Cryptbara: Dependency-Guided Detection of Python Cryptographic API Misuses
Seogyeong Cho, Seungeun Yu, Seunghoon Woo
Abstract
We present Cryptbara, a precise approach for detecting Python cryptographic API misuses. Cryptographic APIs are widely used to ensure data security, but their improper use can inadvertently compromise the security of entire systems. Existing approaches often fail to capture how cryptographic objects are initialized and used across inter-procedural contexts, limiting their ability to detect context-dependent misuses. In contrast, the key innovation of Cryptbara lies in synergistically combining static dependency analysis with LLM reasoning guided by dependency context, enabling context-sensitive misuse detection. To this end, Cryptbara extracts intra- and inter-procedural dependencies from Python code and encodes them into context-rich prompts, allowing the LLM to perform semantically-aware analysis despite syntactic complexity. We evaluated Cryptbara on two benchmarks containing real-world cryptographic API misuses. Cryptbara achieved F1 scores of 95.43% and 84%, outperforming existing approaches that achieved at most 73.68% and 70.59% F1 scores, respectively. Cryptbara further demonstrated its practical impact by discovering previously unknown misuses in popular Python repositories, with 22 representative cases reported to and confirmed by maintainers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bcdd3160-7023-472e-9af5-b97336411ce2Cited by top-tier papers1
Ask how each one uses itBuilds on18
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 388 citations
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel et al.S&P 2017 · 261 citations
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon et al.CCS 2019 · 159 citations
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim et al.CCS 2017 · 126 citations
Related papers
- Beyond Static Pattern Matching? Rethinking Automatic Cryptographic API Misuse Detection in the Era of LLMsYifan Xia, Zichen Xie, Peiyu Liu, Kangjie Lu et al.ISSTA 2025 · 2 citations
- Gopher: High-Precision and Deep-Dive Detection of Cryptographic API Misuse in the Go EcosystemYuexi Zhang, Bingyu Li, Jingqiang Lin, Linghui Li et al.CCS 2024 · 2 citations
- Towards Precise Reporting of Cryptographic MisusesYikang Chen, Yibo Liu, Ka Lok Wu, Duc Viet Le et al.NDSS 2024
- JScamd: An Automated Static Taint Analysis Framework for Detecting Cryptographic API Misuses in JavaScriptShijie Jia, Bowen Xu, Yuan Ma, Yingjiao Niu et al.USENIX Security 2026
- Improving Data Leakage Detection in Machine Learning Notebooks through Static Slicing and Structured LLM PromptsTaha Draoui, Mohamed Wiem Mkaouer, Christian D. NewmanFSE 2026 · 1 citation
