Paper deep dive
Security Debt in LLM Agent Applications: A Measurement Study of Vulnerabilities and Mitigation Trade-offs
Zhuoxiang Shen, Jiarun Dai, Yuan Zhang, Min Yang
Intelligence
Status: succeeded | Model: google/gemini-3.1-flash-lite-preview | Prompt: intel-v1 | Confidence: 98%
Last extracted: 3/11/2026, 1:19:01 AM
Summary
This paper presents a comprehensive measurement study of security vulnerabilities in LLM agent applications. The authors analyzed 221 real-world vulnerabilities, identifying 14 vulnerability types and 15 root causes across 7 components. The study evaluates developer mitigation strategies, highlights practical challenges and trade-offs, and provides 12 key findings to guide future research and development in securing LLM-based agents.
Entities (4)
Relation Signals (3)
Zhuoxiang Shen â affiliatedwith â Fudan University
confidence 100% · Zhuoxiang Shen Fudan University
Zhuoxiang Shen â authored â Security Debt in LLM Agent Applications: A Measurement Study of Vulnerabilities and Mitigation Trade-offs
confidence 100% · WhoZhuoxiang Shen, Jiarun Dai, Yuan Zhang, Min Yang
Security Debt in LLM Agent Applications: A Measurement Study of Vulnerabilities and Mitigation Trade-offs â presentedat â ASE 2025
confidence 100% · ASE 2025 (series) / Research Papers / Security Debt in LLM Agent Applications
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Welcome to the website of the 40th IEEE/ACM International Conference on Automated Software Engineering, ASE 2025. The ASE conference is the premier research forum for Automated Software Engineering. Each year, it brings together researchers and practitioners from academia and industry to discuss foundations, techniques, and tools for automating the analysis, design, implementation, testing, and maintenance of large software systems. ASE 2025 will be in Seoul, Republic of Korea. We are working hard to prepare the webpage and also looking forward to seeing you in Seoul! Photos from ASE 2025 ...
Tags
Links
- Source: https://conf.researchr.org/details/ase-2025/ase-2025-papers/19/Security-Debt-in-LLM-Agent-Applications-A-Measurement-Study-of-Vulnerabilities-and-M
- Canonical: https://conf.researchr.org/details/ase-2025/ase-2025-papers/19/Security-Debt-in-LLM-Agent-Applications-A-Measurement-Study-of-Vulnerabilities-and-M
- Code: https://github.com/SZXSec/Agent-Vulnerability-Dataset
Full Text
16,473 characters extracted from source content.
Expand or collapse full text
ASE 2025Sun 16 - Thu 20 November 2025 Seoul, South KoreaToggle navigationAttending Venue: Grand Walkerhill SeoulTransportation to VenueFloor PlanAccommodationsRegistrationVisa LetterHotel Shuttle ServiceDaily MealsAbout SeoulCode of ConductDiversity and Inclusion PlanTravel SupportSponsorshipProgram ASE Program Your ProgramProgram OverviewSun 16 NovMon 17 NovTue 18 NovWed 19 NovThu 20 NovTracks ASE 2025KeynoteResearch PapersJournal-FirstIndustry ShowcaseNIERTool Demonstration TrackMIP AwardWorkshopsDoctoral SymposiumNew Faculty SymposiumStudent Research CompetitionTutorialsStudent VolunteersPostersTSE Editorial Board MeetingCo-hosted ConferencesAIware AIwareAIware KeynotesAIware Main TrackAIware ArXiv TrackAIware Benchmark & Dataset TrackAIware Industry Demo TrackWorkshopsA-MobileAgenticSEAISMASYDECode Completion ChallengeEx-ASEIntelligent SEMAS-GAINVARSECo-hosted SymposiaSSBSE SSBSESSBSE Hot-off-the-PressSSBSE KeynoteSSBSE RENE/NIERSSBSE Research PapersSSBSE ChallengeOrganization ASE 2025 CommitteesOrganizing CommitteeTrack Committees Research PapersJournal-FirstIndustry ShowcaseNIERTool Demonstration TrackWorkshopsDoctoral SymposiumDoctoral Symposium CommitteeDoctoral Symposium PanelNew Faculty SymposiumStudent Research CompetitionStudent Research Competition