LibAlchemy: A Two-Layer Persistent Summary Design for Taming Third-Party Libraries in Static Bug-Finding Systems
Rongxin Wu, Yuxuan He, Jiafeng Huang, Chengpeng Wang, Wensheng Tang, Qingkai Shi, Xiao Xiao, Charles Zhang
Abstract
Despite the benefits of using third-party libraries (TPLs), the misuse of TPL functions raises quality and security concerns. Using traditional static analysis to detect bugs caused by TPL function is non-trivial. One promising solution would be to automatically generate and persist the summaries of TPL functions offline and then reuse these summaries in compositional static analysis online. However, when dealing with millions of lines of TPL code, the summaries designed by existing studies suffer from an unresolved paradox. That is, a highly precise form of summary leads to an unaffordable space and time overhead, while an imprecise one seriously hurts its precision or recall.
To address the paradox, we propose a novel two-layer summary design. The first layer utilizes a line-sized program representation known as the program dependence graph to compactly encode path conditions, while the second layer encodes bug-type-specific properties. We implemented our idea as a tool called LibAlchemy and evaluated it on fifteen mature and extensively checked opensource projects. Experimental results show that LibAlchemy can check over ten million lines of code within ten hours. LibAlchemy has detected 55 true bugs with a high precision of 90.16%, eleven of which have been assigned CVE IDs. Compared to whole-program
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Preserving Privacy in Software Composition Analysis: A Study of Technical Solutions and EnhancementsHuaijin Wang, Zhibo Liu, Yanbo Dai, Shuai Wang et al.ICSE 2025 · 2 citations
- Boosting Path-Sensitive Value Flow Analysis Via Removal of Redundant SummariesYongchao Wang, Yuandao Cai, Charles ZhangICSE 2025 · 1 citation
- ProSec: Fortifying Code LLMs with Proactive Security AlignmentXiangzhe Xu, Zian Su, Jinyao Guo, Kaiyuan Zhang et al.ICML 2025
Builds on10
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 388 citations
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu et al.ICSE 2021 · 85 citations
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller et al.ICSE 2020 · 34 citations
- Path-sensitive sparse analysis without path conditionsQingkai Shi, Peisen Yao, Rongxin Wu, Charles ZhangPLDI 2021 · 24 citations
- Chianina: an evolving graph system for flow- and context-sensitive analyses of million lines of C codeZhiqiang Zuo, Yiyu Zhang, Qiuhong Pan, Shenming Lu et al.PLDI 2021 · 18 citations
Related papers
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang et al.ICSE 2023 · 29 citations
- Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at ScaleChengyue Liu, Zhengzi Xu, Kaixuan Li, Jiahui Wu et al.FSE 2026
- An Empirical Study on the Robustness of Android Third-Party Library Detection Tools Against Advanced ObfuscationDahan Pan, Zhuohao Zhang, Yunjia Min, Runhan Feng et al.ICSE 2026
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan et al.USENIX Security 2023
- Enhancing Security in Third-Party Library Reuse - Comprehensive Detection of 1-day Vulnerability through Code Patch AnalysisShangzhi Xu, Jialiang Dong, Weiting Cai, Juanru Li et al.NDSS 2025
