MioHint: LLM-Assisted Request Mutation for Whitebox REST API Testing
Jia Li, Jiacheng Shen, Yuxin Su, Michael R. Lyu
Abstract
Cloud applications heavily rely on APIs to communicate with each other and exchange data. To ensure the reliability of cloud applications, cloud providers widely adopt API testing techniques. Unfortunately, existing API testing approaches are insufficient to reach strict conditions, a problem known as fitness plateaus, due to the lack of a gradient provided by coverage metrics. To address this issue, we propose MioHint, a novel white-box API testing approach that leverages the code comprehension capabilities of Large Language Model (LLM) to boost API testing. The key challenge of LLM-based API testing lies in system-level testing, which emphasizes the dependencies between requests and targets across functions and files, thereby making the entire codebase the object of analysis. However, feeding the entire codebase to an LLM is impractical due to its limited context length and short memory. MioHint addresses this challenge by synergizing static analysis with LLMs. We retrieve relevant code with data-dependency analysis at the statement level, including def-use analysis for variables used in the target and function expansion for subfunctions called by the target.
To evaluate the effectiveness of our method, we conducted experiments across 16 real-world REST API services. The findings reveal that MioHint achieves an average increase of 4.95% absolute in line coverage compared to the baseline, EvoMaster, alongside a remarkable factor of 67× improvement in mutation accuracy. Furthermore, our method successfully covers over 57% of hard-to-cover targets, while in the baseline, the coverage is less than 10%.
• Software and its engineering → Software testing and debugging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on14
- Is Your Code Generated by ChatGPT Really Correct? Rigorous Evaluation of Large Language Models for Code GenerationJiawei Liu, Chunqiu Steven Xia, Yuyao Wang, Lingming ZhangNeurIPS 2023 · 2,317 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- CodaMosa: Escaping Coverage Plateaus in Test Generation with Pre-trained Large Language ModelsCaroline Lemieux, Jeevana Priya Inala, Shuvendu K. Lahiri, Siddhartha SenICSE 2023 · 221 citations
- ReACC: A Retrieval-Augmented Code Completion FrameworkShuai Lu, Nan Duan, Hojae Han, Daya Guo et al.ACL 2022 · 208 citations
- Repository-Level Prompt Generation for Large Language Models of CodeDisha Shrivastava, Hugo Larochelle, Daniel TarlowICML 2023 · 184 citations
Related papers
- Improving Test Case Generation for REST APIs Through Hierarchical ClusteringDimitri Michel Stallenberg, Mitchell Olsthoorn, Annibale PanichellaASE 2021 · 32 citations
- SAINT: Service-level Integration Test Generation with Program Analysis and LLM-based AgentsRangeet Pan, Raju Pavuluri, Ruikai Huang, Tyler Stennett et al.ICSE 2026 · 1 citation
- LlamaRestTest: Effective REST API Testing with Small Language ModelsMyeongsoo Kim, Saurabh Sinha, Alessandro OrsoFSE 2025 · 9 citations
- RBCTest: Leveraging LLMs to Mine and Verify Oracles of API Response Bodies for RESTful API TestingHieu Huynh, Quoc-Tri Le, Tu Nguyen, Viet Nguyen et al.ICSE 2026
- TestWeaver: Execution-aware, Feedback-driven Regression Testing Generation with Large Language ModelsCuong Chi Le, Cuong Duc Van, Tung Duy Vu, Minh Vu Thai Pham et al.ICSE 2026 · 1 citation
