LLM-Driven SAST-Genius: A Hybrid Static Analysis Framework for Comprehensive and Actionable Security

This report examines the synergy between Large Language Models (LLMs) and Static Application Security Testing (SAST) to improve vulnerability discovery. Traditional SAST tools, while effective for proactive security, are limited by high false-positive rates and a lack of contextual understanding. Conversely, LLMs excel at code analysis and pattern recognition but can be prone to inconsistencies and hallucinations. By integrating these two technologies, a more intelligent and efficient system is created. This combination moves beyond mere vulnerability detection optimization, transforming security into a deeply integrated, contextual process that provides tangible benefits like improved triage, dynamic bug descriptions, bug validation via exploit generation and enhanced analysis of complex codebases. The result is a more effective security approach that leverages the strengths of both technologies while mitigating their weaknesses. SAST-Genius reduced false positives by about 91 % (225 to 20) compared to Semgrep alone.

Paper

References (19)

05Package Hallucinations: How LLMs Can Invent Vulnerabilities | USENIX2025 · USENIX
06Principles for coding securely with LLMs2025 · Sean Goedecke
07What is Static Application Security Testing (SAST)? | CrowdStrike2025 · CrowdStrike
08[2502.07049] LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights - arXiv2025
10A Technical Analysis on Detecting Coding Bugs of GPT4-Advanced Data Analysis - arXiv
12scientist, 0 → 1 product leader, and serial founderdeep

Scroll for more · 7 remaining

Similar papers

© 2026 NYSGPT2525 LLC