static analysis 2code behavior graphs 1code security 1cross-language analysis 1dynamic analysis 1large language models 1llm reasoning 1malicious npm packages 1program representation 1supply chain security 1vulnerability detection 1
From the 2 of 3 linked papers with an AI index.
3 papers
cs.SE2026
ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dynamic Analysis Synergy
Yiheng Huang, Zhijia Zhao, Bihuan Chen +6
The paper presents ProfMalPlus, a system that detects malicious NPM packages by combining object-sensitive behavior graphs with coordinated large language model reasoning over stat…
cs.SE2026
VulWeaver: Weaving Broken Semantics for Grounded Vulnerability Detection
Yiheng Cao, Yihao Chen, Xin Hu +9
VulWeaver is an LLM‑driven system that improves source‑code vulnerability detection by combining deterministic static analysis with LLM‑based semantic inference to build a unified…
cs.CR2026
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Yiheng Huang, Zhijia Zhao, Bihuan Chen +5
The model context protocol (MCP) standardizes how LLMs connect to external tools and data sources, enabling faster integration but introducing new attack vectors. Despite the growi…