{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:3OVK6ICU34ZRNADZ25SSMQIUD2","short_pith_number":"pith:3OVK6ICU","schema_version":"1.0","canonical_sha256":"dbaaaf2054df33168079d7652641141eb7788ed14bbf0185a87280fada155bf6","source":{"kind":"arxiv","id":"2405.17238","version":3},"attestation_state":"computed","paper":{"title":"IRIS: LLM-Assisted Static Analysis for Detecting Security Vulnerabilities","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.PL","cs.SE"],"primary_cat":"cs.CR","authors_text":"Mayur Naik, Saikat Dutta, Ziyang Li","submitted_at":"2024-05-27T14:53:35Z","abstract_excerpt":"Software is prone to security vulnerabilities. Program analysis tools to detect them have limited effectiveness in practice due to their reliance on human labeled specifications. Large language models (or LLMs) have shown impressive code generation capabilities but they cannot do complex reasoning over code to detect such vulnerabilities especially since this task requires whole-repository analysis. We propose IRIS, a neuro-symbolic approach that systematically combines LLMs with static analysis to perform whole-repository reasoning for security vulnerability detection. Specifically, IRIS leve"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.17238","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2024-05-27T14:53:35Z","cross_cats_sorted":["cs.PL","cs.SE"],"title_canon_sha256":"ef60290e5f2e8cbcb58588ee1115e393acfcd67fa1cba9de2291e834710fde25","abstract_canon_sha256":"aa14091c5fb1846699a16d5f07e38618c5a77c5fb1b3706e1275591c742a3f7c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:45:08.536258Z","signature_b64":"iepiGW7iZDShyrrhkXQpmu+Twaxzvgl+4BgtQ9dMEdP5Z0VaE/1SGynRZvGf/Hn6vygNm+Y9dCRl95MRu1BlAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dbaaaf2054df33168079d7652641141eb7788ed14bbf0185a87280fada155bf6","last_reissued_at":"2026-07-05T10:45:08.535787Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:45:08.535787Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"IRIS: LLM-Assisted Static Analysis for Detecting Security Vulnerabilities","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.PL","cs.SE"],"primary_cat":"cs.CR","authors_text":"Mayur Naik, Saikat Dutta, Ziyang Li","submitted_at":"2024-05-27T14:53:35Z","abstract_excerpt":"Software is prone to security vulnerabilities. Program analysis tools to detect them have limited effectiveness in practice due to their reliance on human labeled specifications. Large language models (or LLMs) have shown impressive code generation capabilities but they cannot do complex reasoning over code to detect such vulnerabilities especially since this task requires whole-repository analysis. We propose IRIS, a neuro-symbolic approach that systematically combines LLMs with static analysis to perform whole-repository reasoning for security vulnerability detection. Specifically, IRIS leve"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.17238","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.17238/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.17238","created_at":"2026-07-05T10:45:08.535842+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.17238v3","created_at":"2026-07-05T10:45:08.535842+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.17238","created_at":"2026-07-05T10:45:08.535842+00:00"},{"alias_kind":"pith_short_12","alias_value":"3OVK6ICU34ZR","created_at":"2026-07-05T10:45:08.535842+00:00"},{"alias_kind":"pith_short_16","alias_value":"3OVK6ICU34ZRNADZ","created_at":"2026-07-05T10:45:08.535842+00:00"},{"alias_kind":"pith_short_8","alias_value":"3OVK6ICU","created_at":"2026-07-05T10:45:08.535842+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":22,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.18619","citing_title":"Code-Augur: Agentic Vulnerability Detection via Specification Inference","ref_index":50,"is_internal_anchor":false},{"citing_arxiv_id":"2606.31368","citing_title":"MOA: A Profiling-Guided LLM Framework for Memory-Optimization Automation at Codebase Scale","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2605.30604","citing_title":"An Organization-Scoped LLM Agent Runtime Architecture for Regulated Cybersecurity Operations","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2606.00669","citing_title":"NeuroLog: Reasoning You Can Audit -- Neuro-Symbolic Vulnerability Discovery via LLM Facts, Datalog, and SMT","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2505.13766","citing_title":"A Blueprint for AI-Driven Software Quality: Integrating LLMs with Established Standards","ref_index":160,"is_internal_anchor":false},{"citing_arxiv_id":"2601.22655","citing_title":"Do Fine-Tuned LLMs Understand Vulnerabilities? An Investigation into the Semantic Trap","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21779","citing_title":"FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18153","citing_title":"Three Heads Are Better Than One: A Multi-perspective Reasoning Framework for Enhanced Vulnerability Detection","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2605.14859","citing_title":"Do Coding Agents Understand Least-Privilege Authorization?","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2509.11787","citing_title":"CodeCureAgent: Automatic Classification and Repair of Static Analysis Warnings","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2605.15097","citing_title":"Veritas: Grounding LLM Agents for Reliable Vulnerability Reasoning over Stripped Binaries","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2603.27224","citing_title":"Finding Memory Leaks in C/C++ Programs via Neuro-Symbolic Augmented Static Analysis","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2604.27000","citing_title":"Adaptive and AI-Augmented Security Testing: A Systematic Survey of Program Analysis, Feedback-Driven Testing, and Hybrid Learning-Based Approaches","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09304","citing_title":"Generating Complex Code Analyzers from Natural Language Questions","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05424","citing_title":"Evaluating the Reliability of Multiple Large Language Models in Risk Assessment: A CIS Controls Based Approach","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01892","citing_title":"CyberAId: AI-Driven Cybersecurity for Financial Service Providers","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00314","citing_title":"Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12220","citing_title":"Learning Project-wise Subsequent Code Edits via Interleaving Neural-based Induction and Tool-based Deduction","ref_index":69,"is_internal_anchor":false},{"citing_arxiv_id":"2604.10767","citing_title":"VulWeaver: Weaving Broken Semantics for Grounded Vulnerability Detection","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11950","citing_title":"AnyPoC: Universal Proof-of-Concept Test Generation for Scalable LLM-Based Bug Detection","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07900","citing_title":"Longitudinal Analyses of SAST Tools: A CodeQL Case Study","ref_index":41,"is_internal_anchor":false},{"citing_arxiv_id":"2604.19049","citing_title":"Refute-or-Promote: An Adversarial Stage-Gated Multi-Agent Review Methodology for High-Precision LLM-Assisted Defect Discovery","ref_index":17,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2","json":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2.json","graph_json":"https://pith.science/api/pith-number/3OVK6ICU34ZRNADZ25SSMQIUD2/graph.json","events_json":"https://pith.science/api/pith-number/3OVK6ICU34ZRNADZ25SSMQIUD2/events.json","paper":"https://pith.science/paper/3OVK6ICU"},"agent_actions":{"view_html":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2","download_json":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2.json","view_paper":"https://pith.science/paper/3OVK6ICU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.17238&json=true","fetch_graph":"https://pith.science/api/pith-number/3OVK6ICU34ZRNADZ25SSMQIUD2/graph.json","fetch_events":"https://pith.science/api/pith-number/3OVK6ICU34ZRNADZ25SSMQIUD2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2/action/storage_attestation","attest_author":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2/action/author_attestation","sign_citation":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2/action/citation_signature","submit_replication":"https://pith.science/pith/3OVK6ICU34ZRNADZ25SSMQIUD2/action/replication_record"}},"created_at":"2026-07-05T10:45:08.535842+00:00","updated_at":"2026-07-05T10:45:08.535842+00:00"}