Large language model (LLM)-based repository auditors are increasingly deployed as security controls within continuous integration (CI) pipelines, where their findings admit, block, or delay software changes. As Agentic Software Development Life Cycle (SDLC) Security Controls, their non-deterministic behaviour changes t...
Guy Lupo, Nguyen Hung Nguyen, V. Vo et al.· 0 citations
Agentic AI extends LLM security beyond generated content to persistent state, autonomous actions, tool use, and interactions with humans and other agents. Existing threat classifications often emphasize individual dimensions, obscuring connections among entry points, affected components, and security consequences. The...
Heewon Baek, Alsharif Abuadbba, Kristen Moore et al.· 0 citations
This survey provides a unified analysis of how LLMs amplify web vulnerabilities across client-side, server-side, and pipeline layers while evaluating defenses and their limitations, and outlines future directions for secure AI-enabled web systems.
Nivedita Singh, Alsharif Abuadbba, Yan-Song Gao et al.· 1 citation
SHAQ (shadow query generation), a semantic-decomposition and embedding-decoupling defense against EIAs, is proposed, which uses a generative language model to create diverse shadow queries that capture different semantic aspects of each document.
Xinguo Feng, Zhongkui Ma, Zi-Han Wang et al.· 0 citations
This work presents GraftyVul, a system that constructs vulnerable programs by grafting real-world vulnerabilities into open-source projects, and introduces a language- and context-agnostic semantic embedding that compares vulnerabilities by sink, mechanism and host-feature rather than surface code.
Omri Ram, Mitchell Horner, R. van der Meyden et al.· 0 citations
This work forms sector-targeted CTI dissemination as a multilabel classification problem, leveraging deep field knowledge of CTI structures and sector-specific threat patterns, and applies BERT, a transformer-based model, to automate the mapping of CTI events to sectors.
Fajar Wijitrisnanto, A. Abuadbba, Yan-Song Gao et al.· 0 citations
It is found that developers rarely raised security concerns when engaging with Copilot, and many did not recognize that their final implementations remained insecure, so future research directions to support safer AI-assisted software development are proposed.
Zahra Mousavi, Chadni Islam, M. A. Babar et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.