On the Real-World Effectiveness of Static Bug Detectors at Finding Null Pointer Exceptions
David A. Tomassi, Cindy Rubio-González
Abstract
Static bug detectors aim at helping developers to automatically find and prevent bugs. In this experience paper, we study the effectiveness of static bug detectors at identifying Null Pointer Dereferences or Null Pointer Exceptions (NPEs). NPEs pervade all programming domains from systems to web development. Specifically, our study measures the effectiveness of five Java static bug detectors: CheckerFramework, ERADICATE, INFER, NULLAWAY, and SPOTBUGS. We conduct our study on 102 real-world and reproducible NPEs from 42 open-source projects found in the BUGSWARM and DEFECTS4J datasets. We apply two known methods to determine whether a bug is found by a given tool, and introduce two new methods that leverage stack trace and code coverage information. Additionally, we provide a categorization of the tool’s capabilities and the bug characteristics to better understand the strengths and weaknesses of the tools. Overall, the tools under study only find 30 out of 102 bugs (29.4%), with the majority found by ERADICATE. Based on our observations, we identify and discuss opportunities to make the tools more effective and useful.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1a50b2d7-c973-40bd-a8cf-3abe2a44622eCited by top-tier papers7
- AutoPruner: transformer-based call graph pruningThanh Le-Cong, Hong Jin Kang, Truong Giang Nguyen, Stefanus Agus Haryono et al.FSE 2022 · 21 citations
- Combining Structured Static Code Information and Dynamic Symbolic Traces for Software Vulnerability PredictionHuanting Wang, Zhanyong Tang, Shin Hwei Tan, Jie Wang et al.ICSE 2024 · 15 citations
- A Comprehensive Study on Quality Assurance Tools for JavaHan Liu, Sen Chen, Ruitao Feng, Chengwei Liu et al.ISSTA 2023 · 12 citations
- Understanding and Detecting Annotation-Induced Faults of Static AnalyzersHuaien Zhang, Yu Pei, Shuyun Liang, Shin Hwei TanFSE 2024 · 4 citations
- Characterizing and Detecting Program Representation Faults of Static Analysis FrameworksHuaien Zhang, Yu Pei, Shuyun Liang, Zezhong Xing et al.ISSTA 2024 · 2 citations
Related papers
- Effective Unit Test Generation for Java Null Pointer ExceptionsMyungho Lee, Jiseong Bak, Seokhyeon Moon, Yoonchan Jhi et al.ASE 2024 · 1 citation
- Practical Inference of Nullability TypesNima Karimipour, Justin Pham, Lazaro Clapp, Manu SridharanFSE 2023 · 6 citations
- Detecting Memory-Related Bugs by Tracking Heap Memory Management of C++ Smart PointersXutong Ma, Jiwei Yan, Wei Wang, Jun Yan et al.ASE 2021 · 10 citations
- Towards Effective Static Type-Error Detection for PythonWonseok Oh, Hakjoo OhASE 2024 · 1 citation
- UnitCon: Synthesizing Targeted Unit Tests for Java Runtime ExceptionsSujin Jang, Yeonhee Ryou, Heewon Lee, Kihong HeoFSE 2025
