Arizona State’s Yan Shoshitaishvili on Eliminating False Positives With Agentic AI
Michael Novinson (MichaelNovinson) •
August 17, 2026
Yan Shoshitaishvili, associate professor, Arizona State University
Artificial intelligence agents are evolving vulnerability detection by moving beyond code review to direct software interaction. They can run commands, observe behavior and test whether a suspected flaw can be triggered, said Yan Shoshitaishvili, associate professor at Arizona State University.
See Also: Rise of Malicious AI Skills Expands Enterprise Risk
That agentic loop can reduce one of software security’s oldest burdens: false positives. Traditional program analysis tools often rely on abstractions and assumptions that create imprecision. Agents can follow investigative steps, test hypotheses and classify findings at a level closer to human review.
“Human analysts traditionally spend a long time reverse-engineering malware to understand it. We’re increasingly automating this [with AI agents],” Shoshitaishvili said. “The ability to filter out false positives with an agentic loop is a big superpower.”
In this video interview with ISMG at Black Hat USA 2026, Shoshitaishvili also discussed:
How AI agents can automate root cause analysis and malware reverse engineering;
Comparing LLM vulnerability discovery with static and dynamic analysis techniques;
Using threat models and adversarial review to improve agent reliability.
Shoshitaishvili focuses on cybersecurity research, education and real-world security impact at Arizona State University. His research centers on automated program analysis and vulnerability detection. He has published dozens of research papers and led Shellphish’s participation in the DARPA Cyber Grand Challenge, creating a fully autonomous hacking system.