13 papers
VeriPort: Automated and Verified Patch Backporting at Scale
Jonah Ghebremichael, Wenxin Jiang, Mikola Lysenko +3
One of the key challenges for securing the software supply chain is addressing known vulnerabilities in third-party open-source dependencies. Security patches are frequently only a…
S3C2 Summit 2025-09: Industry Secure Supply Chain Summit
Md Atiqur Rahman, Yasemin Acar, Michel Cucker +5
Today's digital ecosystem relies heavily on software supply chains, which enable developers to reuse code and ship software at scale. However, a single vulnerable component can jeo…
S3C2 Summit 2025-07: Government Secure Supply Chain Summit
Sivana Hamer, Pat Morrison, William Enck +6
Software supply chains, while providing immense economic and software development value, are only as strong as their weakest link. Over the past several years, there has been an ex…
WAAA! Web Adversaries Against Agentic Browsers
Sohom Datta, Alex Nahapetyan, William Enck +1
Large language models (LLMs) are increasingly being integrated into web browsers to create agentic browsing systems that execute actions on behalf of the user. Prior work consideri…
Multi-Agent Taint Specification Extraction for Vulnerability Detection
Jonah Ghebremichael, Saastha Vasan, Saad Ullah +6
Static Application Security Testing (SAST) tools using taint analysis are widely viewed as providing higher-quality vulnerability detection results compared to traditional pattern-…
Towards Verifiably Safe Tool Use for LLM Agents
Aarya Doshi, Yining Hong, Congying Xu +3
Large language model (LLM)-based AI agents extend LLM capabilities by enabling access to tools such as data sources, APIs, search engines, code sandboxes, and even other agents. Wh…