ASE 2026
Mon 12 - Fri 16 October 2026 Munich, Germany

Current Large Language Model (LLM) based vulnerability detection systems rely on static prompting strategies and fixed analysis pipelines that fail to adapt to evolving threat landscapes. These approaches struggle to discover unknown vulnerability patterns beyond their training distributions, limiting their effectiveness against emerging security threats. This paper explores adversarial meta-learning where foundation models autonomously discover vulnerability detection strategies through reinforcement learning and competitive self-play. We present MetaMorphSES, a framework that enables Foundational models to evolve in terms of both vulnerability generation capabilities (as a red team) and detection strategies (as a blue team) through adversarial co-evolution without predetermined prompts or fixed architectures. The system learns to generate increasingly sophisticated synthetic vulnerabilities while simultaneously developing detection strategies that generalize to real-world security flaws. Through a dual-loop optimization process, the inner loop generates and detects vulnerabilities while the outer meta-learning loop discovers optimal detection strategies through reinforcement learning. Our experiments on six real-world vulnerability corpora demonstrate that meta-learned security strategies yield substantially stronger detection of unseen vulnerabilities (up to 0.90 F1) against nine strong baselines spanning rule-based static analysis, zero-shot and fine-tuned LLMs, and recent vulnerability detectors, with the system reaching a stable equilibrium. While training remains resource-intensive, the approach establishes adversarial meta-learning as a novel and effective way to discover security vulnerabilities with foundational models through self-directed adaptation without explicit programming of detection rules.

Wed 14 Oct

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

10:30 - 12:30
Security and Other Non-Functional Properties: Security and Privacy 4Research Papers / Industry Showcase / Journal First at Forum 3
10:30
15m
Talk
GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
Industry Showcase
Omar Tsai Simon Fraser University, Jianing Li Simon Fraser University, Tsz Tung Cheung Simon Fraser University, Lejing Huang Simon Fraser University, Hao Zhu Simon Fraser University, Jianrui Xiao Simon Fraser University, Iman Sharafaldin Forward Security, Mohammad A. Tayebi Simon Fraser University
Pre-print
10:45
15m
Talk
When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents
Research Papers
Zesen Liu Hong Kong University of Science and Technology, Zhixiang Zhang Fudan University, Yuchong Xie Hong Kong University of Science and Technology, Dongdong She HKUST (The Hong Kong University of Science and Technology)
11:00
15m
Talk
Self-Discovering Security Oracles: Meta-learning Vulnerability Detection Strategies through Adversarial Self-Play
Research Papers
Md Rashedul Hasan University of Nebraska-Lincoln, Hamid Bagheri University of Nebraska-Lincoln
Media Attached
11:15
15m
Talk
To Think or Not to Think: Evaluating LLM Reasoning and Agents in Vulnerability Detection
Research Papers
Hua Beng Tan Singapore Management University, Ratnadira Widyasari Singapore Management University, Singapore, Merve Astekin SINTEF, Arda Goknil SINTEF Digital, Hasan Sozer Ozyegin University, Yan Naing Tun Singapore Management University, Erik Johannes Husom SINTEF Digital, Lwin Khin Shar Singapore Management University, Lingxiao Jiang Singapore Management University
11:30
15m
Talk
Decompiling the Web: Automated Semantic Recovery of Post-compilation Abstraction Leaks
Research Papers
Shriyans Sudhi Rochester Institute of Technology, Yinxi Liu Rochester Institute of Technology
11:45
15m
Talk
Context-Enhanced Vulnerability Detection Based on Large Language Models
Journal First
Yixin Yang , Bowen Xu Beihang University, Xiang Gao Beihang University, Hailong Sun Beihang University
DOI
12:00
15m
Talk
CLEAR: Causal Context-Based Agentic Reasoning for Vulnerability Detection
Research Papers
Sungju Yun Hanyang University, Sijune hwang Hanyang University, Yeonjoon Lee Hanyang University, Kyungtae Kang Hanyang University, Sungbin Park Hanyang University
12:15
15m
Talk
Learning to Triage Vulnerability Reports from Program Analysis: An Empirical Study in Node.js
Research Papers
Ronghao Ni Carnegie Mellon University, Aidan Z.H. Yang Amazon Web Services, Min-Chien Hsu Carnegie Mellon University, Nuno Sabino Carnegie Mellon University, Limin Jia Carnegie Mellon University, Ruben Martins Carnegie Mellon University, Darion Cassel Amazon Web Services, Kevin Cheang Amazon Web Services
Pre-print