USENIX Security2026Top-tier venue
BugAuditor: Detecting Bugs via Inconsistent Defensive Code Auditing
Miaoqian Lin, Kai Chen, Hao Chen
Abstract
Modern software systems contain complex behaviors that are prone to bugs when handled incorrectly. Detecting such bugs requires reliable oracles, which are difficult to construct as they require project-specific knowledge. Prior studies mainly obtain oracles from comparable code deviations, documentation, or historical bugs. However, these sources are inherently limited, leaving many project-specific bugs undetected.
In this paper, we propose inconsistent defensive handling as a new bug oracle for LLM-driven bug auditing. Specifically, we observe that real-world systems contain abundant defensive code, where developers proactively apply defensive handling in security-sensitive contexts to prevent bugs, and inconsistencies in such handling can indicate bugs. To realize this idea, we design BugAuditor, a framework that performs bug auditing via inconsistent defensive handling. BugAuditor first locates defensive code snippets across the codebase. It then reasons about the code to infer its security intent and underlying defensive patterns, characterizing the associated security-sensitive behaviors and defensive handling. Finally, BugAuditor applies the inferred patterns to audit the codebase and reports inconsistent defensive handling of the same security-sensitive behaviors across different contexts.
We evaluate BugAuditor on the Linux kernel. The results show that BugAuditor effectively mines project-specific knowledge embedded in defensive code that existing methods miss. Using the inferred defensive patterns, BugAuditor detects 54 long-latent bugs, including resource leaks, information leaks, and invalid pointer dereferences. To date, 20 bugs have been confirmed and fixed in the latest version, and two have been assigned CVE identifiers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6355c2df-dc3e-43ad-9245-988a33e9c324Builds on28
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 388 citations
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu et al.ICSE 2024 · 131 citations
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang et al.USENIX Security 2016 · 107 citations
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 97 citations
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung et al.USENIX Security 2019 · 77 citations
Related papers
- SpecAuditor: Generating Audit Specifications for LLM-Driven Bug DetectionMiaoqian Lin, Hao ChenS&P 2026 · 3 citations
- eBPF Misbehavior Detection: Fuzzing with a Specification-Based OracleTao Lyu, Kumar Kartikeya Dwivedi, Thomas Bourgeat, Mathias Payer et al.SOSP 2025
- ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic VerificationXiangpu Song, Longjia Pei, Jianliang Wu, Yingpei Zeng et al.NDSS 2026 · 3 citations
- Non-Distinguishable Inconsistencies as a Deterministic Oracle for Detecting Security BugsQingyang Zhou, Qiushi Wu, Dinghao Liu, Shouling Ji et al.CCS 2022 · 2 citations
- Detecting Missed Security Operations Through Differential Checking of Object-based Similar PathsDinghao Liu, Qiushi Wu, Shouling Ji, Kangjie Lu et al.CCS 2021 · 11 citations
