Skip to content
LyraShield AIOpen beta

Research

Security patterns in AI-built applications

Original research from LyraShield AI scans. All statistics are derived from anonymized, privacy-safe scan metadata — no target names, repository URLs, finding payloads, user identities, or IP addresses are published.

Last updated:

Research in progress. This page will be populated with statistics once a sufficient sample of anonymized scan data is available. The framework below describes what we plan to publish and how the data is collected and privacy-protected.

Research methodology

Data source
Scan metadata from authorized LyraShield AI scans. Only scans where the target owner authorized analysis are included.
Privacy protection
All data is anonymized before aggregation. No target names, repository URLs, finding payloads, user identities, IP addresses, or raw source code are retained for research purposes.
Sample size
Statistics are only published when the underlying sample is large enough to be statistically meaningful. The minimum sample size is stated with each finding.
Reproducibility
The Vibe Security 50 control registry is versioned and public. The evidence-state definitions are published on the methodology page. Research results cite the control version used.

Planned research areas

Most common vulnerability classes in AI-built apps

Distribution of finding categories across the Vibe Security 50 controls. Which controls most frequently produce detected candidates, and which most frequently produce verified findings.

Evidence-state distribution

What fraction of detected candidates are independently verified? What fraction of verified findings are retest-confirmed after a fix? How many remain inconclusive?

Coverage gaps

Which of the 7 evidence-required controls most frequently lack operational or human evidence outside the scan? Which of the 43 code/URL review controls most frequently return inconclusive?

Fix proposal outcomes

When a fix proposal is generated and applied, how often does the retest confirm the condition is absent? How often does it remain inconclusive? This measures the effectiveness of the fix-then-retest loop.

Scan mode comparison

How do finding rates, coverage, and evidence-state distributions differ across scan modes? Are there control categories where deeper analysis consistently produces more verified findings?

Citing this research

When published, statistics on this page may be cited as: "LyraShield AI, [report name], lyrashieldai.com/research, [access date]." Each statistic includes its sample size, control version, and collection period. Do not cite a statistic without including its stated limitations.

Put this research to work on your own app.

Registration is open in the beta. New research is published to the guides feed.