works on

From the 2 of 6 linked papers with an AI index.

collaborators

6 papers

cs.SE2026

ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dynamic Analysis Synergy

Yiheng Huang, Zhijia Zhao, Bihuan Chen +6

The paper presents ProfMalPlus, a system that detects malicious NPM packages by combining object-sensitive behavior graphs with coordinated large language model reasoning over stat…

cs.SE2026

VulWeaver: Weaving Broken Semantics for Grounded Vulnerability Detection

Yiheng Cao, Yihao Chen, Xin Hu +9

VulWeaver is an LLM‑driven system that improves source‑code vulnerability detection by combining deterministic static analysis with LLM‑based semantic inference to build a unified…

cs.CR2026

Mitigating Taint-Style Vulnerabilities in MCP Servers via Security-Aware Tool Descriptions

Yang Shi, Jiaheng Fu, Yihe Huang +3

Large language models (LLMs) are increasingly deployed as autonomous agents that interact with external tools and services via the Model Context Protocol (MCP), a standardized inte…

cs.CR2026

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers

Yiheng Huang, Zhijia Zhao, Bihuan Chen +5

The model context protocol (MCP) standardizes how LLMs connect to external tools and data sources, enabling faster integration but introducing new attack vectors. Despite the growi…

cs.SE2025

Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain

Kaifeng Huang, Bihuan Chen, You Lu +7

Large language models (LLMs) have sparked significant impact with regard to both intelligence and productivity. Numerous enterprises have integrated LLMs into their applications to…

cs.CR2025

Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence

Junan Zhang, Kaifeng Huang, Yiheng Huang +4

Open-source software (OSS) supply chain enlarges the attack surface, which makes package registries attractive targets for attacks. Recently, package registries NPM and PyPI have b…