arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CLEAR:基于因果上下文的智能体推理漏洞检测

CLEAR: Causal Context-Based Agentic Reasoning for Vulnerability Detection

Sungju Yun, Sijune Hwang, Yeonjoon Lee, Kyungtae Kang, Sungbin Park

arXiv 2608.03134首次发表:更新:

发表机构

Hanyang University(汉阳大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对现有漏洞检测方法无法捕捉漏洞复杂因果依赖的问题,提出CLEAR多智能体框架,通过构建VCKG并结合四类智能体协同推理,在C/C++和Java基准上性能显著优于现有最优方法。

AI 中文摘要

随着现代安全漏洞根植于执行流、控制条件和程序状态之间的复杂因果依赖关系,检测源代码漏洞的难度日益增大。尽管大型语言模型(LLMs)和多智能体框架近期取得了进展,但现有方法主要关注良性函数与漏洞函数之间的表面相似性,未能捕捉安全漏洞固有的复杂因果依赖关系。为解决这些局限,我们提出了基于因果上下文的智能体推理框架CLEAR,该框架集成了因果知识图谱。CLEAR系统构建了漏洞因果知识图谱(VCKG),对漏洞实例中入口点、前提条件、根本原因和修复意图之间的因果链进行建模。借助该结构化知识,包括收集器、声明者、批评者和判定者在内的四个专业智能体通过检索到的因果上下文协同验证漏洞假设。在C/C++和Java漏洞基准上的实验结果表明,CLEAR相较于现有最优方法,将配对正确率(P-C)性能分别提升了130.7%和71.56%,证明了因果知识图谱引导的自动漏洞检测推理的有效性。

英文摘要

Detecting source code vulnerabilities is increasingly difficult as modern security flaws are rooted in complex causal dependencies between execution flows, control conditions, and program states. Despite recent advances in Large Language Models (LLMs) and multi-agent frameworks, existing approaches primarily address superficial similarities between benign and vulnerable functions while failing to capture the complex causal dependencies inherent in security flaws. To address these limitations, we propose Causal Context-based Agentic Reasoning (CLEAR), a novel multi-agent vulnerability detection framework integrated with a causal knowledge graph. CLEAR systematically constructs a Vulnerability Causal Knowledge Graph (VCKG) that models the causal chains between entrypoints, preconditions, root causes, and fix intents across vulnerability instances. Leveraging this structured knowledge, four specialized agents, including the Collector, Claim, Critic, and Judge, collaboratively verify vulnerability hypotheses through retrieved causal contexts. Experimental results on C/C++ and Java vulnerability benchmarks demonstrate that CLEAR improves Pair-Correct (P-C) performance by 130.7% and 71.56% over state-of-the-art approaches, demonstrating the effectiveness of causal knowledge graph-guided reasoning for automated vulnerability detection.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