arXiv cs.AIOctober 7, 2026
VulValidate: Auditing Function-Level Vulnerability Labels with Executable Evidence
Excerpt
arXiv:2610.05103v1 Announce Type: cross Abstract: Reliable learning-based vulnerability detection requires high-quality labels, yet datasets built from vulnerability-fixing commits may label functions as vulnerable simply because they were changed by a security patch. We present VulValidate, a framework that uses LLM agents to coordinate dynamic analysis tools and construct vulnerability-triggering experiments from runtime feedback. Given a labeled function and its fixing patch, VulValidate reco