LLMs frequently specify library versions with known CVEs in generated code (36-56% of tasks), show low compatibility (20-63%), and converge on the same risky versions across models.
Title resolution pending
5 Pith papers cite this work. Polarity classification is still indexing.
citation-role summary
citation-polarity summary
years
2026 5roles
background 3polarities
background 3representative citing papers
PoVSmith automates PoV test generation for library vulnerabilities in apps via call paths and LLM feedback, correctly identifying 96% of entry points and producing effective attack tests in 55% of 33 evaluated Java pairs.
A technique for enforcing differential privacy in temporal runtime monitoring by analyzing dependencies and injecting noise into specifications while using tree mechanisms to limit accuracy loss.
ReTokSync resolves tokenization ambiguity in generative linguistic steganography via targeted self-synchronizing resets, achieving over 99.7% extraction accuracy and 100% recovery with an auxiliary channel while matching baseline security and quality.
VPFinder integrates multi-source semantic information using multi-head attention to achieve 0.941 F1-score in vulnerability identification and 0.610 F1-score in type classification, outperforming prior approaches.
citing papers explorer
-
Correct Code, Vulnerable Dependencies: A Large Scale Measurement Study of LLM-Specified Library Versions
LLMs frequently specify library versions with known CVEs in generated code (36-56% of tasks), show low compatibility (20-63%), and converge on the same risky versions across models.
-
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
PoVSmith automates PoV test generation for library vulnerabilities in apps via call paths and LLM feedback, correctly identifying 96% of entry points and producing effective attack tests in 55% of 33 evaluated Java pairs.
-
Differentially Private Runtime Monitoring
A technique for enforcing differential privacy in temporal runtime monitoring by analyzing dependencies and injecting noise into specifications while using tree mechanisms to limit accuracy loss.
-
ReTokSync: Self-Synchronizing Tokenization Disambiguation for Generative Linguistic Steganography
ReTokSync resolves tokenization ambiguity in generative linguistic steganography via targeted self-synchronizing resets, achieving over 99.7% extraction accuracy and 100% recovery with an auxiliary channel while matching baseline security and quality.
-
Vulnerability Identification by Harnessing Inter-connected Multi-Source Information
VPFinder integrates multi-source semantic information using multi-head attention to achieve 0.941 F1-score in vulnerability identification and 0.610 F1-score in type classification, outperforming prior approaches.