023)
by: Mousavi, Zahra, et al.
Published: (2023)
Generating API Parameter Security Rules with LLM for API Misuse Detection
by: Liu, Jinghua, et al.
Published: (2024)
by: Liu, Jinghua, et al.
Published: (2024)
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
by: Firouzi, Ehsan, et al.
Published: (2024)
by: Firouzi, Ehsan, et al.
Published: (2024)
An Investigation into Misuse of Java Security APIs by Large Language Models
by: Mousavi, Zahra, et al.
Published: (2024)
by: Mousavi, Zahra, et al.
Published: (2024)
Mutation-based Evaluation of Cryptographic API Misuse Detectors
by: Ami, Amit Seal, et al.
Published: (2021)
by: Ami, Amit Seal, et al.
Published: (2021)
Security Testing of RESTful APIs With Test Case Mutation
by: Salva, Sebastien, et al.
Published: (2024)
by: Salva, Sebastien, et al.
Published: (2024)
R+R: Security Vulnerability Dataset Quality Is Critical
by: Yadav, Anurag Swarnim, et al.
Published: (2025)
by: Yadav, Anurag Swarnim, et al.
Published: (2025)
When Security Meets Usability: An Empirical Investigation of Post-Quantum Cryptography APIs
by: Toruan, Marthin, et al.
Published: (2026)
by: Toruan, Marthin, et al.
Published: (2026)
Give LLMs a Security Course: Securing Retrieval-Augmented Code Generation via Knowledge Injection
by: Lin, Bo, et al.
Published: (2025)
by: Lin, Bo, et al.
Published: (2025)
GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
by: Tsai, Omar, et al.
Published: (2025)
by: Tsai, Omar, et al.
Published: (2025)
Evaluating Cryptographic API Misuse Detectors for Go
by: Andersson, Vivi, et al.
Published: (2026)
by: Andersson, Vivi, et al.
Published: (2026)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
PrediQL: Automated Testing of GraphQL APIs with LLMs
by: Liu, Shaolun, et al.
Published: (2025)
by: Liu, Shaolun, et al.
Published: (2025)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
LLMs for Cyber Security: New Opportunities
by: Divakaran, Dinil Mon, et al.
Published: (2024)
by: Divakaran, Dinil Mon, et al.
Published: (2024)
LLMs + Security = Trouble
by: Livshits, Benjamin
Published: (2026)
by: Livshits, Benjamin
Published: (2026)
Using LLMs for Security Advisory Investigations: How Far Are We?
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
Towards Secure Logging: Characterizing and Benchmarking Logging Code Security Issues with LLMs
by: Yuan, He Yang, et al.
Published: (2026)
by: Yuan, He Yang, et al.
Published: (2026)
Managing Security Evidence in Safety-Critical Organizations
by: Mohamad, Mazen, et al.
Published: (2024)
by: Mohamad, Mazen, et al.
Published: (2024)
FLAMES: Fine-tuning LLMs to Synthesize Invariants for Smart Contract Security
by: Eshghie, Mojtaba, et al.
Published: (2025)
by: Eshghie, Mojtaba, et al.
Published: (2025)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
by: Han, Junxiao, et al.
Published: (2025)
by: Han, Junxiao, et al.
Published: (2025)
Security study based on the Chatgptplugin system: ldentifying Security Vulnerabilities
by: Ren, Ruomai
Published: (2025)
by: Ren, Ruomai
Published: (2025)
Leveraging Security Observability to Strengthen Security of Digital Ecosystem Architecture
by: Ramachandran, Renjith
Published: (2024)
by: Ramachandran, Renjith
Published: (2024)
VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs
by: Castiglione, Gianpietro, et al.
Published: (2026)
by: Castiglione, Gianpietro, et al.
Published: (2026)
Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation
by: Lin, Bo, et al.
Published: (2025)
by: Lin, Bo, et al.
Published: (2025)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
by: Seth, Aishwarya, et al.
Published: (2023)
by: Seth, Aishwarya, et al.
Published: (2023)
Security Incentivization: An Empirical Study of how Micropayments Impact Code Security
by: Rass, Stefan, et al.
Published: (2026)
by: Rass, Stefan, et al.
Published: (2026)
Software Security Analysis in 2030 and Beyond: A Research Roadmap
by: Böhme, Marcel, et al.
Published: (2024)
by: Böhme, Marcel, et al.
Published: (2024)
Symmaries: Automatic Inference of Formal Security Summaries for Java Programs
by: Khakpour, Narges, et al.
Published: (2025)
by: Khakpour, Narges, et al.
Published: (2025)
VulInstruct: Teaching LLMs Root-Cause Reasoning for Vulnerability Detection via Security Specifications
by: Zhu, Hao, et al.
Published: (2025)
by: Zhu, Hao, et al.
Published: (2025)
Civil Servants as Builders: Enabling Non-IT Staff to Develop Secure Python and R Tools
by: Sharma, Prashant
Published: (2025)
by: Sharma, Prashant
Published: (2025)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
How Secure is Secure Code Generation? Adversarial Prompts Put LLM Defenses to the Test
by: Tessa, Melissa, et al.
Published: (2026)
by: Tessa, Melissa, et al.
Published: (2026)
ProSec: Fortifying Code LLMs with Proactive Security Alignment
by: Xu, Xiangzhe, et al.
Published: (2024)
by: Xu, Xiangzhe, et al.
Published: (2024)
Evaluating and Improving the Robustness of Security Attack Detectors Generated by LLMs
by: Pasini, Samuele, et al.
Published: (2024)
by: Pasini, Samuele, et al.
Published: (2024)
Numeric Truncation Security Predicate
by: Mezhuev, Timofey, et al.
Published: (2023)
by: Mezhuev, Timofey, et al.
Published: (2023)
LLM Security Guard for Code
by: Kavian, Arya, et al.
Published: (2024)
by: Kavian, Arya, et al.
Published: (2024)
An Introduction to Adaptive Software Security
by: Nia, Mehran Alidoost
Published: (2023)
by: Nia, Mehran Alidoost
Published: (2023)
Similar Items
-
RAGent: Retrieval-based Access Control Policy Generation
by: Jayasundara, Sakuna Harinda, et al.
Published: (2024) -
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023) -
Generating API Parameter Security Rules with LLM for API Misuse Detection
by: Liu, Jinghua, et al.
Published: (2024) -
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
by: Firouzi, Ehsan, et al.
Published: (2024) -
An Investigation into Misuse of Java Security APIs by Large Language Models
by: Mousavi, Zahra, et al.
Published: (2024)