<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-10-05T21:44:55Z</responseDate>
  <request identifier="27969" metadataPrefix="oai_dc" verb="GetRecord">https://drops.dagstuhl.de/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:drops-oai.dagstuhl.de:27969</identifier>
        <datestamp>2026-10-05T06:44:02Z</datestamp>
        <setSpec>ddc:004</setSpec>
        <setSpec>open_access</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>CognixShield: PoV-Guided Vulnerable API Usage Detection in Large Codebases via LLMs</dc:title>
          <dc:creator>Fu, Quanzhi</dc:creator>
          <dc:creator>Lingxiang, Wang</dc:creator>
          <dc:creator>Song, Wenjia</dc:creator>
          <dc:creator>Deng, Gelei</dc:creator>
          <dc:creator>Liu, Yi</dc:creator>
          <dc:creator>Williams, Dan</dc:creator>
          <dc:creator>Zhang, Ying</dc:creator>
          <dc:subject>Vulnerable API usage detection</dc:subject>
          <dc:subject>program analysis</dc:subject>
          <dc:subject>LLMs</dc:subject>
          <dc:subject>agentic RAG</dc:subject>
          <dc:description>Background. The integration of open-source libraries in Java development introduces severe security risks through vulnerable APIs. Existing program analysis and deep learning tools face challenges in capturing inter-procedural vulnerability semantics at scale. While LLMs show promise for semantic reasoning, they cannot handle large codebases due to context limits, and they lack the vulnerability-specific understanding needed to determine exploitability.&#13;
&#13;
Aim. This work aims to overcome these limitations and enable LLM-based detection of vulnerable API usage in large-scale Java applications.&#13;
&#13;
Method. We present CognixShield, an LLM-powered framework for detecting vulnerable API usage through three core components. First, semantic-preserving AST-based fragmentation partitions large codebases while maintaining syntactic completeness within LLM context windows. Second, vulnerability-aware multi-agent RAG traces relevant program context across these fragments, iteratively assembling security-critical context spanning functions and files. Third, PoV-guided semantic reasoning uses Proof-of-Vulnerability tests that encode precise triggering conditions and exploitation mechanics to determine vulnerability.&#13;
&#13;
Results. CognixShield achieves 84% precision, 95% recall, 84% accuracy, and an 89% F1-score on 57 real-world Java applications, outperforming state-of-the-art tools.&#13;
&#13;
Conclusions. Our results show that vulnerability detection requires specialized architectural innovations beyond generic LLM applications.</dc:description>
          <dc:publisher>Schloss Dagstuhl – Leibniz-Zentrum für Informatik</dc:publisher>
          <dc:contributor>Quanzhi Fu and Wang Lingxiang and Wenjia Song and Gelei Deng and Yi Liu and Dan Williams and Ying Zhang</dc:contributor>
          <dc:date>2026</dc:date>
          <dc:relation>Is Part Of LIPIcs, Volume 394, 20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)</dc:relation>
          <dc:type>InProceedings</dc:type>
          <dc:type>Text</dc:type>
          <dc:type>doc-type:ResearchArticle</dc:type>
          <dc:type>publishedVersion</dc:type>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>doi:10.4230/LIPIcs.ESEM.2026.1</dc:identifier>
          <dc:identifier>urn:nbn:de:0030-drops-279698</dc:identifier>
          <dc:identifier>https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ESEM.2026.1</dc:identifier>
          <dc:language>eng</dc:language>
          <dc:rights>https://creativecommons.org/licenses/by/4.0/legalcode</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
