3 papers
cs.CR2026
Evaluating Cryptographic API Misuse Detectors for Go
Vivi Andersson, Martin Monperrus
Cryptographic API misuse represents a critical vulnerability class that undermines the security foundations of modern software. Yet, it remains largely unexplored in Go despite its…
cs.CR2025
PoCo: Agentic Proof-of-Concept Exploit Generation for Smart Contracts
Vivi Andersson, Sofia Bobadilla, Harald Hobbelhagen +1
Smart contracts operate in a highly adversarial environment, where vulnerabilities can lead to substantial financial losses. Thus, smart contracts are subject to security audits. I…
cs.CR2024
GoSurf: Identifying Software Supply Chain Attack Vectors in Go
Carmine Cesarano, Vivi Andersson, Roberto Natella +1
In Go, the widespread adoption of open-source software has led to a flourishing ecosystem of third-party dependencies, which are often integrated into critical systems. However, th…