ChairJudgeProgram CommitteeTutorialsStudent VolunteersContributors People IndexCo-hosted ConferencesAIwareSteering CommitteeOrganizing CommitteeMain TrackArXiv TrackBenchmark & Dataset TrackWorkshopsA-MobileOrganising CommitteeProgram CommitteeAgenticSE N/A - check homepageAISM N/A - check homepageASYDE N/A - check homepageCode Completion ChallengeOrganizing committeeEx-ASE N/A - check homepageIntelligent SE N/A - check homepageMAS-GAINOrganizing CommitteeSteering CommitteeProgram CommitteeVARSE N/A - check homepageCo-hosted SymposiaSSBSEOrganizing CommitteeSteering CommitteeHot-off-the-PressRENE/NIERResearch PapersSSBSE Challenge SearchSeries SeriesASE 2026 ASE 2025ASE 2024ASE 2023ASE 2022ASE 2021ASE 2020ASE 2019Past Editions Sign inSign up ASE 2025 (series) / Research Papers / Security Debt in LLM Agent Applications: A Measurement Study of Vulnerabilities and Mitigation Trade-offsWhoZhuoxiang Shen, Jiarun Dai, Yuan Zhang, Min YangTrackASE 2025 Research PapersProgram Display ConfigurationTime ZoneThe program is currently displayed in (GMT+09:00) Seoul.Use conference time zone: (GMT+09:00) SeoulSelect other time zone(GMT-12:00) AoE (Anywhere On Earth)(GMT-11:00) Midway Island, Samoa(GMT-10:00) Hawaii-Aleutian(GMT-10:00) Hawaii(GMT-09:30) Marquesas Islands(GMT-09:00) Gambier Islands(GMT-09:00) Alaska(GMT-08:00) Tijuana, Baja California(GMT-08:00) Pitcairn Islands(GMT-08:00) Pacific Time (US & Canada)(GMT-07:00) Mountain Time (US & Canada)(GMT-06:00) Chihuahua, La Paz, Mazatlan(GMT-07:00) Arizona(GMT-06:00) Saskatchewan, Central America(GMT-06:00) Guadalajara, Mexico City, Monterrey(GMT-05:00) Easter Island(GMT-05:00) Cancun(GMT-06:00) Central Time (US & Canada)(GMT-05:00) Eastern Time (US & Canada)(GMT-05:00) Cuba(GMT-05:00) Bogota, Lima, Quito, Rio Branco(GMT-04:00) Caracas(GMT-03:00) Santiago(GMT-04:00) La Paz(GMT-03:00) Faukland Islands(GMT-04:00) Manaus, Amazonas, Brazil(GMT-04:00) Atlantic Time (Goose Bay)(GMT-04:00) Atlantic Time (Canada)(GMT-03:30) Newfoundland(GMT-03:00) UTC-3(GMT-03:00) Montevideo(GMT-03:00) Miquelon, St. Pierre(GMT-03:00) Greenland(GMT-03:00) Buenos Aires(GMT-03:00) Brasilia, Distrito Federal, Brazil(GMT-02:00) Mid-Atlantic(GMT-01:00) Cape Verde Is.(GMT-01:00) Azores(UTC) Coordinated Universal Time(GMT) Belfast(GMT) Dublin(GMT) Lisbon(GMT) London(GMT) Monrovia, Reykjavik(GMT+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna(GMT+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague(GMT+01:00) Brussels, Copenhagen, Madrid, Paris(GMT+01:00) West Central Africa(GMT+02:00) Windhoek(GMT+02:00) Athens(GMT+02:00) Beirut(GMT+02:00) Cairo(GMT+02:00) Gaza(GMT+02:00) Harare, Pretoria(GMT+02:00) Jerusalem(GMT+03:00) Minsk(GMT+03:00) Syria(GMT+03:00) Moscow, St. Petersburg, Volgograd(GMT+03:00) Nairobi(GMT+03:30) Tehran(GMT+04:00) Abu Dhabi, Muscat(GMT+04:00) Yerevan(GMT+04:30) Kabul(GMT+05:00) Ekaterinburg(GMT+05:00) Tashkent(GMT+05:30) Chennai, Kolkata, Mumbai, New Delhi(GMT+05:45) Kathmandu(GMT+06:00) Astana, Dhaka(GMT+07:00) Novosibirsk(GMT+06:30) Yangon (Rangoon)(GMT+07:00) Bangkok, Hanoi, Jakarta(GMT+07:00) Krasnoyarsk(GMT+08:00) Beijing, Chongqing, Hong Kong, Urumqi(GMT+08:00) Irkutsk, Ulaan Bataar(GMT+08:00) Perth(GMT+08:45) Eucla(GMT+09:00) Osaka, Sapporo, Tokyo(GMT+09:00) Seoul(GMT+09:00) Yakutsk(GMT+10:30) Adelaide(GMT+09:30) Darwin(GMT+10:00) Brisbane(GMT+11:00) Hobart(GMT+10:00) Vladivostok(GMT+11:00) Lord Howe Island(GMT+11:00) Solomon Is., New Caledonia(GMT+11:00) Magadan(GMT+12:00) Norfolk Island(GMT+12:00) Anadyr, Kamchatka(GMT+13:00) Auckland, Wellington(GMT+12:00) Fiji, Kamchatka, Marshall Is.