arrow
Return

Enhancing static vulnerability alert validation using large language models

delete2026-08-03
delete0
PRE
AI
S
Sheng-Shan Chen
Y
Yi-Sheng Hsu
T
Tien-Chih Lin
C
C. Chen
C
Chin‐Yu Sun *
DOI:10.1016/j.jss.2026.113040delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
• A hybrid framework combining SAST, CPG, and LLM for vulnerability validation. • Utilizes CPG as a structural anchor to ground LLM reasoning for higher accuracy. • Reduces false-positive SAST alerts through evidence-grounded LLM adjudication.

Journal

Journal of Systems and Software cover
Journal of Systems and Software
IF:
4.1
Papers:
5.4K
Citations:
8.4K

Organization

N
National Taipei University of Technology
Scholars:
7.1K
Papers: 7.3K
Citations: 6.8K
C
cycraft technology
Scholars:
5
Papers: 3
Citations: 0