Lune

ISSTA2026Top-tier venue

Testing Static Taint Analyzers with Equivalence Modulo Taint

Maria Christakis, Anastasia Isychev, Samuel Pilz, Florian Tesarek, Valentin Wüstholz

2026Year

Abstract

Static taint analyzers are widely used to detect security vulnerabilities, yet their complexity makes them prone to soundness and precision issues. Validating these analyzers is challenging because ground-truth taint flows are rarely available and differential testing requires multiple comparable tools. To address this challenge, we introduce Equivalence Modulo Taint (EMT), a testing oracle for static taint analysis that defines program equivalence in terms of preserved source-sink flows rather than program semantics. EMT enables testing a single analyzer without ground-truth labels by checking consistency of reported flows across equivalentmodulo-taint program variants. Based on EMT, we present TaintCC, a framework that generates equivalentmodulo-taint variants through semantically equivalent, taint-oblivious, and taint-aware transformations targeting recurring difficulty dimensions in taint analysis. We evaluate TaintCC on four widely used analyzers-FlowDroid, Mariana Trench, Pysa, and Semgrep-and uncover 16 unique developer-confirmed issues, showing that even mature analyzers, whether academic or industrial, remain susceptible to reliability issues.

CCS Concepts: • Software and its engineering → Software testing and debugging.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Builds on18

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines