LLM agents paired with rule-based reasoning to find security holes in web APIs automatically. An agent reads live API details, writes attack tests (SQL injection, XSS, broken access control) and improves them after each failed attempt. It found 34% more vulnerabilities than standard scanners and cut manual testing effort by 70%. Published at IEEE AIRC 2026.
OWASP API Security · fuzzing · neuro-symbolic AI