[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84001-en":3,"doc-seo-84001-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84001,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Detecting Vulnerability-Inducing Commits via Multi-Stage Reasoning with LLM-Based Agents","Detecting vulnerability-inducing commits (VICs) at submission time is essential for improving software security and reliability, yet it is difficult because it demands semantic reasoning over code diffs, commit messages, and surrounding contextual code. The paper proposes VIC-RAGENT, an LLM-based multi-agent framework designed for effective and explainable vulnerability detection. Specialized agents support structural analysis, intent understanding, and vulnerability inspection, while a multi-stage reasoning pipeline progressively refines candidates through inspection, reanalysis, and final decision. Experiments on a real-world dataset show consistent F1 improvements over Direct, CoT, and CodeAgent.","arXiv :2607 .05772v 1 [ cs . SE] 7 Jul 2026  \nDetecting Vulnerability-Inducing Commits via Multi-Stage Reasoning with LLM-Based Agents  \nLiyou Chen 1 , Hailong Sun 1 ,2,⋆, Xiang Gao 1 ,2,⋆, and Yue Pan3  \n1 State Key Laboratory of Complex & Critical Software Environment (CCSE), Beihang University, Beijing, [China.](China. chenliyou@buaa.edu.cn)[ chenliyou@buaa.edu.cn](China. chenliyou@buaa.edu.cn)  \n2 Hangzhou Innovation Institute of Beihang University, Hangzhou, Zhejiang, China.  \n[sunhl@buaa.edu.cn](sunhl@buaa.edu.cn), [xiang_gao@buaa.edu.cn](xiang_gao@buaa.edu.cn)  \n3 North China Municipal Engineering Design & Research Institute Co. , Ltd. , Beijing, [China.](China. loveangel_3344@yeah.net)[ loveangel_3344@yeah.net](China. loveangel_3344@yeah.net)  \nAbstract. Detecting vulnerability-inducing commits (VICs) at submission time is critical for improving the security and reliability of software systems. However, this task is highly challenging because it requires reasoning about the semantic impact of code changes from heterogeneous information sources, including code diffs, commit messages, and the surrounding contextual code. Existing approaches often struggle to fully capture these complex interactions, resulting in limited detection performance. In this paper, we propose VIC-RAGENT, an LLM-based multiagent framework for effective and explainable vulnerability detection.  \nVIC-RAGENT leverages multiple specialized agents to provide complementary perspectives, including structural analysis, intent understanding, and vulnerability inspection. To further improve detection reliability, the framework employs a multi-stage reasoning process that progressively refines candidate vulnerabilities through preliminary inspection, reanalysis, and a final decision stage. Experimental results on a real-world dataset across multiple LLMs demonstrate that VIC-RAGENT consistently outperforms baselines, including Direct, CoT, and CodeAgent.  \nCompared to the strongest baseline, VIC-RAGENT achieves 1.2–1.7 × higher F1-scores across different models. Overall, VIC-RAGENT offers a robust, explainable, and practical solution for detecting VICs in modern software development workflows.  \nKeywords: vulnerability-inducing commits · just-in-time vulnerability detection · large language models · software security.  \n1 Introduction  \nOpen source software (OSS) has become fundamental infrastructure for modern software systems [25, 5], but its collaborative development model enlarges the software supply chain attack surface [29] . In large-scale projects with continuous integration, even minor code changes may unintentionally introduce exploitable  \n⋆ Corresponding authors  \n2 Chen et al.  \nweaknesses [12] . Prior studies [28, 12] show that many vulnerabilities originate from vulnerability-inducing commits (VICs) [2], which introduce security flaws during routine development activities such as feature additions and refactoring [10, 35] .  \nDetecting whether a newly submitted commit introduces a vulnerability—known as Just-In-Time Vulnerability Detection (JIT-VD) [21]—remains a challenging task. JIT-VD aims to detect whether a commit introduces vulnerabilities based on code changes and contextual information. Existing approaches include feature-based methods and deep learning models [26, 36], but they struggle to capture commit semantics and developer intent. To address these limitations, deep learning approaches have been proposed to learn representations from code and diffs, including neural vulnerability detection systems [16, 15], graph-based models [40, 3], and transformer-based models [8] . More recently, JIT-specific models [21, 31] attempt to capture the semantics of code changes.  \nRecent advances in LLMs have demonstrated strong capabilities in code understanding and reasoning [34, 23, 37] . LLM-based approaches have been applied to vulnerability detection and software security analysis [19, 39, 33], including prompt-based methods and retrieval-au","cbCaipeWqC1yu31V","https://ap.wps.com/l/cbCaipeWqC1yu31V","pdf",425658,4,1,16,"English","en",105,"# Introduction\n## Problem Definition\n## Related Work\n# Method Overview\n## VIC-RAGENT Multi-Stage Reasoning Framework\n## Multi-Agent Workflow\n# Evaluation","[{\"question\":\"What problem does VIC-RAGENT address?\",\"answer\":\"It addresses just-in-time vulnerability detection by identifying vulnerability-inducing commits (VICs) from newly submitted changes, using code diffs, commit messages, and contextual code.\"},{\"question\":\"How does VIC-RAGENT improve detection reliability?\",\"answer\":\"It uses multiple role-specialized agents and a multi-stage reasoning process that refines candidate vulnerabilities through preliminary inspection, reanalysis, and a final decision stage.\"},{\"question\":\"How does VIC-RAGENT perform compared with existing baselines?\",\"answer\":\"Experiments on a real-world dataset across multiple LLMs show VIC-RAGENT consistently outperforms baselines such as Direct, CoT, and CodeAgent, achieving 1.2–1.7× higher F1-scores than the strongest baseline.\"}]",1784191954,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"detecting-vulnerability-inducing-commits-via-multi-stage-reasoning-with-llm-based-agents","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/detecting-vulnerability-inducing-commits-via-multi-stage-reasoning-with-llm-based-agents/84001/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does VIC-RAGENT address?","Question",{"text":75,"@type":76},"It addresses just-in-time vulnerability detection by identifying vulnerability-inducing commits (VICs) from newly submitted changes, using code diffs, commit messages, and contextual code.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does VIC-RAGENT improve detection reliability?",{"text":80,"@type":76},"It uses multiple role-specialized agents and a multi-stage reasoning process that refines candidate vulnerabilities through preliminary inspection, reanalysis, and a final decision stage.",{"name":82,"@type":73,"acceptedAnswer":83},"How does VIC-RAGENT perform compared with existing baselines?",{"text":84,"@type":76},"Experiments on a real-world dataset across multiple LLMs show VIC-RAGENT consistently outperforms baselines such as Direct, CoT, and CodeAgent, achieving 1.2–1.7× higher F1-scores than the strongest baseline.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]