漏洞报告自动化复现智能体技术
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

国家自然科学基金联合基金重点项目(U2436207)


Vulnerability Report Automated Reproduction Agent Technology
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    现有大语言模型智能体工作在自动化复现漏洞报告过程中, 面临着缺少信息源、对应用运行状态关注不足且难以适应复杂环境的技术挑战. 鉴于此, 本文提出一种漏洞报告自动化复现智能体技术VulVerifier. 该技术运用了3项关键技术: 首先, 通过综合分析漏洞描述、源码仓库及相关文档等多信息源内容来对关键信息的补全与完善; 其次, 通过自动化交互来引导目标应用逐步进入满足漏洞触发的前置状态, 从而提升复现漏洞的可行性; 最后, 在复现执行过程中动态感知异常并进行实时纠错, 从而提升对复杂环境的适应能力与复现漏洞的健壮性. 在86份真实漏洞报告上的实验结果表明, VulVerifier的复现成功率达到44.7%, 接近人类专家66.3%的水平; 相较于现有方法CVE-Genie, 额外成功复现34份漏洞报告, 并降低平均复现成本3.19美元.

    Abstract:

    Existing large language model (LLM) agent based approaches to automated vulnerability report reproduction face several technical challenges, including limited information sources, insufficient attention to application runtime states, and difficulty in adapting to complex environments. To address these issues, this study proposes VulVerifier, an agent-based technique for automated vulnerability report reproduction. The proposed technique uses three key components. First, it integrates multiple information sources, such as vulnerability descriptions, source code repositories, and related documentation, to fill in and refine missing key information. Second, it uses automated interactions to guide the target application step by step into a prerequisite state for vulnerability triggering, thus improving the feasibility of vulnerability reproduction. Finally, during the reproduction execution, anomalies are dynamically detected and corrected in real time, thus enhancing adaptability to complex environments and improving the robustness of vulnerability reproduction. Experimental results on 86 real-world vulnerability reports show that VulVerifier achieves a reproduction success rate of 44.7%, which is close to the 66.3% success rate of human experts. Compared with the existing method, CVE-Genie, the proposed system successfully reproduces 34 additional vulnerability reports and reduces the average reproduction cost by 3.19 dollars.

    参考文献
    相似文献
    引证文献
引用本文

袁乐天,于正民,聂翌楠,张源.漏洞报告自动化复现智能体技术.计算机系统应用,,():1-11

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2026-03-11
  • 最后修改日期:2026-04-03
  • 录用日期:
  • 在线发布日期: 2026-07-17
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62661041 传真: Email:csa@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号