Tailoring programs for static analysis via program transformation
Rijnard van Tonder, Claire Le Goues
Abstract
Static analysis is a proven technique for catching bugs during software development. However, analysis tooling must approximate, both theoretically and in the interest of practicality. False positives are a pervading manifestation of such approximations---tool configuration and customization is therefore crucial for usability and directing analysis behavior. To suppress false positives, developers readily disable bug checks or insert comments that suppress spurious bug reports. Existing work shows that these mechanisms fall short of developer needs and present a significant pain point for using or adopting analyses. We draw on the insight that an analysis user always has one notable ability to influence analysis behavior regardless of analyzer options and implementation: modifying their program. We present a new technique for automated, generic, and temporary code changes that tailor to suppress spurious analysis errors. We adopt a rule-based approach where simple, declarative templates describe general syntactic changes for code patterns that are known to be problematic for the analyzer. Our technique promotes program transformation as a general primitive for improving the fidelity of analysis reports (we treat any given analyzer as a black box). We evaluate using five different static analyzers supporting three different languages (C, Java, and PHP) on large, real world programs (up to 800KLOC). We show that our approach is effective in sidestepping long-standing and complex issues in analysis implementations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b0df52b7-1d3b-4d92-82d1-78cb1ab3a5f3Cited by top-tier papers8
- Statfier: Automated Testing of Static Analyzers via Semantic-Preserving Program TransformationsHuaien Zhang, Yu Pei, Junjie Chen, Shin Hwei TanFSE 2023 · 15 citations
- Detecting Memory-Related Bugs by Tracking Heap Memory Management of C++ Smart PointersXutong Ma, Jiwei Yan, Wei Wang, Jun Yan et al.ASE 2021 · 10 citations
- CodeImprove: Program Adaptation for Deep Code ModelsRavishka Rathnasuriya, Zijie Zhao, Wei YangICSE 2025 · 3 citations
- An Empirical Study of Suppressed Static Analysis WarningsHuimin Hu, Yingying Wang, Julia Rubin, Michael PradelFSE 2025 · 1 citation
- SemRep : Generative Code Representation Learning with Code TransformationsWeichen Li, Jiamin Song, Bogdan Stoica, Arav Dhoot et al.ICML 2026
Builds on1
Related papers
- Striking a Balance: Pruning False-Positives from Static Call GraphsAkshay Utture, Shuyang Liu, Christian Gram Kalhauge, Jens PalsbergICSE 2022 · 18 citations
- Automatically Tailoring Abstract Interpretation to Custom Usage ScenariosMuhammad Numair Mansur, Benjamin Mariano, Maria Christakis, Jorge A. Navas et al.CAV 2021 · 5 citations
- Learning to Reduce False Positives in Analytic Bug DetectorsAnant Kharkar, Roshanak Zilouchian Moghaddam, Matthew Jin, Xiaoyu Liu et al.ICSE 2022 · 33 citations
- A large-scale study of usability criteria addressed by static analysis toolsMarcus Nachtigall, Michael Schlichtig, Eric BoddenISSTA 2022 · 38 citations
- Understanding and Detecting Annotation-Induced Faults of Static AnalyzersHuaien Zhang, Yu Pei, Shuyun Liang, Shin Hwei TanFSE 2024 · 4 citations
