API-Misuse Detection Driven by Fine-Grained API-Constraint Knowledge Graph
Xiaoxue Ren, Xinyuan Ye, Zhenchang Xing, Xin Xia, Xiwei Xu, Liming Zhu, Jianling Sun
Abstract
API misuses cause significant problem in software development. Existing methods detect API misuses against frequent API usage patterns mined from codebase. They make a naive assumption that API usage that deviates from the most-frequent API usage is a misuse. However, there is a big knowledge gap between API usage patterns and API usage caveats in terms of comprehensiveness, explainability and best practices. In this work, we propose a novel approach that detects API misuses directly against the API caveat knowledge, rather than API usage patterns. We develop open information extraction methods to construct a novel API-constraint knowledge graph from API reference documentation. This knowledge graph explicitly models two types of API-constraint relations (call-order and condition-checking) and enriches return and throw relations with return conditions and exception triggers. It empowers the detection of three types of frequent API misuses - missing calls, missing condition checking and missing exception handling, while existing detectors mostly focus on only missing calls. As a proof-of-concept, we apply our approach to Java SDK API Specification. Our evaluation confirms the high accuracy of the extracted API-constraint relations. Our knowledge-driven API misuse detector achieves 0.60 (68/113) precision and 0.28 (68/239) recall for detecting Java API misuses in the API misuse benchmark MuBench. This performance is significantly higher than that of existing pattern-based API misused detectors. A pilot user study with 12 developers shows that our knowledge-driven API misuse detection is very promising in helping developers avoid API misuses and debug the bugs caused by API misuses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers18
- CLEAR: Contrastive Learning for API RecommendationMoshi Wei, Nima Shiri Harzevili, Yuchao Huang, Junjie Wang et al.ICSE 2022 · 43 citations
- Prompt-tuned Code Language Model as a Neural Knowledge Base for Type Inference in Statically-Typed Partial CodeQing Huang, Zhiqiang Yuan, Zhenchang Xing, Xiwei Xu et al.ASE 2022 · 40 citations
- From Misuse to Mastery: Enhancing Code Generation with Knowledge-Driven AI ChainingXiaoxue Ren, Xinyuan Ye, Dehai Zhao, Zhenchang Xing et al.ASE 2023 · 28 citations
- Mining Android API Usage to Generate Unit Test Cases for Pinpointing Compatibility IssuesXiaoyu Sun, Xiao Chen, Yanjie Zhao, Pei Liu et al.ASE 2022 · 16 citations
- Conflict-aware Inference of Python Compatible Runtime Environments with Domain Knowledge GraphWei Cheng, Xiangrong Zhu, Wei HuICSE 2022 · 16 citations
Builds on2
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Demystify official API usage directives with crowdsourced API misuse scenarios, erroneous code examples and patchesXiaoxue Ren, Jiamou Sun, Zhenchang Xing, Xin Xia et al.ICSE 2020 · 28 citations
Related papers
- API Misuse Detection via Probabilistic Graphical ModelYunlong Ma, Wentong Tian, Xiang Gao, Hailong Sun et al.ISSTA 2024 · 1 citation
- APP-Miner: Detecting API Misuses via Automatically Mining API Path PatternsJiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo et al.S&P 2024 · 8 citations
- SFA-Miner: Mining Path-Sensitive API Usage Patterns Via Symbolic Finite AutomataJiasheng Jiang, Mingwei Zheng, Qingkai Shi, Xiangyu ZhangS&P 2026 · 1 citation
- Patch-Guided Vulnerability Detection: Extracting Java API Security Rules via Attack–Defense Cross-AnalysisBofei Chen, Shuang Liao, Lei Zhang, Chibin Zhang et al.USENIX Security 2026
- APICAD: Augmenting API Misuse Detection through Specifications from Code and DocumentsXiaoke Wang, Lei ZhaoICSE 2023 · 7 citations
