In brief

  • Automated security: LLMs are leveraged to generate API parameter security rules from source code, while a generative fuzzer uses a software-based digital twin to refine hardware tests efficiently.
  • Privacy at scale: An evaluation of WhatsApp’s contact discovery reveals the ability to enumerate 3.5 billion active accounts, exposing highly sensitive data globally.

Generating API Parameter Security Rules with LLM for API Misuse Detection

  • Introduces GPTAid, a system that automatically generates API Parameter Security Rules (APSRs) by analysing API source code using an LLM.

  • Uses an execution feedback-checking approach alongside code differential analysis to create concrete APSRs and apply them to detect API misuse.

  • Evaluated on eight popular libraries, generating 579 APSRs that enrich existing documentation.

  • Found 210 previously unknown security bugs across 47 applications integrating these libraries, identifying vulnerabilities capable of causing crashes and denial of service.

  • Jinghua Liu, Yi Yang, Kai Chen, Miaoqian Lin. “Generating API Parameter Security Rules with LLM for API Misuse Detection.” NDSS 2025 — https://www.ndss-symposium.org/ndss-paper/generating-api-parameter-security-rules-with-llm-for-api-misuse-detection/

GoldenFuzz: Generative Golden Reference Hardware Fuzzing

  • Introduces a novel language-model-based hardware fuzzer that decouples test case refinement from coverage and vulnerability exploration.

  • Utilises a software-based Golden Reference Model (GRM), a digital twin conforming to the device under test’s ISA, to refine fuzzing strategies efficiently before executing tests on actual hardware.

  • Reduces the computational overhead and cost typically associated with cycle-accurate device simulations.

  • Discovered seven new vulnerabilities in open-source and commercial cores, four of which were rated as CVSS 7.0 severity.

  • Lichao Wu, Mohamadreza Rostami, Huimin Li, Nikhilesh Singh, Ahmad-Reza Sadeghi. “GoldenFuzz: Generative Golden Reference Hardware Fuzzing.” NDSS 2026 — https://www.ndss-symposium.org/ndss-paper/goldenfuzz-generative-golden-reference-hardware-fuzzing/

Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy

  • Developed a method to generate plausible mobile phone numbers for 245 countries to evaluate the feasibility of large-scale enumeration on WhatsApp.

  • Enumerated 3.5 billion active user accounts, collecting phone numbers, public keys, and E2EE encryption signatures.

  • Demonstrated that the platform’s contact discovery architecture inherently exposes user registration status globally.

  • Highlighted severe privacy risks, noting the exposure of users in nations where WhatsApp is banned, and the potential for the dataset to be exploited for spam, phishing, or surveillance.

  • Gabriel K. Gegenhuber, Philipp É. Frenzel, Maximilian Günther, Johanna Ullrich, Aljosha Judmayer. “Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy.” NDSS 2026 — https://www.ndss-symposium.org/ndss-paper/hey-there-you-are-using-whatsapp-enumerating-three-billion-accounts-for-security-and-privacy/