ABSENTIA: Detecting Broken Access Control Vulnerabilities in Web Applications
André V. Duarte, Aditya Oke, Rui Melo, Shubham Gandhi, Nachiket Kotalwar, Charmi Khandor, Danqing Wang, Arlindo L. Oliveira, Carolyn Rosé, Lei Li
Abstract
Broken access control, the failure of authorization, is one of the most prevalent web security risks. Unlike injection, a flow of untrusted input into a dangerous operation, authorization is a relation: who may act on what, not how data moves. Each application decides that relation for itself, so no rule written in advance carries to the next. An LLM agent can infer it from the code, but with no systematic way to cover the application and prioritize what to inspect, its search stays undirected and access-control flaws go undetected. We present ABSENTIA, a security scaffolding that turns general LLM agents into systematic vulnerability detectors for the backend of web applications, run as an audit by the developers and security engineers who maintain the code. Under its direction, the agents build a graph that maps the application's routes to the code behind them. ABSENTIA then works route by route, applying invariant falsification: it infers the properties the code is meant to satisfy, and where one is not enforced, reports the route for maintainer review. We also release BAC-Bench, a benchmark of 30 broken access control advisories across 25 repositories, 3 languages, and 9 frameworks, each published in 2025 or later, verified by a human auditor, and paired with its fixing commit, so credit requires flagging the vulnerable version and not the fixed one. ABSENTIA recalls 19 of them, 17 under paired credit, and an LLM verifier confirms 51% of its findings. CodeQL and Semgrep recall none, and an unstructured agent on the same model recalls 3. In the OWASP Benchmark injection categories, ABSENTIA leads the dedicated analyzers in Python and trails only CodeQL and IRIS in Java.
Create a lesson
Related papers
System-Level Optimization Beyond Cryptographic Kernels: An ML-KEM Case Study on Arm Cortex-M7
Mahmoud Abdelhafeez Sayed, Mostafa Taha, Gurp Nijjer
A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders
Emmanuela Andam, Yasir Abbas Zaidi, Abdelali Hadir et al.
Detection and Resolution of Periodic Artifacts in OpenDP's Discrete Laplace Sampler
Cesare Gerolimetto Fabrello, Valeria Rossi, Alberto Trombetta et al.
A Structured State Space Sequence Model for Multi-Class Classification of Malware
Emmanuela Andam, Rana Shaaban, Emanuel Grant et al.
From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures
Yahya Shahsavari, Sara Rouhani, Kaiwen Zhang
Walking the Embedding Space: Datastore Extraction from Multimodal RAG
Maria Carmen Jica, Ali Satvaty, Suzan Verberne et al.