Uppsats
Agentic AI Framework for Web Vulnerability Detection, Mitigation and Patching
H
Chalmers tekniska högskola / Institutionen för data och informationsteknik
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Modern web applications expose increasingly complex attack surfaces, and existingsecurity automation is still most effective at producing candidate findings ratherthan reviewable repairs. Static and dynamic analysis tools can identify possibleweaknesses at scale, but the path from a finding to a validated, scoped, and reviewready patch remains weakly automated and difficult to inspect. This thesis investigates whether a multi-stage agentic AI workflow can improve web vulnerabilitydetection, mitigation, and patch delivery in white-box repository settings.To examine this question, the proposed framework decomposes security review intostages for discovery, triage, analysis, mitigation, verification, and delivery. Eachstage produces structured artifacts that are consumed by later stages, making theworkflow more inspectable than a single end-to-end repair agent. The design emphasizes repository-grounded evidence, explicit repair hypotheses, independent verification, and reviewer-oriented delivery units.The evaluation combines issue-level repair experiments with repository case studies. On the PatchEval runtime-validated subset of 230 vulnerability-repair tasks,the multi-stage workflow achieves 78 successful repairs, compared with 73 for amatched single-agent baseline under the same model. This improvement is modestand requires higher token use and cost, but case-level analysis suggests that stagingcan influence repair strategy by clarifying vulnerability boundaries and providingindependent feedback on patch completeness. In repository case studies, agenticdiscovery and triage cover more answer-key vulnerabilities than CodeQL, Semgrep,and OWASP ZAP, especially for issues that require cross-file or design-level reasoning. The workflow also improves reviewability by organizing patches and reportsinto structured delivery units.Overall, the results indicate that the main value of multi-stage orchestration is nota large increase in repair success, but a more inspectable and controllable securityreview process. The workflow records repository evidence, analysis assumptions,verification results, and delivery boundaries, helping reviewers understand why avulnerability was found, how it was analyzed, whether the patch addresses the issue,and how the repair should be reviewed. These benefits remain constrained by modelcapability and cost.
Information
- Författare
- Xuanhao, Liu, Jiangzhao, Xie
- Lärosäte / institution
- Chalmers tekniska högskola / Institutionen för data och informationsteknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- H
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
H, Chalmers tekniska högskola / Institutionen för data och informationsteknik
Gisselblad Seibt , Hanna, Shasawar, Pawan
Publicerad: 2026