{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:03:27Z","timestamp":1782846207523,"version":"3.54.5"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/legalcode"}],"funder":[{"name":"the RIE2025 Industry Alignment Fund - Industry Collaboration Projects (IAF-ICP) Funding Initiative","award":["I2501E0045"],"award-info":[{"award-number":["I2501E0045"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Java deserialization vulnerabilities (JDVs) enable attackers to execute arbitrary code by crafting malicious serialized objects that trigger sequences of method calls (gadget chains) leading to dangerous operations. Existing detection approaches face a fundamental trade-off: static analysis achieves scalability but suffers from high false positives due to infeasible paths and imprecision with dynamic features like reflection; dynamic validation reduces false positives but incurs prohibitive costs and fails to explore deep exploitation chains.<\/jats:p>\n                  <jats:p>We present GadgetHunter, a neuro-symbolic JDV detector that combines scalable static analysis with  \ntargeted LLM reasoning and JDV exploitation-oriented constraint solving. Our approach partitions gadget chains into regions based on analyzability: statically resolvable segments are processed via interprocedural taint analysis, while dynamic boundaries are delegated to LLMs for semantic validation. We then extract critical constraints from each gadget and compose them into SMT formulas to determine chain feasibility through satisfiability solving. Evaluation on the ysoserial benchmark demonstrates that GadgetHunter reduces false negatives by up to 32% and false positives by 12-85% compared to state-of-the-art tools, while discovering 197 previously unknown gadget chains and rediscovering 4 recent CVEs. Our results show that combining symbolic reasoning with semantic understanding achieves both precision and practical impact in vulnerability detection.<\/jats:p>","DOI":"10.1145\/3797065","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"46-68","source":"Crossref","is-referenced-by-count":0,"title":["GadgetHunter: Region-Based Neuro-symbolic Detection of Java Deserialization Vulnerabilities"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-3517-353X","authenticated-orcid":false,"given":"Kaixuan","family":"Li","sequence":"first","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-8316-1894","authenticated-orcid":false,"given":"Jian","family":"Zhang","sequence":"additional","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0003-1424-6290","authenticated-orcid":false,"given":"Chong","family":"Wang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-9477-4100","authenticated-orcid":false,"given":"Sen","family":"Chen","sequence":"additional","affiliation":[{"name":"Nankai University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0001-2069-4949","authenticated-orcid":false,"given":"Zong","family":"Cao","sequence":"additional","affiliation":[{"name":"Imperial Global Singapore of Imperial College London, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-3152-4347","authenticated-orcid":false,"given":"Min","family":"Zhang","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai Key Laboratory of Trustworthy Computing, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-6423(99)00007-6"},{"key":"e_1_2_1_2_1","volume-title":"Use XML Tags to Structure Your Prompts. https:\/\/2.zoppoz.workers.dev:443\/https\/platform.claude.com\/docs\/en\/build-withclaude\/prompt-engineering\/use-xml-tags [Online","year":"2025","unstructured":"Anthropic. 2025. Use XML Tags to Structure Your Prompts. https:\/\/2.zoppoz.workers.dev:443\/https\/platform.claude.com\/docs\/en\/build-withclaude\/prompt-engineering\/use-xml-tags [Online; accessed 2025-09-01]."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594299"},{"key":"e_1_2_1_4_1","volume-title":"A static byte code analyzer for Java deserialization gadget research. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/ mbechler\/serianalyzer [Online","author":"Bechler Moritz","year":"2025","unstructured":"Moritz Bechler. 2016. A static byte code analyzer for Java deserialization gadget research. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/ mbechler\/serianalyzer [Online; accessed 2025-09-09]."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2408776.2408795"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179377"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00044"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3652588.3663317"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00150"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00028"},{"key":"e_1_2_1_11_1","volume-title":"2024 CWE Top 10 KEV Weaknesses. https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre.org\/top25\/archive\/ 2024\/2024_kev_list.html [Online","author":"Enumeration Common Weakness","year":"2025","unstructured":"Common Weakness Enumeration. 2024. 2024 CWE Top 10 KEV Weaknesses. https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre.org\/top25\/archive\/ 2024\/2024_kev_list.html [Online; accessed 2025-09-09]."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/512950.512973"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-78800-3_24"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056650"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.64"},{"key":"e_1_2_1_16_1","volume-title":"CWE -CWE-502: Deserialization of Untrusted Data (4.18). https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre. org\/data\/definitions\/502.html [Online","author":"Enumeration Common Weakness","year":"2025","unstructured":"Common Weakness Enumeration. 