Detecting False Alarms from Automatic Static Analysis Tools: How Far are We?
Hong Jin Kang, Khai Loong Aw, David Lo
Abstract
Automatic static analysis tools (ASATs), such as Findbugs, have a high false alarm rate. The large number of false alarms produced poses a barrier to adoption. Researchers have proposed the use of machine learning to prune false alarms and present only actionable warnings to developers. The state-of-the-art study has identified a set of "Golden Features" based on metrics computed over the characteristics and history of the file, code, and warning. Recent studies show that machine learning using these features is extremely effective and that they achieve almost perfect performance. We perform a detailed analysis to better understand the strong performance of the "Golden Features". We found that several studies used an experimental procedure that results in data leakage and data duplication, which are subtle issues with significant implications. Firstly, the ground-truth labels have leaked into features that measure the proportion of actionable warnings in a given context. Secondly, many warnings in the testing dataset appear in the training dataset. Next, we demonstrate limitations in the warning oracle that determines the ground-truth labels, a heuristic comparing warnings in a given revision to a reference revision in the future. We show the choice of reference revision influences the warning distribution. Moreover, the heuristic produces labels that do not agree with human oracles. Hence, the strong performance of these techniques previously seen is overoptimistic of their true performance if adopted in practice. Our results convey several lessons and provide guidelines for evaluating false alarm detectors. CCS CONCEPTS • Software and its engineering → Software defect analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext afe2bfd5-949c-4e0e-bd47-daa3c7df5b12Cited by top-tier papers20
- Data Quality for Software Vulnerability DatasetsRoland Croft, Muhammad Ali Babar, M. Mehdi KholoosiICSE 2023 · 138 citations
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
- Comparison and Evaluation on Static Application Security Testing (SAST) Tools for JavaKaixuan Li, Sen Chen, Lingling Fan, Ruitao Feng et al.FSE 2023 · 43 citations
- CHRONOS: Time-Aware Zero-Shot Identification of Libraries from Vulnerability ReportsYunbo Lyu, Thanh Le-Cong, Hong Jin Kang, Ratnadira Widyasari et al.ICSE 2023 · 20 citations
- FuzzSlice: Pruning False Positives in Static Analysis Warnings through Function-Level FuzzingAniruddhan Murali, Noble Saji Mathews, Mahmoud Alfadel, Meiyappan Nagappan et al.ICSE 2024 · 9 citations
Builds on3
- Deep just-in-time defect prediction: how far are we?Zhengran Zeng, Yuqun Zhang, Haotian Zhang, Lingming ZhangISSTA 2021 · 97 citations
- Code to Comment "Translation": Data, Metrics, Baselining & EvaluationDavid Gros, Hariharan Sezhiyan, Prem Devanbu, Zhou YuASE 2020 · 43 citations
- Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on ThemMohammad Tahaei, Kami Vaniea, Konstantin Beznosov, Maria K. WoltersCHI 2021 · 35 citations
Related papers
- Actionable Warning Is Not Enough: Recommending Valid Actionable Warnings with Weak SupervisionZhipeng Xue, Zhipeng Gao, Tongtong Xu, Xing Hu et al.ICSE 2026
- Is Call Graph Pruning Really Effective?: An Empirical Re-evaluationMohammad Rafieian, Vlad Birsan, Kunal Katiyar, Dylan Zhong et al.ICSE 2026 · 1 citation
- Striking a Balance: Pruning False-Positives from Static Call GraphsAkshay Utture, Shuyang Liu, Christian Gram Kalhauge, Jens PalsbergICSE 2022 · 18 citations
- Learning to Reduce False Positives in Analytic Bug DetectorsAnant Kharkar, Roshanak Zilouchian Moghaddam, Matthew Jin, Xiaoyu Liu et al.ICSE 2022 · 33 citations
- Data Leakage in Notebooks: Static Detection and Better ProcessesChenyang Yang, Rachel A. Brower-Sinning, Grace A. Lewis, Christian KästnerASE 2022 · 25 citations
