Fetching the paper…
Reading the bibliography…
In this work, we present MoCQ, a neuro-symbolic static analysis framework that leverages large language models (LLMs) to automatically generate vulnerability detection patterns.
Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints. In
Patrick Cousot and Radhia Cousot. 1977 · 1977
Earlier work this paper cites.
Backus-naur form (bnf)
Daniel D McCracken and Edwin D Reilly. 2003 · 2003
Earlier work this paper cites.
Using model checking to find serious file system errors
Junfeng Yang, Paul Twohey, Dawson Engler, and Madanlal Musuvathi. 2006 · 2006
Earlier work this paper cites.
Automatic detection and correction of web application vulnerabilities using data mining to predict false positives. In
Ibéria Medeiros, Nuno F. Neves, and Miguel Correia. 2011 · 2011
Earlier work this paper cites.
The definitive ANTLR 4 reference
Terence Parr. 2013 · 2013
Earlier work this paper cites.
Static detection of
Johannes Dahse and Thorsten Holz. 2014 · 2014
Earlier work this paper cites.
Modeling and discovering vulnerabilities with code property graphs. In
Fabian Yamaguchi, Nico Golde, Daniel Arp, and Konrad Rieck. 2014 · 2014
Earlier work this paper cites.
Formal verification methods
Osman Hasan and Sofiene Tahar. 2015 · 2015
Earlier work this paper cites.
On fast large-scale program analysis in datalog. In
Bernhard Scholz, Herbert Jordan, Pavle Subotić, and Till Westmann. 2016 · 2016
Earlier work this paper cites.
SVF: interprocedural static value-flow analysis in LLVM. In
Yulei Sui and Jingling Xue. 2016 · 2016
Earlier work this paper cites.
Efficient and flexible discovery of php application vulnerabilities. In
Michael Backes, Konrad Rieck, Malte Skoruppa, Ben Stock, and Fabian Yamaguchi. 2017 · 2017
Earlier work this paper cites.
Using static symbolic execution to detect buffer overflows
IA Dudina and AA Belevantsev. 2017 · 2017
Earlier work this paper cites.
Directed greybox fuzzing. In
Marcel Pham, Van Thuan, Manh Dung Nguyen, and Abhik Roychoudhury. 2017 · 2017
Earlier work this paper cites.
A survey of symbolic execution techniques
Roberto Baldoni, Emilio Coppa, Daniele Cono D’elia, Camil Demetrescu, and Irene Finocchi. 2018 · 2018
Earlier work this paper cites.
Automated vulnerability detection in source code using deep representation learning. In
Rebecca Russell, Louis Kim, Lei Hamilton, Tomo Lazovich, Jacob Harer, Onur Ozdemir, Paul Ellingwood, and Marc McConley. 2018 · 2018
Earlier work this paper cites.
Spatio-temporal context reduction: A pointer-analysis-based static approach for detecting use-after-free vulnerabilities. In
Hua Yan, Yulei Sui, Shiping Chen, and Jingling Xue. 2018 · 2018
Earlier work this paper cites.
CodeBERT: A Pre-Trained Model for Programming and Natural Languages. In
Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, Daxin Jiang, and Ming Zhou. 2020 · 2020
Earlier work this paper cites.
Deep learning based vulnerability detection: Are we there yet?
Saikat Chakraborty, Rahul Krishna, Yangruibo Ding, and Baishakhi Ray. 2021 · 2021
Earlier work this paper cites.
Constraint-guided directed greybox fuzzing. In
Gwangmu Lee, Woochul Shim, and Byoungyoung Lee. 2021 · 2021
Earlier work this paper cites.
LChecker: Detecting Loose Comparison Bugs in PHP. In
Penghui Li and Wei Meng. 2021 · 2021
Earlier work this paper cites.
Sysevr: A framework for using deep learning to detect software vulnerabilities
Zhen Li, Deqing Zou, Shouhuai Xu, Hai Jin, Yawei Zhu, and Zhaoxuan Chen. 2021b · 2021
Cited alongside, same era.
Model-checking support for file system development. In
Wei Su, Yifei Liu, Gomathi Ganesan, Gerard Holzmann, Scott Smolka, Erez Zadok, and Geoff Kuenning. 2021 · 2021
Cited alongside, same era.
CodeT5: Identifier-aware Unified Pre-trained Encoder-Decoder Models for Code Understanding and Generation. In
Yue Wang, Weishi Wang, Shafiq R. Joty, and Steven C. H. Hoi. 2021 · 2021
Cited alongside, same era.
Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites.. In
Zifeng Kang, Song Li, and Yinzhi Cao. 2022 · 2022
Cited alongside, same era.
TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP Applications. In
Changhua Luo, Penghui Li, and Wei Meng. 2022 · 2022
Cited alongside, same era.
Effectiveness of ChatGPT for Static Analysis: How Far Are We?. In
Mohammad Mahdi Mohajer, Reem Aleithan, Nima Shiri Harzevili, Moshi Wei, Alvine Boaye Belle, Hung Viet Pham, and Song Wang. 2024 · 2024
Later among the works it cites.
