ABSENTIA: Detecting Broken Access Control Vulnerabilities in Web Applications

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the lack of systematic coverage and prioritization in large language models (LLMs) when detecting broken access control (BAC) vulnerabilities in web applications. To this end, it proposes a security scaffolding framework that transforms general-purpose LLMs into systematic BAC detectors. By constructing routing code graphs and integrating static analysis with invariant falsification techniques, the method guides LLM agents to precisely audit authorization logic flaws in backend systems. The primary contributions include the introduction of this novel detection framework and the release of the BAC-Bench benchmark dataset. Experimental evaluations demonstrate that the proposed approach successfully identifies 19 vulnerabilities on BAC-Bench, achieving recall rates significantly superior to those of CodeQL and Semgrep, while also exhibiting leading performance in detecting OWASP injection vulnerabilities.
📝 Abstract
Broken access control, the failure of authorization, is one of the most prevalent web security risks. Unlike injection, a flow of untrusted input into a dangerous operation, authorization is a relation: who may act on what, not how data moves. Each application decides that relation for itself, so no rule written in advance carries to the next. An LLM agent can infer it from the code, but with no systematic way to cover the application and prioritize what to inspect, its search stays undirected and access-control flaws go undetected. We present ABSENTIA, a security scaffolding that turns general LLM agents into systematic vulnerability detectors for the backend of web applications, run as an audit by the developers and security engineers who maintain the code. Under its direction, the agents build a graph that maps the application's routes to the code behind them. ABSENTIA then works route by route, applying invariant falsification: it infers the properties the code is meant to satisfy, and where one is not enforced, reports the route for maintainer review. We also release BAC-Bench, a benchmark of 30 broken access control advisories across 25 repositories, 3 languages, and 9 frameworks, each published in 2025 or later, verified by a human auditor, and paired with its fixing commit, so credit requires flagging the vulnerable version and not the fixed one. ABSENTIA recalls 19 of them, 17 under paired credit, and an LLM verifier confirms 51% of its findings. CodeQL and Semgrep recall none, and an unstructured agent on the same model recalls 3. In the OWASP Benchmark injection categories, ABSENTIA leads the dedicated analyzers in Python and trails only CodeQL and IRIS in Java.
Problem

Research questions and friction points this paper is trying to address.

Broken Access Control
Web Application Security
Authorization Vulnerabilities
Vulnerability Detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Broken Access Control
LLM Agent
Invariant Falsification
Security Scaffolding
BAC-Bench
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
A
André V. Duarte
INESC-ID, Instituto Superior Técnico
A
Aditya Oke
Carnegie Mellon University
R
Rui Melo
Faculdade de Engenharia do Porto
Shubham Gandhi
Shubham Gandhi
LTI, Carnegie Mellon University
Large Language ModelsAI4Code
N
Nachiket Kotalwar
Carnegie Mellon University
C
Charmi Khandor
Carnegie Mellon University
Danqing Wang
Danqing Wang
Carnegie Mellon University
Natural Language ProcessingDrug Discovery
A
Arlindo L. Oliveira
INESC-ID, Instituto Superior Técnico
C
Carolyn Rosé
Carnegie Mellon University
Lei Li
Lei Li
Associate Professor, School of Computer Science, Carnegie Mellon University
Machine LearningNatural Language ProcessingMachine TranslationLLMAI Drug Discovery