Aug 2026· Journal of Computer Virology and Hacking Techniques· Vol 22· 0 citations· 24 references
Abstract
The detection of vulnerabilities in stripped binaries remains a challenge in software security because stripping removes many of the contextual signals that both humans and automated systems use to identify and validate unsafe behavior. Detecting stack buffer overflows is particularly challenging: symbols are gone, types are absent, stack objects are poorly represented, and the decompiler output that replaces them is often noisy, incomplete, or incorrect. Prior work has applied LLMs to vulnerability analysis in binaries, but typically over decompiler output alone or with limited additional context. In this work, we take the position that the central problem is not whether an LLM can read decompiled code, but whether it can be given enough recovered program context to reason effectively about a stripped binary. We therefore introduce a static, decompiler-driven pipeline built on top of Ghidra that augments decompiled functions with binary-derived evidence including recovered stack regions, callgraph context, and p-code-derived features. This pipeline applies LLM agents in three progressively narrower stages of analysis designed to separate broad screening from expensive confirmation. We evaluate this pipeline using gpt-oss-120b [1] on a synthetic dataset compiled from a subset of NIST’s Juliet [2] dataset and stress-test the pipeline using both gpt-oss-120b and gpt-5.4 on paired vulnerable and patched real-world binaries: 12 CVE pairs published after the model’s training cutoff and 10 pre-cutoff pairs. The Juliet results show that context-augmented, staged LLM analysis can identify stack buffer overflow behavior in stripped binaries under controlled conditions. On real-world binaries, candidate generation usually surfaces the known-vulnerable target but at a high discovery burden, and final targeted reachability remains low; we therefore present the real-world evaluation as a diagnostic stress test rather than evidence of a deployable detector.
MAGE explains how externalized knowledge, bounded action, independent evaluation, and retained human authority can compose into a governed engineering environment, and proposes tests of when that environment turns commodity intelligence into durable engineering progress.
James C. Davis, Kelechi G. Kalu, Huiyun Peng et al.· 1 citation
LLMs are increasingly used for code generation, yet they frequently hallucinate non-existent software packages, creating exploitable entry points into the software supply chain. We make four contributions to this problem. First, we show that prior evaluation methodologies systematically inflate hallucination rates by misclassifying standard-library modules as hallucinations in some languages. For Python, the overestimation reaches 9.4 percentage points. Second, we evaluate seven inference-time defenses for mitigating package hallucinations, including five guided decoding strategies (Greedy, Contrastive, DoLa, Nudging, and Active Layer-Contrastive Decoding), an iterative self-refinement approach (Self-Refine), and a Retrieval-Augmented Generation (RAG)-based defense.. Across eight models spanning five families and four programming languages (Python, JavaScript, Ruby, Rust), RAG reduces the package hallucination rate (PHR) in 18 of 32 model--language configurations. Third, we introduce Package Utility (PU) to assess whether defenses preserve valid and task-relevant recommendations. Among strategies evaluated, Greedy decoding provides the strongest average mitigation--utility trade-off. Fourth, we stress-test all strategies under adversarial prompts seeded with fabricated package names and find that PHR surges by up to 45 percentage points relative to standard prompts, with Ruby consistently the most vulnerable language (80.9--95.2\%). Under adversarial conditions, RAG and Self-Refine outperform all decoding-only strategies, indicating that robust defense requires either external grounding or iterative self-verification when prompts are actively hostile. Our results recast package hallucination as both a measurement problem and a decoding-time control problem, and they demonstrate that the choice of defense must be matched to the threat model and recommendation utility.
Albérick Euraste Djiré, Iyiola E. Olatunji, Melissa Tessa et al.· 1 citation
HawkEye is introduced, a modular, web-based vulnerability auditing platform designed to streamline security analysis by integrating multiple scanning tools within a unified dashboard and illustrates how consolidated reporting improves vulnerability prioritization for development teams.
D. R. Patil, Varad Salgare, Devaj Arya et al.· International Journal for Re...· 0 citations
By streamlining workflows and fostering collaboration, this platform offers a scalable, cost- effective solution for SMEs and contributes to software engineering by demonstrating how integrated technologies can modernize development processes in resource limited contexts, with potential for broader adoption in Albania and beyond.
The findings of the present study indicated that potential complications such as delayed union, nonunion, and osteomyelitis in the intramedullary nailing method are approximately comparable to those of the external fixator method.
Reza Noktesanj, Ali Nami, F. Amani et al.· journal of Health Research a...· 0 citations
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduAug 17, 2026
A USAF cadet and a Lincoln Laboratory researcher found AI chatbots can help nontechnical service members produce viable software applications for their unique problems.