SPLASH 2026
Sun 4 - Fri 9 October 2026 Oakland, California, United States
co-located with SPLASH/ISSTA 2026
Mon 5 Oct 2026 11:06 - 11:24 at East Hall 2 - LLM Agents for Program Analysis Chair(s): Yun Lin

Path-sensitive vulnerabilities, such as use-after-free, integer overflows, and command injection, pose significant challenges for traditional static analysis tools, which often face trade-offs between precision, scalability, and interpretability. To address these challenges, we present SEVDF (Semantic-Enhanced Vulnerability Detection Framework), a novel methodology that integrates may-analysis taint propagation with large language models (LLMs) to detect path-related vulnerabilities in large C/C++ codebases. SEVDF begins by constructing a program dependency graph and performing a sound but incomplete taint analysis to extract all potential vulnerable paths. After segmentation, deduplication, feasibility check, and semantic summarization by LLMs, the vulnerable paths are reformed and confirmed with LLMs for their inter-procedural feasibility and semantic consistency.

We evaluate SEVDF on the Juliet Test Suite (thirteen representative CWE categories) and a curated real-world dataset of 71 vulnerabilities across 9 projects. SEVDF consistently outperforms the default CodeQL rules, CodeQL rules with all unnecessary constraints removed, and three open-source detectors, which are Infer, Cppcheck and CodeChecker. SEVDF is able to achieve 100% precision on several CWEs while maintaining or improving recall on Juliet benchmark. Moreover, our segment-based design reduces the analysis workload for LLMs by 90.6% compared to direct-path prompting through Logic Unit deduplication, making SEVDF cost-effective for large-scale deployment. Finally, SEVDF uncovered and reported 29 0-day vulnerabilities (12 confirmed to date), including 3 CVEs in VirtualBox, demonstrating practical value.

Mon 5 Oct

Displayed time zone: Pacific Time (US & Canada) change

10:30 - 12:00
LLM Agents for Program AnalysisOOPSLA at East Hall 2
Chair(s): Yun Lin Shanghai Jiao Tong University
10:30
18m
Talk
Process-Centric Analysis of Agentic Software Systems
OOPSLA
Shuyang Liu University of Illinois at Urbana-Champaign, Yang Chen University of Illinois at Urbana-Champaign, Rahul Krishna IBM Research, Saurabh Sinha IBM Research, Jatin Ganhotra IBM, Reyhaneh Jabbarvand University of Illinois at Urbana-Champaign
DOI
10:48
18m
Talk
MetaSpace: Metamorphic Testing for Spatial Cognition in Embodied Agents
OOPSLA
Gengyang Xu Hong Kong University of Science and Technology, Dongwei Xiao Hong Kong University of Science and Technology, Yiteng Peng Hong Kong University of Science and Technology, Shuai Wang Hong Kong University of Science and Technology
DOI
11:06
18m
Talk
Reframing Paths as Logic: Semantic Segmentation for Vulnerability Detection
OOPSLA
Zong Cao Imperial Global Singapore; Nanyang Technological University, Yuqiang Sun Nanyang Technological University, Zhengzi Xu Imperial Global Singapore, Kaixuan Li Nanyang Technological University, Yeqi Fu National University of Singapore, Yiran Zhang Nanyang Technological University, Ziqiao Kong Nanyang Technological University, Yang Liu Nanyang Technological University
DOI
11:24
18m
Talk
Agent-Based Automated Remediation for Vulnerabilities in Maven Projects
OOPSLA
Lyuye Zhang Nankai University; Nanyang Technological University, He Ye University College London, Federica Sarro University College London, Yuqiang Sun Nanyang Technological University, Yang Liu Nanyang Technological University
DOI
11:42
18m
Talk
LLM-Based Alarm Resolution Guided by Bayesian Program Analysis
OOPSLA
Yifan Zhang Peking University, Yuanfeng Shi Peking University, Haoran Lin Peking University, Yingfei Xiong Ministry of Education; Peking University; Zhongguancun Laboratory, Xin Zhang Peking University
DOI