(GMT+13:45) Chatham Islands(GMT+13:00) Nuku'alofa(GMT+14:00) Kiritimati The GMT offsets shown reflect the offsets at the moment of the conference.Time BandBy setting a time band, the program will dim events that are outside this time window. This is useful for (virtual) conferences with a continuous program (with repeated sessions).The time band will also limit the events that are included in the personal iCalendar subscription service.Display full programSpecify a time band - Save CloseWhenTue 18 Nov 2025 14:20 - 14:30 at Grand Hall 5 - Security 2 Chair(s): Saeid Tizpaz-NiariAbstractThe advantages of large language models (LLMs) in content comprehension and question answering have led to the rapid emergence of LLM agent. Developers across diverse domains are actively building their own agent applications (apps), as these apps can streamline workflows, boost efficiency, or deliver innovative solutions, thereby enhancing the competitiveness of their products. Agent apps are playing an increasingly important role in our daily lives. However, numerous serious vulnerabilities and security issues have been identified in these apps. To effectively manage future security risks, it is essential to systematically understand the unique characteristics of agent app vulnerabilities and their mitigation. In this paper, we present the first comprehensive study on the vulnerabilities of agent apps, the mitigation practices of app developers, and the associated challenges and trade-offs. We identify 14 types of vulnerabilities and 15 root causes across 7 components, based on an analysis of 221 real-world vulnerabilities. Our study further investigates developer reactions, evaluates the effectiveness of various mitigation strategies, and explores the practical challenges and inevitable trade-offs in vulnerability mitigation. Finally, we distill 12 key findings, discuss their implications for agent app developers, maintainers, and security researchers, and offer suggestions for future research directions. Zhuoxiang ShenFudan UniversityJiarun DaiFudan UniversityChinaYuan ZhangFudan UniversityChinaMin YangFudan UniversityChinaProgram Display ConfigurationTime ZoneThe program is currently displayed in (GMT+09:00) Seoul.Use conference time zone: (GMT+09:00) SeoulSelect other time zone(GMT-12:00) AoE (Anywhere On Earth)(GMT-11:00) Midway Island, Samoa(GMT-10:00) Hawaii-Aleutian(GMT-10:00) Hawaii(GMT-09:30) Marquesas Islands(GMT-09:00) Gambier Islands(GMT-09:00) Alaska(GMT-08:00) Tijuana, Baja California(GMT-08:00) Pitcairn Islands(GMT-08:00) Pacific Time (US & Canada)(GMT-07:00) Mountain Time (US & Canada)(GMT-06:00) Chihuahua, La Paz, Mazatlan(GMT-07:00) Arizona(GMT-06:00) Saskatchewan, Central America(GMT-06:00) Guadalajara, Mexico City, Monterrey(GMT-05:00) Easter Island(GMT-05:00) Cancun(GMT-06:00) Central Time (US & Canada)(GMT-05:00) Eastern Time (US & Canada)(GMT-05:00) Cuba(GMT-05:00) Bogota, Lima, Quito, Rio Branco(GMT-04:00) Caracas(GMT-03:00) Santiago(GMT-04:00) La Paz(GMT-03:00) Faukland Islands(GMT-04:00) Manaus, Amazonas, Brazil(GMT-04:00) Atlantic Time (Goose Bay)(GMT-04:00) Atlantic Time (Canada)(GMT-03:30) Newfoundland(GMT-03:00) UTC-3(GMT-03:00) Montevideo(GMT-03:00) Miquelon, St. Pierre(GMT-03:00) Greenland(GMT-03:00) Buenos Aires(GMT-03:00) Brasilia, Distrito Federal, Brazil(GMT-02:00) Mid-Atlantic(GMT-01:00) Cape Verde Is.