arXiv:cs.LG· Jugal Gajjar·· 5 小时前AI 评分40
Verify Before You Fix:面向可信跨语言代码分析的智能体执行验证框架
Verify Before You Fix: Agentic Execution Grounding for Trustworthy Cross-Language Code Analysis
AI 导读
研究者提出一套跨语言漏洞生命周期框架,通过混合结构-语义检测、执行验证的智能体确认与验证感知迭代修复三阶段,并遵循"未经执行确认可利用性就不修复"的不变量。
正文
Abstract:Learned classifiers deployed in agentic pipelines face a fundamental reliability problem: predictions are probabilistic inferences, not verified conclusions, and acting on them without grounding in observable evidence leads to compounding failures across downstream stages. Software vulnerability analysis makes this cost concrete and measurable. We address this through a unified cross-language vulnerability lifecycle framework built around three LLM-driven reasoning stages-hybrid structural-semantic detection, execution-grounded agentic validation, and validation-aware iterative repair-governed by a strict invariant: no repair action is taken without execution-based confirmation of exploitability. Cross-language generalization is achieved via a Universal Abstract Syntax Tree (uAST) normalizing Java, Python, and C++ into a shared structural schema, combined with a hybrid fusion of GraphSAGE and Qwen2.5-Coder-1.5B embeddings through learned two-way gating, whose per-sample weights provide intrinsic explainability at no additional cost. The framework achieves 89.84-92.02% intra-language detection accuracy and 74.43-80.12% zero-shot cross-language F1, resolving 69.74% of vulnerabilities end-to-end at a 12.27% total failure rate. Ablations establish necessity: removing uAST degrades cross-language F1 by 23.42%, while disabling validation increases unnecessary repairs by 131.7%. These results demonstrate that execution-grounded closed-loop reasoning is a principled and practically deployable mechanism for trustworthy LLM-driven agentic AI.
| Comments: | 20 pages (13 main + 7 appendices), 9 figures, 10 tables |
| Subjects: | Software Engineering (cs.SE); Artificial Intelligence (cs.AI); Cryptography and Security (cs.CR); Machine Learning (cs.LG); Programming Languages (cs.PL) |
| Cite as: | arXiv:2604.10800 [cs.SE] |
| (or arXiv:2604.10800v2 [cs.SE] for this version) | |
| https://doi.org/10.48550/arXiv.2604.10800 arXiv-issued DOI via DataCite |
Submission history
From: Jugal Gajjar [view email]
[v1]
Sun, 12 Apr 2026 20:22:23 UTC (5,914 KB)
[v2]
Fri, 2 Oct 2026 14:35:57 UTC (5,915 KB)
来源:arXiv:cs.LG · arxiv.org