GadgetHunter: Region-Based Neuro-Symbolic Detection of Java Deserialization Vulnerabilities
This program is tentative and subject to change.
Java deserialization vulnerabilities (JDVs) enable attackers to execute arbitrary code by crafting malicious serialized objects that trigger sequences of method calls (gadget chains) leading to dangerous operations. Existing detection approaches face a fundamental trade-off: static analysis achieves scalability but suffers from high false positives due to infeasible paths and imprecision with dynamic features like reflection; dynamic validation reduces false positives but incurs prohibitive costs and fails to explore deep exploitation chains.
We present GadgetHunter, a neuro-symbolic JDV detector that combines scalable static analysis with targeted LLM reasoning and JDV exploitation-oriented constraint solving. Our approach partitions gadget chains into regions based on analyzability: statically resolvable segments are processed via interprocedural taint analysis, while dynamic boundaries are delegated to LLMs for semantic validation. We then extract critical constraints from each gadget and compose them into SMT formulas to determine chain feasibility through satisfiability solving. Evaluation on the ysoserial benchmark demonstrates that GadgetHunter reduces false negatives by up to 32% and false positives by 12-85% compared to state-of-the-art tools, while discovering 197 previously unknown gadget chains and rediscovering 4 recent CVEs. Our results show that combining symbolic reasoning with semantic understanding achieves both precision and practical impact in vulnerability detection.
This program is tentative and subject to change.
Wed 8 JulDisplayed time zone: Eastern Time (US & Canada) change
10:30 - 12:30 | |||
10:30 20mTalk | YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group Industry Papers Yayi Wang Ant Group, Shenao Wang Huazhong University of Science and Technology, Jian Zhao Huazhong University of Science and Technology, Shaosen Shi Ant Group, Ting Li Ant Group, Yan Cheng Ant Group, Lizhong Bian Ant Group, Kan Yu Ant Group, Yanjie Zhao Huazhong University of Science and Technology, Haoyu Wang Huazhong University of Science and Technology | ||
10:50 20mTalk | InDe-LLM: Defending Against Jailbreak Attacks in LLM-Powered Systems via Intention Disentangling Research Papers YujueWang Tsinghua University, Quan Zhang East China Normal University, Chijin Zhou East China Normal University, Gwihwan Go Tsinghua University, Dalong Shi AVIC International Digital Network Technology Co., Ltd., Yu Jiang Tsinghua University | ||
11:10 20mTalk | Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study Research Papers Weijie Liu Nankai University, Hongbo Chen Indiana University Bloomington, Shuo Huai Nankai University, Zhen Xu Nanyang Technological University, Wenhao Wang Institute of Information Engineering, CAS, XiaoFeng Wang Nanyang Technological University, Danfeng Zhang Duke University, Zhi Li Huazhong University of Science and Technology, Haixu Tang Indiana University Bloomington, Zheli Liu Nankai University | ||
11:30 20mTalk | GadgetHunter: Region-Based Neuro-Symbolic Detection of Java Deserialization Vulnerabilities Research Papers Kaixuan Li Nanyang Technological University, Jian Zhang Beihang University, Chong Wang Nanyang Technological University, Sen Chen Nankai University, Zong Cao Imperial Global Singapore, Min Zhang East China Normal University, Yang Liu Nanyang Technological University Pre-print | ||
11:50 20mTalk | ReGA: Model-based Safeguard for LLMs via Representation-Guided Abstraction Research Papers | ||