(GMT-01:00) Azores(UTC) Coordinated Universal Time(GMT) Belfast(GMT) Dublin(GMT) Lisbon(GMT) London(GMT) Monrovia, Reykjavik(GMT+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna(GMT+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague(GMT+01:00) Brussels, Copenhagen, Madrid, Paris(GMT+01:00) West Central Africa(GMT+02:00) Windhoek(GMT+02:00) Athens(GMT+02:00) Beirut(GMT+02:00) Cairo(GMT+02:00) Gaza(GMT+02:00) Harare, Pretoria(GMT+02:00) Jerusalem(GMT+03:00) Minsk(GMT+03:00) Syria(GMT+03:00) Moscow, St. Petersburg, Volgograd(GMT+03:00) Nairobi(GMT+03:30) Tehran(GMT+04:00) Abu Dhabi, Muscat(GMT+04:00) Yerevan(GMT+04:30) Kabul(GMT+05:00) Ekaterinburg(GMT+05:00) Tashkent(GMT+05:30) Chennai, Kolkata, Mumbai, New Delhi(GMT+05:45) Kathmandu(GMT+06:00) Astana, Dhaka(GMT+07:00) Novosibirsk(GMT+06:30) Yangon (Rangoon)(GMT+07:00) Bangkok, Hanoi, Jakarta(GMT+07:00) Krasnoyarsk(GMT+08:00) Beijing, Chongqing, Hong Kong, Urumqi(GMT+08:00) Irkutsk, Ulaan Bataar(GMT+08:00) Perth(GMT+08:45) Eucla(GMT+09:00) Osaka, Sapporo, Tokyo(GMT+09:00) Seoul(GMT+09:00) Yakutsk(GMT+10:30) Adelaide(GMT+09:30) Darwin(GMT+10:00) Brisbane(GMT+11:00) Hobart(GMT+10:00) Vladivostok(GMT+11:00) Lord Howe Island(GMT+11:00) Solomon Is., New Caledonia(GMT+11:00) Magadan(GMT+12:00) Norfolk Island(GMT+12:00) Anadyr, Kamchatka(GMT+13:00) Auckland, Wellington(GMT+12:00) Fiji, Kamchatka, Marshall Is.(GMT+13:45) Chatham Islands(GMT+13:00) Nuku'alofa(GMT+14:00) Kiritimati The GMT offsets shown reflect the offsets at the moment of the conference.Time BandBy setting a time band, the program will dim events that are outside this time window. This is useful for (virtual) conferences with a continuous program (with repeated sessions).The time band will also limit the events that are included in the personal iCalendar subscription service.Display full programSpecify a time band - Save CloseSession ProgramTue 18 NovDisplayed time zone: Seoul change14:00 - 15:30Security 2Journal-First / Research Papers at Grand Hall 5 Chair(s): Saeid Tizpaz-Niari University of Illinois Chicago14:0010mTalkTowards Generalizable Instruction Vulnerability Prediction via LLM-Enhanced Code RepresentationResearch PapersBao Wen Nanjing University of Aeronautics and Astronautics, Jingjing Gu Nanjing University of Aeronautics and Astronautics, Jingxuan Zhang Nanjing University of Aeronautics and Astronautics, Yang Liu Nanyang Technological University, Pengfei Yu Nanjing University of Aeronautics and Astronautics, Yanchao Zhao Nanjing University of Aeronautics and Astronautics14:1010mTalkInterpretable Vulnerability Detection ReportsResearch PapersClaudia Mamede Carnegie Mellon University, Jose Campos FEUP & LASIGE, Claire Le Goues Carnegie Mellon University, Rui Abreu Faculty of Engineering of the University of Porto, Portugal14:2010mTalkSecurity Debt in LLM Agent Applications: A Measurement Study of Vulnerabilities and Mitigation Trade-offsResearch PapersZhuoxiang Shen Fudan University, Jiarun Dai Fudan University, Yuan Zhang Fudan University, Min Yang Fudan University14:3010mTalkAltered Histories in Version Control System Repositories: Evidence from the TrenchesResearch PapersSolal Rapaport Télécom Paris, Institut Polytechnique de Paris, Laurent Pautet Télécom Paris, Institut Polytechnique de Paris, Samuel Tardieu Télécom Paris, Institut Polytechnique de Paris, Stefano Zacchiroli LTCI, Télécom Paris, Institut Polytechnique de Paris, Palaiseau, France Pre-print14:4010mTalkLares: LLM-driven Code Slice Semantic Search for Patch Presence TestingResearch PapersSiyuan Li School of Cyber Science and Technology, Shandong University, China & University of Chinese Academy of Sciences & Institute of Information Engineering Chinese Academy of Sciences, China, Yaowen Zheng Institute of Information Engineering at Chinese Academy of Sciences, Hong Li Institute of Information Engineering at Chinese Academy of Sciences, Jingdong Guo Institute of Information Engineering, CAS, Beijing, China; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China;, Chaopeng Dong Institute of Information Engineering, CAS, Beijing, China; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China;, Chunpeng Yan Institute of Information Engineering Chinese Academy of Sciences & University of Chinese Academy of