The authors designed ABSENTIA as a multi-step framework that first constructs a call graph linking web application routes to their backend code.
LLM agent scaffolding systematically finds broken access control vulnerabilities in web apps
The ABSENTIA framework maps routes to code and uses invariant falsification to infer missing authorization checks, outperforming static analyzers and unstructured agents.
Top University
André V. Duarte · Aditya Oke · Rui Melo · Shubham Gandhi · Nachiket Kotalwar · Charmi Khandor · +4 more
Carnegie Mellon University · Instituto Superior Técnico · Faculdade de Engenharia do Porto
Research Digest··2 min read
Duarte et al.
Why this paper
From Carnegie Mellon University and 2 others
In one line
ABSENTIA turns LLM agents into route-by-route auditors that infer intended authorization invariants and report where they are not enforced.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ·No stated limitations found
- ✓Reports numbers on named benchmarks (2 benchmarks)
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§