Perhimpunan Mahasiswa SUTD Indonesia (PADI
TriVul Framework for Enhanced Java Vulnerability Detection
Pages
28
Time to read
57 mins
Publication
Language
English
Pages
28
Time to read
57 mins
Publication
Language
English
This document is a technical report that presents TriVul, a multi-agent assisted static analysis framework designed to improve the precision of vulnerability detection in Java applications. The report outlines the persistent challenge of high false-positive rates in existing static application security testing (SAST) tools and introduces TriVul as a solution that integrates heterogeneous static analyzers with stage-specific large language model (LLM) reasoning. TriVul employs a multi-stage refinement process that includes candidate filtering, structural validation, and semantic judgment through LLMs. The evaluation of TriVul on the CWE-Bench-Java dataset demonstrates significant improvements in precision and F1 scores compared to traditional SAST tools and other LLM-assisted approaches. The findings indicate that LLMs are most effective when utilized as specialized components within a hybrid framework rather than as standalone detectors. The report further discusses the implications of these findings for the future of vulnerability detection methodologies.