7 papers
ThreatLens: Evidence-Guided Ranking of High-Priority CVEs
Soroush Motamedi Sedeh, Panteha Shahrivar, Malaika Qureshi +2
Security teams must prioritize vulnerabilities before exploitation evidence is complete. Existing signals, such as CVSS, EPSS, advisories, and public exploits, are useful but fragm…
IntelliAudit: Using Large Language Models to Evaluate Audit Controls
Allison Wilson, Sina Moradi Sabet, Diar Shakimov +4
IT audits require auditors to judge whether heterogeneous organizational evidence satisfies semantic security and compliance controls. This judgment is difficult to automate becaus…
CleverCatch: A Knowledge-Guided Weak Supervision Model for Fraud Detection
Amirhossein Mozafari, Kourosh Hashemi, Erfan Shafagh +3
Healthcare fraud detection remains a critical challenge due to limited availability of labeled data, constantly evolving fraud tactics, and the high dimensionality of medical recor…
DEPTEX: Organization-First, Open Source Dependency Risk Monitoring
Henry Ruckman-Utting, Vrushal Nedungadi, Taiga Okuma +3
Open-source software (OSS) dependencies introduce systemic risks that are difficult to manage at scale. Existing Software Composition Analysis (SCA) and reachability tools generate…
PrediQL: Automated Testing of GraphQL APIs with LLMs
Shaolun Liu, Sina Marefat, Omar Tsai +4
GraphQL's flexible query model and nested data dependencies expose APIs to complex, context-dependent vulnerabilities that are difficult to uncover using conventional testing tools…
ZeroFalse: Improving Precision in Static Analysis with LLMs
Mohsen Iranmanesh, Sina Moradi Sabet, Sina Marefat +4
Static Application Security Testing (SAST) tools are integral to modern software development, yet their adoption is undermined by excessive false positives that weaken developer tr…