Self-Discovering Security Oracles: Meta-learning Vulnerability Detection Strategies through Adversarial Self-Play
Current Large Language Model (LLM) based vulnerability detection systems rely on static prompting strategies and fixed analysis pipelines that fail to adapt to evolving threat landscapes. These approaches struggle to discover unknown vulnerability patterns beyond their training distributions, limiting their effectiveness against emerging security threats. This paper explores adversarial meta-learning where foundation models autonomously discover vulnerability detection strategies through reinforcement learning and competitive self-play. We present MetaMorphSES, a framework that enables Foundational models to evolve in terms of both vulnerability generation capabilities (as a red team) and detection strategies (as a blue team) through adversarial co-evolution without predetermined prompts or fixed architectures. The system learns to generate increasingly sophisticated synthetic vulnerabilities while simultaneously developing detection strategies that generalize to real-world security flaws. Through a dual-loop optimization process, the inner loop generates and detects vulnerabilities while the outer meta-learning loop discovers optimal detection strategies through reinforcement learning. Our experiments on six real-world vulnerability corpora demonstrate that meta-learned security strategies yield substantially stronger detection of unseen vulnerabilities (up to 0.90 F1) against nine strong baselines spanning rule-based static analysis, zero-shot and fine-tuned LLMs, and recent vulnerability detectors, with the system reaching a stable equilibrium. While training remains resource-intensive, the approach establishes adversarial meta-learning as a novel and effective way to discover security vulnerabilities with foundational models through self-directed adaptation without explicit programming of detection rules.
Wed 14 OctDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
10:30 - 12:30 | Security and Other Non-Functional Properties: Security and Privacy 4Research Papers / Industry Showcase / Journal First at Forum 3 | ||
10:30 15mTalk | GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing Industry Showcase Omar Tsai Simon Fraser University, Jianing Li Simon Fraser University, Tsz Tung Cheung Simon Fraser University, Lejing Huang Simon Fraser University, Hao Zhu Simon Fraser University, Jianrui Xiao Simon Fraser University, Iman Sharafaldin Forward Security, Mohammad A. Tayebi Simon Fraser University Pre-print | ||
10:45 15mTalk | When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Research Papers Zesen Liu Hong Kong University of Science and Technology, Zhixiang Zhang Fudan University, Yuchong Xie Hong Kong University of Science and Technology, Dongdong She HKUST (The Hong Kong University of Science and Technology) | ||
11:00 15mTalk | Self-Discovering Security Oracles: Meta-learning Vulnerability Detection Strategies through Adversarial Self-Play Research Papers Media Attached | ||
11:15 15mTalk | To Think or Not to Think: Evaluating LLM Reasoning and Agents in Vulnerability Detection Research Papers Hua Beng Tan Singapore Management University, Ratnadira Widyasari Singapore Management University, Singapore, Merve Astekin SINTEF, Arda Goknil SINTEF Digital, Hasan Sozer Ozyegin University, Yan Naing Tun Singapore Management University, Erik Johannes Husom SINTEF Digital, Lwin Khin Shar Singapore Management University, Lingxiao Jiang Singapore Management University | ||
11:30 15mTalk | Decompiling the Web: Automated Semantic Recovery of Post-compilation Abstraction Leaks Research Papers | ||
11:45 15mTalk | Context-Enhanced Vulnerability Detection Based on Large Language Models Journal First Yixin Yang , Bowen Xu Beihang University, Xiang Gao Beihang University, Hailong Sun Beihang University DOI | ||
12:00 15mTalk | CLEAR: Causal Context-Based Agentic Reasoning for Vulnerability Detection Research Papers Sungju Yun Hanyang University, Sijune hwang Hanyang University, Yeonjoon Lee Hanyang University, Kyungtae Kang Hanyang University, Sungbin Park Hanyang University | ||
12:15 15mTalk | Learning to Triage Vulnerability Reports from Program Analysis: An Empirical Study in Node.js Research Papers Ronghao Ni Carnegie Mellon University, Aidan Z.H. Yang Amazon Web Services, Min-Chien Hsu Carnegie Mellon University, Nuno Sabino Carnegie Mellon University, Limin Jia Carnegie Mellon University, Ruben Martins Carnegie Mellon University, Darion Cassel Amazon Web Services, Kevin Cheang Amazon Web Services Pre-print | ||