{"id":141960,"date":"2026-08-17T06:22:10","date_gmt":"2026-08-17T06:22:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/141960\/"},"modified":"2026-08-17T06:22:10","modified_gmt":"2026-08-17T06:22:10","slug":"how-ai-agents-validate-software-vulnerabilities-2","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/141960\/","title":{"rendered":"How AI Agents Validate Software Vulnerabilities"},"content":{"rendered":"<p>                    Arizona State&#8217;s Yan Shoshitaishvili on Eliminating False Positives With Agentic AI<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/michael-novinson-i-4923\" rel=\"nofollow noopener\" target=\"_blank\">Michael Novinson<\/a> (<a href=\"https:\/\/www.twitter.com\/MichaelNovinson\" rel=\"nofollow noopener\" target=\"_blank\">MichaelNovinson<\/a>)                                                    \u2022<br \/>\n                        August 17, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/how-ai-agents-validate-software-vulnerabilities-a-32559#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/yan-shoshitaishvili-shell-image_large-5-a-32559.jpg\" alt=\"How AI Agents Validate Software Vulnerabilities\" class=\"img-responsive hidden\"\/><\/p>\n<p>                    Yan Shoshitaishvili, associate professor, Arizona State University<\/p>\n<p>Artificial intelligence agents are evolving vulnerability detection by moving beyond code review to direct software interaction. They can run commands, observe behavior and test whether a suspected flaw can be triggered, said Yan Shoshitaishvili, associate professor at Arizona State University.<\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/rise-malicious-ai-skills-expands-enterprise-risk-a-32475?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Rise of Malicious AI Skills Expands Enterprise Risk<\/a><\/p>\n<p>That agentic loop can reduce one of software security&#8217;s oldest burdens: false positives. Traditional program analysis tools often rely on abstractions and assumptions that create imprecision. Agents can follow investigative steps, test hypotheses and classify findings at a level closer to human review.<\/p>\n<p>&#8220;Human analysts traditionally spend a long time reverse-engineering malware to understand it. We&#8217;re increasingly automating this [with AI agents],&#8221; Shoshitaishvili said. &#8220;The ability to filter out false positives with an agentic loop is a big superpower.&#8221;<\/p>\n<p>In this video interview with ISMG at <a href=\"https:\/\/www.bankinfosecurity.com\/black-hat-c-372\" rel=\"nofollow noopener\" target=\"_blank\">Black Hat USA 2026<\/a>, Shoshitaishvili also discussed:<\/p>\n<p>How AI agents can automate root cause analysis and malware reverse engineering;<br \/>\nComparing LLM vulnerability discovery with static and dynamic analysis techniques;<br \/>\nUsing threat models and adversarial review to improve agent reliability.<\/p>\n<p>Shoshitaishvili focuses on cybersecurity research, education and real-world security impact at Arizona State University. His research centers on automated program analysis and vulnerability detection. He has published dozens of research papers and led Shellphish&#8217;s participation in the DARPA Cyber Grand Challenge, creating a fully autonomous hacking system.<\/p>\n<p>            <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Arizona State&#8217;s Yan Shoshitaishvili on Eliminating False Positives With Agentic AI Michael Novinson (MichaelNovinson) \u2022 August 17, 2026&hellip;\n","protected":false},"author":2,"featured_media":141953,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[70028,179,405,27798,7537,61544,313,70027,45964,2225,36392,70025,21171,7955,58209,22569,70026,47056,70029],"class_list":["post-141960","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-adversarial-review","tag-agentic-ai","tag-ai-agents","tag-arizona-state-university","tag-artificial-intelligence-agents","tag-black-hat-usa-2026","tag-cybersecurity","tag-dynamic-analysis","tag-false-positives","tag-llms","tag-root-cause-analysis","tag-software-analysis","tag-software-security","tag-software-vulnerabilities","tag-static-analysis","tag-threat-modeling","tag-vulnerability-validation","tag-vulnerability-detection","tag-yan-shoshitaishvili"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/141960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=141960"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/141960\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/141953"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=141960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=141960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=141960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}