LLM agent scaffolding systematically finds broken access control vulnerabilities in web apps

The ABSENTIA framework maps routes to code and uses invariant falsification to infer missing authorization checks, outperforming static analyzers and unstructured agents.

Top University
André V. Duarte · Aditya Oke · Rui Melo · Shubham Gandhi · Nachiket Kotalwar · Charmi Khandor · +4 more

Carnegie Mellon University · Instituto Superior Técnico · Faculdade de Engenharia do Porto

Research Digest··2 min read
Duarte et al.

The authors designed ABSENTIA as a multi-step framework that first constructs a call graph linking web application routes to their backend code.

Why this paper

From Carnegie Mellon University and 2 others

In one line

ABSENTIA turns LLM agents into route-by-route auditors that infer intended authorization invariants and report where they are not enforced.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ✓Reports numbers on named benchmarks (2 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.