TitanCA: Lessons from Orchestrating LLM Agents to Discover 100+ CVEs

📅 2026-04-20
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the high false positive rates of traditional static application security testing (SAST) tools, which hinder efficient identification of genuine vulnerabilities. The authors propose the first multi-agent large language model (LLM) collaborative framework tailored for real-world vulnerability discovery, integrating static analysis with deep semantic understanding through a unified pipeline comprising matching, filtering, verification, and adaptive modules. This approach substantially enhances both the accuracy and actionable output of vulnerability detection. Evaluated on open-source software, the method successfully identified 203 confirmed zero-day vulnerabilities, leading to the assignment of 118 CVE identifiers. The study also distills critical practical insights into deploying LLM-based agents in security engineering contexts.

Technology Category

Machine Learning: Large Multimodal Models (LMMs)Natural Language Processing: Safety and RobustnessMultiagent Systems: Adversarial Agents

Application Category

Search and Retrieval-Augmented AI: Search Tool Learning with LLM: Teaching LLMs to invoke search and make use of retrieved informationSemantics and Knowledge: Data modeling to support human-machine intelligence, including LLMs agents, intelligent system behavior, explanations, and user-friendly interactionsSecurity and Privacy: Large-scale security measurements
📝 Abstract
Software vulnerabilities remain one of the most persistent threats to modern digital infrastructure. While static application security testing (SAST) tools have long served as the first line of defense, they suffer from high false-positive rates. This article presents TitanCA, a collaborative project between Singapore Management University and GovTech Singapore that orchestrates multiple large language model (LLM)-powered agents into a unified vulnerability discovery pipeline. Applied in open-source software, TitanCA has discovered 203 confirmed zero-day vulnerabilities and yielded 118 CVEs. We describe the four-module architecture, i.e., matching, filtering, inspection, and adaptation, and share key lessons from building and deploying an LLM-based vulnerability discovery solution in practice.
Problem

Research questions and friction points this paper is trying to address.

software vulnerabilities
static application security testing
false-positive rates
CVEs
zero-day vulnerabilities
Innovation

Methods, ideas, or system contributions that make the work stand out.

LLM agents
vulnerability discovery
CVE detection
collaborative AI
SAST enhancement
🔎 Similar Papers