Reframing Paths as Logic: Semantic Segmentation for Vulnerability Detection
Path-sensitive vulnerabilities, such as use-after-free, integer overflows, and command injection, pose significant challenges for traditional static analysis tools, which often face trade-offs between precision, scalability, and interpretability. To address these challenges, we present SEVDF (Semantic-Enhanced Vulnerability Detection Framework), a novel methodology that integrates may-analysis taint propagation with large language models (LLMs) to detect path-related vulnerabilities in large C/C++ codebases. SEVDF begins by constructing a program dependency graph and performing a sound but incomplete taint analysis to extract all potential vulnerable paths. After segmentation, deduplication, feasibility check, and semantic summarization by LLMs, the vulnerable paths are reformed and confirmed with LLMs for their inter-procedural feasibility and semantic consistency.
We evaluate SEVDF on the Juliet Test Suite (thirteen representative CWE categories) and a curated real-world dataset of 71 vulnerabilities across 9 projects. SEVDF consistently outperforms the default CodeQL rules, CodeQL rules with all unnecessary constraints removed, and three open-source detectors, which are Infer, Cppcheck and CodeChecker. SEVDF is able to achieve 100% precision on several CWEs while maintaining or improving recall on Juliet benchmark. Moreover, our segment-based design reduces the analysis workload for LLMs by 90.6% compared to direct-path prompting through Logic Unit deduplication, making SEVDF cost-effective for large-scale deployment. Finally, SEVDF uncovered and reported 29 0-day vulnerabilities (12 confirmed to date), including 3 CVEs in VirtualBox, demonstrating practical value.
Mon 5 OctDisplayed time zone: Pacific Time (US & Canada) change
10:30 - 12:00 | LLM Agents for Program AnalysisOOPSLA at East Hall 2 Chair(s): Yun Lin Shanghai Jiao Tong University | ||
10:30 18mTalk | Process-Centric Analysis of Agentic Software Systems OOPSLA Shuyang Liu University of Illinois at Urbana-Champaign, Yang Chen University of Illinois at Urbana-Champaign, Rahul Krishna IBM Research, Saurabh Sinha IBM Research, Jatin Ganhotra IBM, Reyhaneh Jabbarvand University of Illinois at Urbana-Champaign DOI | ||
10:48 18mTalk | MetaSpace: Metamorphic Testing for Spatial Cognition in Embodied Agents OOPSLA Gengyang Xu Hong Kong University of Science and Technology, Dongwei Xiao Hong Kong University of Science and Technology, Yiteng Peng Hong Kong University of Science and Technology, Shuai Wang Hong Kong University of Science and Technology DOI | ||
11:06 18mTalk | Reframing Paths as Logic: Semantic Segmentation for Vulnerability Detection OOPSLA Zong Cao Imperial Global Singapore; Nanyang Technological University, Yuqiang Sun Nanyang Technological University, Zhengzi Xu Imperial Global Singapore, Kaixuan Li Nanyang Technological University, Yeqi Fu National University of Singapore, Yiran Zhang Nanyang Technological University, Ziqiao Kong Nanyang Technological University, Yang Liu Nanyang Technological University DOI | ||
11:24 18mTalk | Agent-Based Automated Remediation for Vulnerabilities in Maven Projects OOPSLA Lyuye Zhang Nankai University; Nanyang Technological University, He Ye University College London, Federica Sarro University College London, Yuqiang Sun Nanyang Technological University, Yang Liu Nanyang Technological University DOI | ||
11:42 18mTalk | LLM-Based Alarm Resolution Guided by Bayesian Program Analysis OOPSLA Yifan Zhang Peking University, Yuanfeng Shi Peking University, Haoran Lin Peking University, Yingfei Xiong Ministry of Education; Peking University; Zhongguancun Laboratory, Xin Zhang Peking University DOI | ||