---
格式版本: 2
标题: "SpiderSapien: Client-Centric Web Crawler and Security Scanner"
原文链接: "https://arxiv.org/abs/2609.02532"
发布日期: "2026-09-02"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 2 Sep 2026 12:42:39 UTC (239 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-09-04T01:39:29+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-09-04T01:39:03+08:00"
入库时间: "2026-09-03T17:39:29.749Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=Immersion&searchtype=all"
匹配关键词:
  - "Immersion"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 15
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为Web爬虫与安全扫描，与超节点、AI Rack、液冷等完全无关。命中'Immersion'仅为交互术语，非浸没式液冷。明显无关。"
AI质检模型: "zj-deepseek-v4-flash"
AI质检时间: "2026-09-04T01:40:07+08:00"
AI主题相关性: 0
AI来源权威性: 8
AI新颖性: 2
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 5
AI摘要: "SpiderSapien 提出一种以客户端为中心的 Web 爬虫与安全扫描器，通过沉浸式交互、交互元素检测与 LLM 表单求解，深入探索现代动态 Web 应用。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-04T00:17:34.915Z"
采集批次: "2026年9月3日22点43分34秒"
采集批次ID: "20260903-224334-406"
去重键: "https://arxiv.org/abs/2609.02532"
---

## Computer Science > Cryptography and Security

## Title:SpiderSapien: Client-Centric Web Crawler and Security Scanner

Authors:[Eric Olsson](https://arxiv.org/search/cs?searchtype=author&query=Olsson,+E), [Benjamin Eriksson](https://arxiv.org/search/cs?searchtype=author&query=Eriksson,+B), [Adam Doupé](https://arxiv.org/search/cs?searchtype=author&query=Doup%C3%A9,+A), [Andrei Sabelfeld](https://arxiv.org/search/cs?searchtype=author&query=Sabelfeld,+A)

[View PDF](https://arxiv.org/pdf/2609.02532) [HTML (experimental)](https://arxiv.org/html/2609.02532v1)

> Abstract:Black-box web application crawling and scanning play an important role for security testing of web applications. Yet state-of-the-art scanners fall short of addressing key characteristics of a modern web application: its extreme dynamism and interactivity on the client side. This paper identifies immersive interaction as a key ingredient for scanners to deeply explore modern web applications. We propose SpiderSapien, a client-centric crawler and security scanner. SpiderSapien incorporates a unique combination of high-level, user-facing feedback channels from the web application to achieve immersive interaction in a black-box crawling loop. These feedback channels include both novel methods to detect interactable elements and sensibly order UI interactions, and orthogonally using an LLM to solve forms. In doing so, we demonstrate how to reliably discover and test deep states of modern web applications. Furthermore, our modular approach and useful abstraction layer can serve as a building block for future scanners. The evaluation of our approach shows substantial improvements in both code coverage and vulnerability detection over previous work. Our approach increased average code coverage across applications by at least 46% over any other scanner, or 16% when compared to the union of all other scanners. We find XSS vulnerabilities in 7 web applications, while any other scanner finds XSS in up to 2 applications.

| Subjects: | Cryptography and Security (cs.CR) |
| --- | --- |
| Cite as: | [arXiv:2609.02532](https://arxiv.org/abs/2609.02532) \[cs.CR\] |
|  | (or [arXiv:2609.02532v1](https://arxiv.org/abs/2609.02532v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2609.02532](https://doi.org/10.48550/arXiv.2609.02532) |

## Submission history

From: Eric Olsson \[[view email](https://arxiv.org/show-email/232104e4/2609.02532)\]  
**\[v1\]** Wed, 2 Sep 2026 12:42:39 UTC (239 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2609.02532) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