CodeQL 2.16.3 Change Log
N/A. 2024 · 2024
Later among the works it cites.
RecurScan: Detecting Recurring Vulnerabilities in PHP Web Applications. In
Youkun Shi, Yuan Zhang, Tianhao Bai, Lei Zhang, Xin Tan, and Min Yang. 2024 · 2024
Later among the works it cites.
A systematic literature review on automated software vulnerability detection using machine learning
Nima Shiri Harzevili, Alvine Boaye Belle, Junjie Wang, Song Wang, Zhen Ming Jiang, and Nachiappan Nagappan. 2024 · 2024
Later among the works it cites.
LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and Benchmarks. In
Saad Ullah, Mingji Han, Saurabh Pujar, Hammond Pearce, Ayse K. Coskun, and Gianluca Stringhini. 2024 · 2024
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Joern for Prototype Pollution
2023 · 2023
Cited alongside, same era.
CONCORD: Clone-Aware Contrastive Learning for Source Code. In
Yangruibo Ding, Saikat Chakraborty, Luca Buratti, Saurabh Pujar, Alessandro Morari, Gail Kaiser, and Baishakhi Ray. 2023 · 2023
Cited alongside, same era.
Detection of Prototype Pollution Using Joern: Joern’s Detection Capability Compared to CodeQL’s
Tobias Fröberg. 2023 · 2023
Cited alongside, same era.
Silent spring: Prototype pollution leads to remote code execution in Node. js. In
Mikhail Shcherbakov, Musard Balliu, and Cristian-Alexandru Staicu. 2023 · 2023
Cited alongside, same era.
Code Llama: Open Foundation Models for Code
Hugo Touvron, Louis Martin, Kevin Stone, Peter Albert, Amjad Almahairi, Yasmine El Hage, Baptiste Roziere, Jie Ren, Laurent Sifre, Jean-Rémi King, Thomas Scialom, Gabriel Synnaeve, Nicolas Usunier, Hervé Jégou, and Edouard Grave. 2023 · 2023
Cited alongside, same era.
Toss a fault to your witcher: Applying grey-box coverage-guided mutational fuzzing to detect sql and command injection vulnerabilities. In
Erik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel, Giovanni Vigna, Christopher Kruegel, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, and Adam Doupé. 2023 · 2023
Cited alongside, same era.
CodeQL 2.14.2 Change Log
2024 · 2024
Cited alongside, same era.
LLMSA: A Compositional Neuro-Symbolic Approach to Compilation-free and Customizable Static Analysis. In
Chengpeng Wang, Yifei Gao, Wuqi Zhang, Xuwei Liu, Qingkai Shi, and Xiangyu Zhang. 2024a · 2024
Later among the works it cites.
SCL-CVD: Supervised contrastive learning for code vulnerability detection via GraphCodeBERT
Rongcun Wang, Senlei Xu, Yuan Tian, Xingyu Ji, Xiaobing Sun, and Shujuang Jiang. 2024b · 2024
Later among the works it cites.
Large language model for vulnerability detection: Emerging results and future directions. In
Xin Zhou, Ting Zhang, and David Lo. 2024 · 2024
Later among the works it cites.
Detecting Source Code Vulnerabilities Using Fine-Tuned Pre-Trained LLMs. In
Jin Zhu, Hui Ge, Yun Zhou, Xiao Jin, Rui Luo, and Yanchen Sun. 2024 · 2024
Later among the works it cites.
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs
2025 · 2025
Closest in time.
Vulnerability detection with code language models: How far are we?. In
Yangruibo Ding, Yanjun Fu, Omniyyah Ibrahim, Chawin Sitawarin, Xinyun Chen, Basel Alomair, David Wagner, Baishakhi Ray, and Yizheng Chen. 2025 · 2025
Closest in time.
Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-Procedural Path-Sensitive Taint Analysis. In
Yuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang, and Jingzhu He. 2025 · 2025
Closest in time.
LLMxCPG: Context-Aware vulnerability detection through code property Graph-Guided large language models. In
Ahmed Lekssays, Hamza Mouhcine, Khang Tran, Ting Yu, and Issa Khalil. 2025 · 2025
Closest in time.
Llm-assisted static analysis for detecting security vulnerabilities. In
Ziyang Li, Saikat Dutta, and Mayur Naik. 2025 · 2025
Closest in time.
CVE-2021-44228: Apache Log4j2 Remote Code Execution Vulnerability
MITRE Corporation. 2021 · 2025
Closest in time.
GPT-4o Technical Report
OpenAI. 2024 · 2025
Closest in time.
CodeQL Support in Chromium
The Chromium Project. 2025 · 2025
Closest in time.
Log4Shell: RCE Vulnerability in Log4j (CVE-2021-44228)
Apache Logging Services. 2021 · 2025
Closest in time.
Amazon CodeGuru
Amazon Web Services. 2025 · 2025
Closest in time.
Knighter: Transforming static analysis with llm-synthesized checkers. In
Chenyuan Yang, Zijie Zhao, Zichen Xie, Haoyu Li, and Lingming Zhang. 2025 · 2025
Closest in time.