arXiv · 2506.23644
QLPro: Automated Code Vulnerability Discovery via LLM and Static Code Analysis Integration
Abstract
We introduce QLPro, a vulnerability detection framework that systematically integrates LLMs and static analysis tools to enable comprehensive vulnerability detection across entire open-source projects.We constructed a new dataset, JavaTest, comprising 10 open-source projects from GitHub with 62 confirmed vulnerabilities. CodeQL, a state-of-the-art static analysis tool, detected only 24 of these vulnerabilities while QLPro detected 41. Furthermore, QLPro discovered 6 previously unknown vulnerabilities, 2 of which have been confirmed as 0-days.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Junze Hu, Xiangyu Jin, Yizhe Zeng, Yuling Liu, Yunpeng Li, Dan Du, Kaiyu Xie, Hongsong Zhu. 2025-06-30. QLPro: Automated Code Vulnerability Discovery via LLM and Static Code Analysis Integration. https://arxiv.org/abs/2506.23644
Cite the original work for its findings. Save a collection to share your selection of sources.