TaL2V: Combining LLM With Binary Taint Analysis for Vulnerability Detection
Yu Dong, Bing Xia, Chongjun Tang, Shihao Chu, Yong J. Wang, Chunhai Li, Yong Ding, Wenbo Liu
Zhongyuan University of Technology Guilin University of Electronic Technology
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
With the continuous advancement of binary code analysis technology, traditional taint analysis methods face multiple challenges, especially in the case of missing symbol information, which leads to a significant decrease in the efficiency and accuracy of vulnerability detection. To address this problem, this paper proposes an innovative vulnerability detection method, Taint with LLM to Vulnerability (TaL2V), which recovers binary code semantics through function‐name prediction and optimizes the LLM reasoning process by combining the concept of a chain to achieve automated taint propagation path tracking and vulnerability verification. The experimental results show that TaL2V outperforms existing binary taint analysis methods (e.g., LATTE and Emtaint) in terms of accuracy and F1 score. Although the detection accuracy of TaL2V is slightly lower for some complex vulnerability types (e.g., CWE‐190 and CWE‐606), it performs well in binary file analysis without symbolic information, with strong robustness and wide application potential. The successful detection of 131 vulnerabilities in real firmware shows that the method can greatly help analysts identify and fix vulnerabilities.
逐年被引趋势
暂无年度引用数据
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIAdvanced Malware Detection Techniques
Web Application Security Vulnerabilities · Software Testing and Debugging Techniques
参考文献 20
此处列出前 3 条