Validating SMT Solvers via Skeleton Enumeration Empowered by Historical Bug-Triggering Inputs
Maolin Sun, Yibiao Yang, Ming Wen, Yongcong Wang, Yuming Zhou, Hai Jin
摘要
SMT solvers check the satisfiability of logic formulas over first-order theories, which have been utilized in a rich number of critical applications, such as software verification, test case generation, and program synthesis. Bugs hidden in SMT solvers would severely mislead those applications and further cause severe consequences. Therefore, ensuring the reliability and robustness of SMT solvers is of critical importance. Although many approaches have been proposed to test SMT solvers, it is still a challenge to discover bugs effectively. To tackle such a challenge, we conduct an empirical study on the historical bug-triggering formulas in SMT solvers' bug tracking systems. We observe that the historical bug-triggering formulas contain valuable skeletons (i.e., core structures of formulas) as well as associated atomic formulas which can cast significant impacts on formulas' ability in triggering bugs. Therefore, we propose a novel approach that utilizes the skeletons extracted from the historical bug-triggering formulas and enumerates atomic formulas under the guidance of association rules derived from historical formulas. In this study, we realized our approach as a practical fuzzing tool HistFuzz and conducted extensive testing on the well-known SMT solvers Z3 and cvc5. To date, HistFuzz has found 111 confirmed new bugs for Z3 and cvc5, of which 108 have been fixed by the developers. More notably, out of the confirmed bugs, 23 are soundness bugs and invalid model bugs found in the solvers' default mode, which are essential for SMT solvers. In addition, our experiments also demonstrate that HistFuzz outperforms the state-of-the-art SMT solver fuzzers in terms of achieved code coverage and effectiveness.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Clozemaster: Fuzzing Rust Compiler by Harnessing Llms for Infilling Masked Real ProgramsHongyan Gao, Yibiao Yang, Maolin Sun, Jiangchang Wu 等ICSE 2025 · 被引用 6 次
- Heterogeneous Testing for Coverage Profilers Empowered with Debugging SupportYibiao Yang, Maolin Sun, Yang Wang, Qingyang Li 等FSE 2023 · 被引用 3 次
- Once4All: Skeleton-Guided SMT Solver Fuzzing with LLM-Synthesized GeneratorsMaolin Sun, Yibiao Yang, Yuming ZhouASPLOS 2026 · 被引用 1 次
- SpecBCFuzz: Fuzzing LTL Solvers with Boundary ConditionsLuiz Carvalho, Renzo Degiovanni, Maxime Cordy, Nazareno Aguirre 等ICSE 2024 · 被引用 1 次
它引用的顶会 Paper12
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao 等S&P 2022 · 被引用 139 次
- Validating SMT solvers via semantic fusionDominik Winterer, Chengyu Zhang, Zhendong SuPLDI 2020 · 被引用 80 次
- On the unusual effectiveness of type-aware operator mutations for testing SMT solversDominik Winterer, Chengyu Zhang, Zhendong SuOOPSLA 2020 · 被引用 55 次
- History-Driven Test Program Synthesis for JVM TestingYingquan Zhao, Zan Wang, Junjie Chen, Mengdi Liu 等ICSE 2022 · 被引用 51 次
- Detecting critical bugs in SMT solvers using blackbox mutational fuzzingMuhammad Numair Mansur, Maria Christakis, Valentin Wüstholz, Fuyuan ZhangFSE 2020 · 被引用 51 次
相关 Paper
- SMT Solver Validation Empowered by Large Pre-Trained Language ModelsMaolin Sun, Yibiao Yang, Yang Wang, Ming Wen 等ASE 2023 · 被引用 23 次
- Fuzzing SMT solvers via two-dimensional input space explorationPeisen Yao, Heqing Huang, Wensheng Tang, Qingkai Shi 等ISSTA 2021 · 被引用 18 次
- Skeletal approximation enumeration for SMT solver testingPeisen Yao, Heqing Huang, Wensheng Tang, Qingkai Shi 等FSE 2021 · 被引用 20 次
- Generative type-aware mutation for testing SMT solversJiwon Park, Dominik Winterer, Chengyu Zhang, Zhendong SuOOPSLA 2021 · 被引用 31 次
- Diver: Oracle-Guided SMT Solver Testing with Unrestricted Random MutationsJongwook Kim, Sunbeom So, Hakjoo OhICSE 2023 · 被引用 7 次
