Bridging Coverage and Confidence: Reliable Static False Alarm Elimination via Input-Agnosticity
Jiayi Wang, Yu Wang, Linzhang Wang, Ke Wang
Abstract
Static analysis is a foundational technique for detecting software defects, yet it notoriously suffers from high false positive rates. Prior efforts to reduce false positives via model checking, symbolic execution, dynamic analysis, testing, or machine learning either fail to scale or mistakenly eliminate real defects. This paper presents Rican , a novel approach that leverages dynamic testing to reliably eliminate false alarms in static analysis. The key insight behind Rican is the concept of input-agnosticity : if the validity of an alarm is independent of program inputs along each execution path, then once all such paths from the program entry to the alarm site have been exercised by tests without triggering the alarmed bug, the alarm can be soundly classified as a false positive. To realize this insight, Rican uses a conservative input-agnosticity analysis based on data dependence to identify input-agnostic alarms among all reported alarms. However, validating even input-agnostic alarms requires exploring all feasible paths, which is generally infeasible. To address this, Rican computes a necessary set of paths by identifying only those branches and loops that may influence the alarm’s validity. Finally, Rican eliminates false alarms using existing dynamic testing and post-directed fuzzing to cover these critical paths. We evaluate Rican on six real-world open-source projects using a value-flow-based static analysis front-end. Our experiments show that Rican reliably eliminates 1,313 (45.09%) false positives out of 2,912 double-free, use-after-free, and null-pointer-dereference alarms, without eliminating any real alarms in our evaluation. In addition, Rican incurs negligible overhead beyond the data dependence computed by the underlying analysis. Our user studies further demonstrate that Rican reduces the manual effort required for alarm inspection by over 70% on average and helps programmers find bugs more quickly and accurately, highlighting its practical usefulness in real-world static analysis.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e99dd2f0-bc64-495f-b84b-9bf4b6ab7df1Related papers
- Striking a Balance: Pruning False-Positives from Static Call GraphsAkshay Utture, Shuyang Liu, Christian Gram Kalhauge, Jens PalsbergICSE 2022 · 18 citations
- Statically Discover Cross-Entry Use-After-Free Vulnerabilities in the Linux KernelHang Zhang, Jangha Kim, Chuhong Yuan, Zhiyun Qian et al.NDSS 2025
- Boosting static analysis accuracy with instrumented test executionsTianyi Chen, Kihong Heo, Mukund RaghothamanFSE 2021 · 18 citations
- Learning to Reduce False Positives in Analytic Bug DetectorsAnant Kharkar, Roshanak Zilouchian Moghaddam, Matthew Jin, Xiaoyu Liu et al.ICSE 2022 · 33 citations
- UAFSan: an object-identifier-based dynamic approach for detecting use-after-free vulnerabilitiesBinfa Gui, Wei Song, Jeff HuangISSTA 2021 · 9 citations
