,
Wang Lingxiang
,
Wenjia Song
,
Gelei Deng
,
Yi Liu
,
Dan Williams
,
Ying Zhang
Creative Commons Attribution 4.0 International license
Background. The integration of open-source libraries in Java development introduces severe security risks through vulnerable APIs. Existing program analysis and deep learning tools face challenges in capturing inter-procedural vulnerability semantics at scale. While LLMs show promise for semantic reasoning, they cannot handle large codebases due to context limits, and they lack the vulnerability-specific understanding needed to determine exploitability. Aim. This work aims to overcome these limitations and enable LLM-based detection of vulnerable API usage in large-scale Java applications. Method. We present CognixShield, an LLM-powered framework for detecting vulnerable API usage through three core components. First, semantic-preserving AST-based fragmentation partitions large codebases while maintaining syntactic completeness within LLM context windows. Second, vulnerability-aware multi-agent RAG traces relevant program context across these fragments, iteratively assembling security-critical context spanning functions and files. Third, PoV-guided semantic reasoning uses Proof-of-Vulnerability tests that encode precise triggering conditions and exploitation mechanics to determine vulnerability. Results. CognixShield achieves 84% precision, 95% recall, 84% accuracy, and an 89% F1-score on 57 real-world Java applications, outperforming state-of-the-art tools. Conclusions. Our results show that vulnerability detection requires specialized architectural innovations beyond generic LLM applications.
@InProceedings{fu_et_al:LIPIcs.ESEM.2026.1,
author = {Fu, Quanzhi and Lingxiang, Wang and Song, Wenjia and Deng, Gelei and Liu, Yi and Williams, Dan and Zhang, Ying},
title = {{CognixShield: PoV-Guided Vulnerable API Usage Detection in Large Codebases via LLMs}},
booktitle = {20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)},
pages = {1:1--1:21},
series = {Leibniz International Proceedings in Informatics (LIPIcs)},
ISBN = {978-3-95977-450-5},
ISSN = {1868-8969},
year = {2026},
volume = {394},
editor = {Feldt, Robert and Paasivaara, Maria and Mendez, Daniel and Wagner, Stefan and Bar\'{o}n, Marvin Mu\~{n}oz},
publisher = {Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
address = {Dagstuhl, Germany},
URL = {https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ESEM.2026.1},
URN = {urn:nbn:de:0030-drops-279698},
doi = {10.4230/LIPIcs.ESEM.2026.1},
annote = {Keywords: Vulnerable API usage detection, program analysis, LLMs, agentic RAG}
}