2025. CWE -CWE-502: Deserialization of Untrusted Data (4.18). https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre. org\/data\/definitions\/502.html [Online; accessed 2025-09-09]."},{"key":"e_1_2_1_17_1","volume-title":"ysoserial: A Proof-of-Concept Tool for Generating Payloads that Exploit Unsafe Java Object Deserialization. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/frohoff\/ysoserial [Online","author":"Frohoff Chris","year":"2025","unstructured":"Chris Frohoff. 2025. ysoserial: A Proof-of-Concept Tool for Generating Payloads that Exploit Unsafe Java Object Deserialization. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/frohoff\/ysoserial [Online; accessed 2025-01-31]."},{"key":"e_1_2_1_18_1","volume-title":"Marshalling Pickles: How Deserializing Objects Can Ruin Your Day. Presented at OWASP AppSec California. https:\/\/2.zoppoz.workers.dev:443\/https\/frohoff.github.io\/appseccali-marshalling-pickles\/ [Online","author":"Frohoff Chris","year":"2015","unstructured":"Chris Frohoff and Gabriel Lawrence. 2015. Marshalling Pickles: How Deserializing Objects Can Ruin Your Day. Presented at OWASP AppSec California. https:\/\/2.zoppoz.workers.dev:443\/https\/frohoff.github.io\/appseccali-marshalling-pickles\/ [Online; accessed 2026-06-20]."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065036"},{"key":"e_1_2_1_20_1","volume-title":"Automated Discovery of Deserialization Gadget Chains. Black Hat USA. https:\/\/2.zoppoz.workers.dev:443\/https\/i.blackhat.com\/us- 18\/Thu-August-9\/us-18-Haken-Automated-Discovery-of-Deserialization-Gadget-Chains-wp.pdf [Online","author":"Haken Ian","year":"2026","unstructured":"Ian Haken. 2018. Automated Discovery of Deserialization Gadget Chains. Black Hat USA. https:\/\/2.zoppoz.workers.dev:443\/https\/i.blackhat.com\/us- 18\/Thu-August-9\/us-18-Haken-Automated-Discovery-of-Deserialization-Gadget-Chains-wp.pdf [Online; accessed 2026-06-20]."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360252"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3715711"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3765031"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2502.08447"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE63991.2025.00039"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616262"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3660772"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3650212"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3295739"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2405.17238"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-70896-1_9"},{"key":"e_1_2_1_32_1","first-page":"271","volume-title":"USENIX Security Symposium 14","author":"Benjamin Livshits V","year":"2005","unstructured":"V Benjamin Livshits and Monica S Lam. 2005. Finding security vulnerabilities in Java applications with static analysis. USENIX Security Symposium 14 (2005), 271-286."},{"key":"e_1_2_1_33_1","volume-title":"Java Object Serialization Specification. https:\/\/2.zoppoz.workers.dev:443\/https\/docs.oracle.com\/javase\/8\/docs\/platform\/ serialization\/spec\/serialTOC.html [Online","author":"Oracle Corporation","year":"2025","unstructured":"Oracle Corporation. 2021. Java Object Serialization Specification. https:\/\/2.zoppoz.workers.dev:443\/https\/docs.oracle.com\/javase\/8\/docs\/platform\/ serialization\/spec\/serialTOC.html [Online; accessed 2025-09-11]."},{"key":"e_1_2_1_34_1","volume-title":"Deserialization Cheat Sheet. https:\/\/2.zoppoz.workers.dev:443\/https\/cheatsheetseries.owasp.org\/cheatsheets\/ Deserialization_Cheat_Sheet.html [Online","author":"Foundation OWASP","year":"2025","unstructured":"OWASP Foundation. 2017. Deserialization Cheat Sheet. https:\/\/2.zoppoz.workers.dev:443\/https\/cheatsheetseries.owasp.org\/cheatsheets\/ Deserialization_Cheat_Sheet.html [Online; accessed 2025-09-11]."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3418931"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/199448.199462"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3649851"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3554732"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1081706.1081750"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1561\/2500000014"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616313"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598120"},{"key":"e_1_2_1_43_1","volume-title":"Tree-sitter: A parser generator tool. https:\/\/2.zoppoz.workers.dev:443\/https\/tree-sitter.github.io\/tree-sitter\/ [Online","year":"2025","unstructured":"Tree-sitter. 2025. Tree-sitter: A parser generator tool. https:\/\/2.zoppoz.workers.dev:443\/https\/tree-sitter.github.io\/tree-sitter\/ [Online; accessed 2025-09-11]."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.52202\/079017-4181"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1800"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.5555\/3766078.3766230"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3797065","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:07:48Z","timestamp":1782842868000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3797065"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":46,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3797065"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3797065","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}