acceptodds
Under review as a conference paper at ICLR 2027

Bridging Implicit Semantic Gaps: LLM-Guided Graph Completion for Static Vulnerability Detection

Abstract

Hybrid approaches that combine large language models (LLMs) with classical program analysis have advanced static vulnerability detection, yet many real-world vulnerabilities still evade detection. A key source of these false negatives is implicit semantic gaps: semantically mediated relations that connect attacker-controlled inputs to security-sensitive sinks but are absent from conventional interprocedural control-and data-flow graphs, leaving the end-to-end vulnerability path disconnected. We present SEMBRIDGE, a hybrid framework that bridges these implicit gaps via LLM-guided graph completion. SBMBRIDGE first applies conventional static analysis to recover explicit interprocedural structure and identify candidate sinks. It then uses LLMs to extract bridge facts from heterogeneous repository artifacts and materializes them as typed edges in a Semantic Bridge-Augmented Program Graph(SBPG). These edges reconnect program fragments that are semantically related but structurally disconnected, enabling end-to-end vulnerability reasoning over paths that standard analyses cannot recover. On the 213-case release of C WE-Bench-Java,our approach successfully detects 125 vulnerabilities, whereas the current state-of-the-art tool, IRIS, detects 81, yielding a 54.3% relative improvement over IRIS. More importantly, SEMBRIDGE also uncovers 27 previously unknown (0-day)vulnerabilities in 50 real-world projects.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.