Testing Static Taint Analyzers with Equivalence Modulo Taint
Maria Christakis, Anastasia Isychev, Samuel Pilz, Florian Tesarek, Valentin Wüstholz
Abstract
Static taint analyzers are widely used to detect security vulnerabilities, yet their complexity makes them prone to soundness and precision issues. Validating these analyzers is challenging because ground-truth taint flows are rarely available and differential testing requires multiple comparable tools. To address this challenge, we introduce Equivalence Modulo Taint (EMT), a testing oracle for static taint analysis that defines program equivalence in terms of preserved source-sink flows rather than program semantics. EMT enables testing a single analyzer without ground-truth labels by checking consistency of reported flows across equivalentmodulo-taint program variants. Based on EMT, we present TaintCC, a framework that generates equivalentmodulo-taint variants through semantically equivalent, taint-oblivious, and taint-aware transformations targeting recurring difficulty dimensions in taint analysis. We evaluate TaintCC on four widely used analyzers-FlowDroid, Mariana Trench, Pysa, and Semgrep-and uncover 16 unique developer-confirmed issues, showing that even mature analyzers, whether academic or industrial, remain susceptible to reliability issues.
CCS Concepts: • Software and its engineering → Software testing and debugging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Validating SMT solvers via semantic fusionDominik Winterer, Chengyu Zhang, Zhendong SuPLDI 2020 · 80 citations
- On the unusual effectiveness of type-aware operator mutations for testing SMT solversDominik Winterer, Chengyu Zhang, Zhendong SuOOPSLA 2020 · 55 citations
- GrayC: Greybox Fuzzing of Compilers and Analysers for CKarine Even-Mendoza, Arindam Sharma, Alastair F. Donaldson, Cristian CadarISSTA 2023 · 52 citations
- Detecting critical bugs in SMT solvers using blackbox mutational fuzzingMuhammad Numair Mansur, Maria Christakis, Valentin Wüstholz, Fuyuan ZhangFSE 2020 · 51 citations
- Discovering Flaws in Security-Focused Static Analysis Tools for Android using Systematic MutationRichard Bonett, Kaushal Kafle, Kevin Moran, Adwait Nadkarni et al.USENIX Security 2018 · 35 citations
Related papers
- TRACER: Signature-based Static Analysis for Detecting Recurring VulnerabilitiesWooseok Kang, Byoungho Son, Kihong HeoCCS 2022 · 23 citations
- The impact of tool configuration spaces on the evaluation of configurable taint analysis for AndroidAustin Mordahl, Shiyi WeiISSTA 2021 · 13 citations
- ECSTATIC: An Extensible Framework for Testing and Debugging Configurable Static AnalysisAustin Mordahl, Zenong Zhang, Dakota Soles, Shiyi WeiICSE 2023 · 7 citations
- Detecting Vulnerabilities in Linux-Based Embedded Firmware with SSE-Based On-Demand Alias AnalysisKai Cheng, Yaowen Zheng, Tao Liu, Le Guan et al.ISSTA 2023 · 28 citations
- WhyFlow: Interrogative Debugger for Sensemaking Taint AnalysisBurak Yetistiren, Hong Jin Kang, Miryung KimICSE 2026
