AI-Generated API Test Suites vs Real-World API Vulnerabilities: An Empirical Study

Authors

  • Janhavi Yuvraj Patil Department of Computer Application, G H Raisoni University, Amaravati, India
  • Sachin Laxman Bhangale Department of Computer Application, G H Raisoni University, Amaravati, India
  • Vaishali Shashikant Patil Department of Computer Application, G H Raisoni University, Amaravati, India
  • Bhumika Suresh Patil Department of Computer Application, G H Raisoni University, Amaravati, India

Keywords:

API security, automated test generation, large language models, OWASP API Security Top 10, REST API fuzzing, vulnerability detection, penetration testing.

Abstract

Application Programming Interfaces (APIs) form the backbone of modern distributed systems, yet they remain prime targets for security exploits. While AIpowered test generation tools promise automated, intelligent coverage of API endpoints, their effectiveness against real-world vulnerability classes remains underexplored. This paper presents an empirical study evaluating the detection capabilities of AI-generated API test suites against a curated dataset of real-world API vulnerabilities, including OWASP API Security Top 10 issues such as Broken Object Level Authorization (BOLA), injection flaws, and authentication bypasses. We benchmark multiple AI-driven testing frameworks— including LLM-based payload generators and specification-aware test synthesizers—against vulnerability-oriented inspection tools like VOAPI2 and traditional fuzzers. Our experiments reveal that while AIgenerated tests achieve 60–85% path coverage and reduce manual effort by up to 80%, they systematically miss 30–50% of high-severity, context-dependent vulnerabilities that require stateful request sequences or business-logic exploitation. We identify key failure modes: over-reliance on schema conformance, inability to model multi-step attack chains, and blind spots in authorization boundary testing. Based on these findings, we propose a hybrid testing paradigm that combines AIgenerated breadth with targeted, vulnerability-patterndriven depth, and we release an open benchmark suite of 50+ real-world vulnerable API endpoints for future research. Our results underscore that AI-generated test suites are powerful accelerators but insufficient as standalone security assurance mechanisms for production APIs.

References

Tanveer F, Iradat F, Iqbal W, Ahmad A. Towards secure APIs: A survey on RESTful API vulnerability detection. Computers, Materials & Continua. 2025 Jul 30;84(3):4223-57.

Atlidakis V, Godefroid P, Polishchuk M. Restler: Stateful rest api fuzzing. In2019 IEEE/ACM 41st International Conference on Software Engineering (ICSE) 2019 May 25 (pp. 748-758). IEEE.

Arcuri A. RESTful API automated test case generation with EvoMaster. ACM Transactions on Software Engineering and Methodology (TOSEM). 2019 Jan 9;28(1):1-37.

Arcuri A. Automated black-and white-box testing of restful apis with evomaster. IEEE Software. 2020 Aug 3;38(3):72-8.

Du W, Li J, Wang Y, Chen L, Zhao R, Zhu J, Han Z, Wang Y, Xue Z. Vulnerability-oriented Testing for {RESTful} {APIs}. In33rd USENIX Security Symposium (USENIX Security 24) 2024 (pp. 739-755).

Golmohammadi A, Zhang M, Arcuri A. Testing restful apis: A survey. ACM Transactions on Software Engineering and Methodology. 2023 Nov 24;33(1):1-41.

Ed-Douibi H, Izquierdo JL, Cabot J. Automatic generation of test cases for REST APIs: A specification-based approach. In2018 IEEE 22nd international enterprise distributed object computing conference (EDOC) 2018 Oct 16 (pp. 181-190). IEEE.

Hatfield-Dodds Z, Dygalo D. Deriving semantics- aware fuzzers from web api schemas. arXiv preprint arXiv:2112.10328. 2021 Dec 20.

Hatfield-Dodds Z, Dygalo D. Deriving semantics- aware fuzzers from web api schemas. arXiv preprint arXiv:2112.10328. 2021 Dec 20.

Viglianisi E, Dallago M, Ceccato M. Resttestgen: automated black-box testing of restful apis. In2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST) 2020 Oct 24 (pp. 142-152). IEEE.

Published

2026-09-30