Sciences, China, Weijie Wang Institute of Information Engineering Chinese Academy of Sciences & University of Chinese Academy of Sciences, China, Yimo Ren Institute of Information Engineering Chinese Academy of Sciences & University of Chinese Academy of Sciences, China, Limin Sun Institute of Information Engineering at Chinese Academy of Sciences; University of Chinese Academy of Sciences, Hongsong Zhu Institute of Information Engineering at Chinese Academy of Sciences; University of Chinese Academy of Sciences14:5010mTalkPoliCond: Condition-Aware Ontology-Driven LLMs for Privacy Policy AnalysisResearch PapersYalin Feng Nanjing University, Yifei Lu State Key Laboratory for Novel Software Technology, Nanjing University, China, Minxue Pan Nanjing University15:0010mTalkUnderstanding Resource Injection Vulnerabilities in Kubernetes EcosystemsResearch PapersDefang Bo Institute of Information Engineering, Chinese Academy of Sciences and School of Cyber Security, University of Chinese Academy of Sciences, Jie Lu Institute of Computing Technology of the Chinese Academy of Sciences, Feng Li Key Laboratory of Network Assessment Technology, Institute of Information Engineering, Chinese Academy of Sciences, China; School of CyberSpace Security at University of Chinese Academy of Sciences, China, Jingting Chen Institute of Information Engineering, Chinese Academy of Sciences and School of Cyber Security, University of Chinese Academy of Sciences, Jinchen Wang Institute of Information Engineering, Chinese Academy of Sciences and School of Cyber Security, University of Chinese Academy of Sciences, Chendong Yu Institute of Information Engineering at Chinese Academy of Sciences; University of Chinese Academy of Sciences, Yeting Li Institute of Information Engineering at Chinese Academy of Sciences; University of Chinese Academy of Sciences, Wei Huo Institute of Information Engineering at Chinese Academy of Sciences15:1010mTalkLLM-Powered Static Binary Taint AnalysisJournal-FirstPuzhuo Liu Ant Group & Tsinghua University, Chengnian Sun University of Waterloo, Yaowen Zheng Institute of Information Engineering at Chinese Academy of Sciences, Xuan Feng Independent Researcher, Chuan Qin Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences, Yuncheng Wang Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, UCAS Beijing, China, Zhenyang Xu University of Waterloo, Zhi Li Institute of Information Engineering, Chinese Academy of Sciences, China, Peng Di Ant Group & UNSW Sydney, Yu Jiang Tsinghua university, Limin Sun Institute of Information Engineering at Chinese Academy of Sciences; University of Chinese Academy of Sciences15:2010mTalkStealthy Backdoor Attack for Code ModelsJournal-FirstZhou Yang University of Alberta, Alberta Machine Intelligence Institute , Bowen Xu North Carolina State University, Jie M. Zhang King's College London, Hong Jin Kang University of Sydney, Jieke Shi Singapore Management University, Junda He Singapore Management University, David Lo Singapore Management UniversityxWed 11 Mar 08:14 ASE 2025 contact formusing conf.researchr.org (v1.73.1) Support pageTracksKeynoteResearch PapersJournal-FirstIndustry ShowcaseNIERTool Demonstration TrackMIP AwardWorkshopsDoctoral SymposiumNew Faculty SymposiumStudent Research CompetitionTutorialsStudent VolunteersPostersTSE Editorial Board MeetingCo-hosted ConferencesAIware 2025WorkshopsA-Mobile 2025AgenticSE 2025AISM 2025ASYDE 2025Code Completion Challenge 2025Ex-ASE 2025Intelligent SE 2025MAS-GAIN 2025VARSE 2025Co-hosted SymposiaSSBSE 2025AttendingVenue: Grand Walkerhill SeoulTransportation to VenueFloor PlanAccommodationsRegistrationVisa LetterHotel Shuttle ServiceDaily MealsAbout SeoulCode of ConductDiversity and Inclusion PlanTravel SupportSign Up