
It shows -guided constraint reasoning decisively beating fuzzing at vulnerability validation, and that a locally-run model is enough to do it — no frontier API bill required.
“POVGEN successfully generates PoVs for 78.98% of vulnerabilities in a recent benchmark, outperforming fuzzing (up to 50.20%) and symbolic execution (2.45%).”
“The fine-tuned open-weight models match frontier commercial LLMs on key sub-tasks (i.e., the core constraint-reasoning steps) while running locally at no per-sample API cost.”
“Applying the generated PoVs revealed six flawed patches in disclosed CVEs (all subsequently fixed) and five previously unreported vulnerabilities (of which four have been confirmed and fixed by the developers).”
articleGraph Is the Verifier: Agentic Reinforcement Learning for Interprocedural Vulnerability DetectionYikun Li, Ting Zhang, Jiakun Liu, Jinfeng Jiang, Yuheng Yieh, Yixin Yang, Wen Bin Leow, Yide Yin, Yintong Huo, Eng Lieh Ouh, Lwin Khin Shar, David Lo
articleAutomated Vulnerability Injection in Smart Contracts Using Large Language ModelsLuca Migliaccio, Roberto Natella, Naghmeh Ivaki, Nuno Laranjeiro, Marco Vieira
articleLLMVul: A Vulnerability-Labeled Dataset of LLM-Generated C/C++ Functions from Real Production RepositoriesMohammad Farhad, Shuvalaxmi DassChecking sign-in…
Loading comments…