Diffploit: Facilitating Cross-Version Exploit Migration for Open Source Library Vulnerabilities
Zirui Chen, Zhipeng Xue, Jiayuan Zhou, Xing Hu, Xin Xia, Xiaohu Yang
摘要
Exploits are commonly used to demonstrate the presence of library vulnerabilities and validate their impact across different versions. However, their direct application to alternative versions often fails due to breaking changes introduced during evolution. These failures stem from both changes in triggering conditions (e.g., API refactorings) and broken dynamic environments (e.g., build or runtime errors), which are challenging to interpret and adapt manually. Existing techniques primarily focus on code-level trace alignment through fuzzing, which is both time-consuming and insufficient for handling environment-level failures. Moreover, they often fall short when dealing with complicated triggering condition changes across versions. To overcome this, we propose Diffploit, an iterative, diff-driven exploit migration method structured around two key modules: the Context Module and the Migration Module. The Context Module constructs contexts derived from analyzing behavioral discrepancies between the target and reference versions, which capture the failure symptom and its related diff hunks. Leveraging these contexts, the Migration Module guides an LLM-based adaptation through an iterative feedback loop, balancing exploration of diff candidates and gradual refinement to resolve reproduction failures effectively. We evaluate Diffploit on a large-scale dataset containing 102 Java CVEs and 689 version-migration tasks across 79 libraries. Diffploit successfully migrates 84.2% exploits, outperforming the change-aware test repair tool TaRGET by 52.0% and the rule-based tool in IDEA by 61.6%. Beyond technical effectiveness, Diffploit identifies 5 CVE reports with incorrect affected version ranges, three of which have been confirmed. We also discover 111 unreported versions in GitHub Advisory Database.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Depradar: Agentic Coordination for Context-Aware Defect Impact Analysis in Deep Learning LibrariesYi Gao, Xing Hu, Tongtong Xu, Jiali Zhao 等ICSE 2026
- CREME: Robustness Enhancement of Code LLMs via Layer-Aware Model EditingShuhan Liu, Xing Hu, Kerui Huang, Xiaohu Yang 等ICSE 2026
它引用的顶会 Paper34
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing 等USENIX Security 2019 · 被引用 149 次
- Data Quality for Software Vulnerability DatasetsRoland Croft, Muhammad Ali Babar, M. Mehdi KholoosiICSE 2023 · 被引用 138 次
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu 等USENIX Security 2018 · 被引用 138 次
相关 Paper
- AEM: Facilitating Cross-Version Exploitability Assessment of Linux Kernel VulnerabilitiesZheyue Jiang, Yuan Zhang, Jun Xu, Xinqian Sun 等S&P 2023
- Exploiting Library Vulnerability via Migration Based Automating Test GenerationZirui Chen, Xing Hu, Xin Xia, Yi Gao 等ICSE 2024 · 被引用 10 次
- Facilitating Vulnerability Assessment through PoC MigrationJiarun Dai, Yuan Zhang, Hailong Xu, Haiming Lyu 等CCS 2021 · 被引用 26 次
- LLMPort: Cross-file Patch Porting via Task Decomposition and Self-correctionBofei Chen, Lei Zhang, Peng Deng, Nan Wang 等ASE 2025
- Well Begun is Half Done: Location-Aware and Trace-Guided Iterative Automated Vulnerability RepairZhenlei Ye, Xiaobing Sun, Sicong Cao, Lili Bo 等ICSE 2026
