arXiv (Cornell University)
Automatic Generation of a Cryptography Misuse Taxonomy Using Large Language Models
September 2025 • Jie Gui, Wenyi Ouyang, Yi Zhang, Liang Cheng, Chen Wu, Wenxin Hu
The prevalence of cryptographic API misuse (CAM) is compromising the effectiveness of cryptography and in turn the security of modern systems and applications. Despite extensive efforts to develop CAM detection tools, these tools typically rely on a limited set of predefined rules from human-curated knowledge. This rigid, rule-based approach hinders adaptation to evolving CAM patterns in real practices. We propose leveraging large language models (LLMs), trained on publicly available cryptography-related data, to …