Search Results

Documents authored by Deng, Gelei


Document
Technical Track Paper
CognixShield: PoV-Guided Vulnerable API Usage Detection in Large Codebases via LLMs

Authors: Quanzhi Fu, Wang Lingxiang, Wenjia Song, Gelei Deng, Yi Liu, Dan Williams, and Ying Zhang

Published in: LIPIcs, Volume 394, 20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)


Abstract
Background. The integration of open-source libraries in Java development introduces severe security risks through vulnerable APIs. Existing program analysis and deep learning tools face challenges in capturing inter-procedural vulnerability semantics at scale. While LLMs show promise for semantic reasoning, they cannot handle large codebases due to context limits, and they lack the vulnerability-specific understanding needed to determine exploitability. Aim. This work aims to overcome these limitations and enable LLM-based detection of vulnerable API usage in large-scale Java applications. Method. We present CognixShield, an LLM-powered framework for detecting vulnerable API usage through three core components. First, semantic-preserving AST-based fragmentation partitions large codebases while maintaining syntactic completeness within LLM context windows. Second, vulnerability-aware multi-agent RAG traces relevant program context across these fragments, iteratively assembling security-critical context spanning functions and files. Third, PoV-guided semantic reasoning uses Proof-of-Vulnerability tests that encode precise triggering conditions and exploitation mechanics to determine vulnerability. Results. CognixShield achieves 84% precision, 95% recall, 84% accuracy, and an 89% F1-score on 57 real-world Java applications, outperforming state-of-the-art tools. Conclusions. Our results show that vulnerability detection requires specialized architectural innovations beyond generic LLM applications.

Cite as

Quanzhi Fu, Wang Lingxiang, Wenjia Song, Gelei Deng, Yi Liu, Dan Williams, and Ying Zhang. CognixShield: PoV-Guided Vulnerable API Usage Detection in Large Codebases via LLMs. In 20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 394, pp. 1:1-1:21, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{fu_et_al:LIPIcs.ESEM.2026.1,
  author =	{Fu, Quanzhi and Lingxiang, Wang and Song, Wenjia and Deng, Gelei and Liu, Yi and Williams, Dan and Zhang, Ying},
  title =	{{CognixShield: PoV-Guided Vulnerable API Usage Detection in Large Codebases via LLMs}},
  booktitle =	{20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)},
  pages =	{1:1--1:21},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-450-5},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{394},
  editor =	{Feldt, Robert and Paasivaara, Maria and Mendez, Daniel and Wagner, Stefan and Bar\'{o}n, Marvin Mu\~{n}oz},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ESEM.2026.1},
  URN =		{urn:nbn:de:0030-drops-279698},
  doi =		{10.4230/LIPIcs.ESEM.2026.1},
  annote =	{Keywords: Vulnerable API usage detection, program analysis, LLMs, agentic RAG}
}

Any Issues?
X

Feedback on the Current Page

CAPTCHA

Thanks for your feedback!

Feedback submitted to Dagstuhl Publishing

Could not send message

Please try again later or send an E-mail