VeriCrypt-Agent: Evidence-Grounded Multi-Agent Verification for Cryptographic Dependency Updates
Cryptographic dependency updates can install cleanly and pass visible regression tests while changing project-facing behavior or leaving an application inside a vulnerable version range. This study presents VeriCrypt-Agent, an evidence-grounded workflow for bounded-autonomy cryptographic maintenance. The system combines a frozen snapshot of release/advisory evidence, a public catalog of project-level executable probes, cross-version execution under old and candidate dependency versions, role-specialized LLM reasoning, and a deterministic decision gate. Automatic merging is allowed only when mandatory probes pass, policy constraints are satisfied, and the audit record is complete. On CryptoUpdate-Mini-30, ten unique package-version transitions are evaluated through 30 controlled executions. Visible tests accept all five non-mergeable transitions, while advisory-only screening accepts two of five. The deterministic All-Probes Gate performs best on this benchmark, with perfect transition-level decisions and no review cases, when all relevant probes are already known and inexpensive. The full workflow observes no unsafe auto-merges (0/5; exact 95% CI: 0.000–0.522) and routes 9/30 executions to review (0.30; exact 95% CI: 0.147–0.494). Removing grounding accepts three of five non-mergeable transitions, and a fixed probe budget accepts two of five. On 48 blinded static crypto-API audit files, including 32 unsafe cases, two-pass review detects 20/32 unsafe cases (0.625; exact 95% CI: 0.437–0.789) and reaches macro-F1 =0.556. These point estimates characterize evidence-backed release decisions only under the evaluated conditions; they do not establish general superiority over exhaustive deterministic testing or a deployable static vulnerability detector.
Authors
- А. С. Бородулин (ORCID: https://orcid.org/0000-0002-9648-2395)
- В С Тынченко (ORCID: https://orcid.org/0000-0002-3959-2969)
- Vladimir Nelyub (ORCID: https://orcid.org/0000-0003-4263-2367)
- Andrei Gantimurov (ORCID: https://orcid.org/0009-0001-4246-9742)
- Ivan Pavlovich Malashin (ORCID: https://orcid.org/0009-0008-8986-402X)
- Dmitry Martysyuk (ORCID: https://orcid.org/0000-0002-1563-4036)
Institutions
- Bauman Moscow State Technical University (RU)
Publication Details
- Journal
- Computers
- Published
- 2026-09-21
- DOI
- https://doi.org/10.3390/computers15090638
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00