{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:BAPGYIHSSUM45TELGKORR3F7PT","short_pith_number":"pith:BAPGYIHS","schema_version":"1.0","canonical_sha256":"081e6c20f29519cecc8b329d18ecbf7cd11b8a996e9b89fc86bfe9985f8f0cbe","source":{"kind":"arxiv","id":"2506.16899","version":2},"attestation_state":"computed","paper":{"title":"Towards Effective Complementary Security Analysis using Large Language Models","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Andreas Both, Christian N\\\"ather, Jan-Philipp Stegh\\\"ofer, Jonas Wagner, Simon M\\\"uller","submitted_at":"2025-06-20T10:46:35Z","abstract_excerpt":"A key challenge in security analysis is the manual evaluation of potential security weaknesses generated by static application security testing (SAST) tools. Numerous false positives (FPs) in these reports reduce the effectiveness of security analysis. We propose using Large Language Models (LLMs) to improve the assessment of SAST findings. We investigate the ability of LLMs to reduce FPs while trying to maintain a perfect true positive rate, using datasets extracted from the OWASP Benchmark (v1.2) and a real-world software project. Our results indicate that advanced prompting techniques, such"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.16899","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2025-06-20T10:46:35Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"1325d34b01a4d420666dd9975f85ddc938c0109fb7661bf14996153a890ee907","abstract_canon_sha256":"8b4b9fe6462c8f405d1e96a79bf207f1d138849fae8928ed3e90adbe303a25c7"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:36:33.315532Z","signature_b64":"PSlecX6vJNChIpD3DrTS3zmonRjEQKT2EwOnMUwHSEYflY0iqpwSxvGTEWFxTPzw/tSVXkzAUBmd8QMxS3H2BQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"081e6c20f29519cecc8b329d18ecbf7cd11b8a996e9b89fc86bfe9985f8f0cbe","last_reissued_at":"2026-07-05T11:36:33.314987Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:36:33.314987Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Towards Effective Complementary Security Analysis using Large Language Models","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Andreas Both, Christian N\\\"ather, Jan-Philipp Stegh\\\"ofer, Jonas Wagner, Simon M\\\"uller","submitted_at":"2025-06-20T10:46:35Z","abstract_excerpt":"A key challenge in security analysis is the manual evaluation of potential security weaknesses generated by static application security testing (SAST) tools. Numerous false positives (FPs) in these reports reduce the effectiveness of security analysis. We propose using Large Language Models (LLMs) to improve the assessment of SAST findings. We investigate the ability of LLMs to reduce FPs while trying to maintain a perfect true positive rate, using datasets extracted from the OWASP Benchmark (v1.2) and a real-world software project. Our results indicate that advanced prompting techniques, such"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.16899","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.16899/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.16899","created_at":"2026-07-05T11:36:33.315054+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.16899v2","created_at":"2026-07-05T11:36:33.315054+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.16899","created_at":"2026-07-05T11:36:33.315054+00:00"},{"alias_kind":"pith_short_12","alias_value":"BAPGYIHSSUM4","created_at":"2026-07-05T11:36:33.315054+00:00"},{"alias_kind":"pith_short_16","alias_value":"BAPGYIHSSUM45TEL","created_at":"2026-07-05T11:36:33.315054+00:00"},{"alias_kind":"pith_short_8","alias_value":"BAPGYIHS","created_at":"2026-07-05T11:36:33.315054+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT","json":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT.json","graph_json":"https://pith.science/api/pith-number/BAPGYIHSSUM45TELGKORR3F7PT/graph.json","events_json":"https://pith.science/api/pith-number/BAPGYIHSSUM45TELGKORR3F7PT/events.json","paper":"https://pith.science/paper/BAPGYIHS"},"agent_actions":{"view_html":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT","download_json":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT.json","view_paper":"https://pith.science/paper/BAPGYIHS","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.16899&json=true","fetch_graph":"https://pith.science/api/pith-number/BAPGYIHSSUM45TELGKORR3F7PT/graph.json","fetch_events":"https://pith.science/api/pith-number/BAPGYIHSSUM45TELGKORR3F7PT/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT/action/storage_attestation","attest_author":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT/action/author_attestation","sign_citation":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT/action/citation_signature","submit_replication":"https://pith.science/pith/BAPGYIHSSUM45TELGKORR3F7PT/action/replication_record"}},"created_at":"2026-07-05T11:36:33.315054+00:00","updated_at":"2026-07-05T11:36:33.315054+00:00"}