Abstract
The rapid proliferation of Internet-of-Things (IoT) systems has led to increasingly heterogeneous, resource-constrained, and security-sensitive software deployments. In this context, detecting vulnerabilities in embedded and system-level IoT code has become particularly critical, as even a single exploitable flaw may compromise entire networks or devices. Vulnerability detection in real-world software continues to pose significant challenges due to the intricate nature of program semantics, the diversity of vulnerability patterns, and the limited explainability offered by current machine learning models. Although Large Language Models (LLMs) have exhibited remarkable capabilities in comprehending and reasoning about source code, their effectiveness is frequently compromised by inadequate domain knowledge and instances of hallucinated outputs. To address these limitations, we propose VulKnow, a retrieval-augmented framework for vulnerability detection that harnesses structured vulnerability knowledge alongside multi-stage prompt-based reasoning. Specifically, VulKnow first constructs a structured knowledge base derived from authoritative sources such as CWE/CVE reports and standard library specifications. Sub-sequently, it conducts context-aware knowledge retrieval and integrates the retrieved items into an LLM-based initial filtering module. To ensure high-confidence and verifiable results, we design a multi-stage reasoning pipeline that progressively validates vulnerabilities through semantic prompts and consistency checks. Experiments conducted on multiple real-world datasets (Linux, Qemu, Big-Vul) demonstrate that VulKnow significantly enhances precision, recall, and explainability compared to existing static analysis tools as well as LLM-only baselines. This positions VulKnow as a reliable solution for practical vulnerability auditing scenarios.
| Original language | English |
|---|---|
| Journal | IEEE Internet of Things Journal |
| DOIs | |
| State | Accepted/In press - 2026 |
| Externally published | Yes |
Keywords
- LLMs
- Prompt Reasoning
- Retrieval-Augmented Generation
- Structured Knowledge
- Vulnerability Detection
Fingerprint
Dive into the research topics of 'VulKnow: Enhancing Vulnerability Detection with Structured Knowledge and Large Language Models'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver