SCARA: A Semantics-Constrained Autonomous Remediation Agent for Opaque Industrial Software Vulnerabilities

📅 2026-05-19
📈 Citations: 0
Influential: 0
📄 PDF

career value

184K/year
🤖 AI Summary
This work proposes SCARA, the first end-to-end autonomous repair agent designed to address the challenge of automatically patching vulnerabilities in opaque industrial software (OIS)—systems that lack source code, symbols, and recompilability. Operating entirely at the binary level, SCARA employs a three-stage mechanism comprising operational state-aware validation (OSVA), repair synthesis under semantic constraints (RSA), and correctness verification (CVA). It integrates protocol-level mitigation, binary hardening, and SSCKG-guided patch generation to ensure both feasibility and semantic correctness of repairs. Evaluated on the OIS-RemedBench benchmark, SCARA achieves 100% repair precision with zero false positives, filters out 20.0% of infeasible cases, and attains an 88.9% final repair success rate after retries.
📝 Abstract
Critical-infrastructure operators are increasingly expected to assess and remediate vulnerabilities in deployed industrial software. However, much of this software exists as opaque industrial software (OIS), including stripped firmware, proprietary protocol handlers, and compiled control logic without source code, symbols, build environments, or hardware interfaces. While binary analysis can identify vulnerability candidates, existing automated repair systems largely rely on source code, compilable artifacts, sanitizer feedback, or instrumentable builds, leaving a gap between binary-level discovery and validated remediation. This paper presents SCARA, a Semantics-Constrained Autonomous Remediation Agent for OIS. SCARA operates under a source-unavailable defender model and connects upstream binary vulnerability candidates to conditionally validated remedies through a four-stage pipeline. Operational-state-aware verification (OSVA) filters infeasible candidates using a nine-component industrial state model; remediation synthesis (RSA) selects the strongest available remedy across protocol mitigation, binary hardening, and SSCKG-constrained source patches; and correctness validation (CVA) provides conditional correctness evidence via behavioral-coverage preservation, independent replay, and typed rejection feedback. On OIS-RemedBench, a 15-case benchmark spanning firmware, protocol handlers, and ICS/PLC artifacts, SCARA achieves observed 100% precision with no false positives, refutes 20.0% of cases as operationally infeasible, and reaches 88.9% remediation success after targeted reruns. To our knowledge, SCARA is the first end-to-end framework that connects binary vulnerability candidates to conditionally validated remediation for opaque industrial software.
Problem

Research questions and friction points this paper is trying to address.

opaque industrial software
binary vulnerability remediation
source-unavailable repair
industrial control systems
automated program repair
Innovation

Methods, ideas, or system contributions that make the work stand out.

opaque industrial software
binary-level remediation
semantics-constrained repair
autonomous vulnerability remediation
operation-state-aware verification
🔎 Similar Papers
No similar papers found.
B
Bowei Ning
Shenyang University of Technology, Shenyang 110870, Liaoning, China
X
Xuejun Zong
Shenyang University of Chemical Technology, Shenyang 110142, Liaoning, China
L
Lian Lian
Shenyang University of Chemical Technology, Shenyang 110142, Liaoning, China
K
Kan He
Shenyang University of Chemical Technology, Shenyang 110142, Liaoning, China
G
Guogang Wang
Shenyang University of Chemical Technology, Shenyang 110142, Liaoning, China
Y
Yifei Sun
Shenyang University of Chemical Technology, Shenyang 110142, Liaoning, China
J
Jinyang Liu
Shenyang University of Technology, Shenyang 110870, Liaoning, China