Recovering fitness gradients for interprocedural Boolean flags in search-based testing
Yun Lin, Jun Sun, Gordon Fraser, Ziheng Xiu, Ting Liu, Jin Song Dong
摘要
In Search-based Software Testing (SBST), test generation is guided by fitness functions that estimate how close a test case is to reach an uncovered test goal (e.g., branch). A popular fitness function estimates how close conditional statements are to evaluating to true or false, i.e., the branch distance. However, when conditions read Boolean variables (e.g., if(x && y)), the branch distance provides no gradient for the search, since a Boolean can either be true or false. This flag problem can be addressed by transforming individual procedures such that Boolean flags are replaced with numeric comparisons that provide better guidance for the search. Unfortunately, defining a semantics-preserving transformation that is applicable in an interprocedural case, where Boolean flags are passed around as parameters and return values, is a daunting task. Thus, it is not yet supported by modern test generators. This work is based on the insight that fitness gradients can be recovered by using runtime information: Given an uncovered interprocedural flag branch, our approach (1) calculates context-sensitive branch distance for all control flows potentially returning the required flag in the called method, and (2) recursively aggregates these distances into a continuous value. We implemented our approach on top of the EvoSuite framework for Java, and empirically compared it with state-of-the-art testability transformations on 807 non-trivial methods suffering from interprocedural flag problems, sampled from 150 open source Java projects. Our experiment demonstrates that our approach achieves higher coverage on the subject methods with statistical significance and acceptable runtime overheads. CCS CONCEPTS • Software and its engineering → Software testing and debugging; Search-based software engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- CodaMosa: Escaping Coverage Plateaus in Test Generation with Pre-trained Large Language ModelsCaroline Lemieux, Jeevana Priya Inala, Shuvendu K. Lahiri, Siddhartha SenICSE 2023 · 被引用 221 次
- Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing WebpagesYun Lin, Ruofan Liu, Dinil Mon Divakaran, Jun Yang Ng 等USENIX Security 2021 · 被引用 164 次
- Cross-Contract Static Analysis for Detecting Practical Reentrancy Vulnerabilities in Smart ContractsYinxing Xue, Mingliang Ma, Yun Lin, Yulei Sui 等ASE 2020 · 被引用 77 次
- Graph-based seed object synthesis for search-based unit testingYun Lin, You Sheng Ong, Jun Sun, Gordon Fraser 等FSE 2021 · 被引用 34 次
- MC2: Rigorous and Efficient Directed Greybox FuzzingAbhishek Shah, Dongdong She, Samanway Sadhu, Krish Singal 等CCS 2022 · 被引用 15 次
它引用的顶会 Paper3
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin 等ICSE 2020 · 被引用 260 次
- Typestate-guided fuzzer for discovering use-after-free vulnerabilitiesHaijun Wang, Xiaofei Xie, Yi Li, Cheng Wen 等ICSE 2020 · 被引用 107 次
- Time-travel testing of Android appsZhen Dong, Marcel Böhme, Lucia Cojocaru, Abhik RoychoudhuryICSE 2020 · 被引用 104 次
相关 Paper
- Increasing the Effectiveness of Automatically Generated Tests by Improving Class ObservabilityGeraldine Galindo-Gutierrez, Juan Pablo Sandoval Alcocer, Nicolas Jimenez-Fuentes, Alexandre Bergel 等ICSE 2025 · 被引用 1 次
- Defect Prediction Guided Search-Based Software TestingAnjana Perera, Aldeida Aleti, Marcel Böhme, Burak TurhanASE 2020 · 被引用 16 次
- Selectively Combining Multiple Coverage Goals in Search-Based Unit Test GenerationZhichao Zhou, Yuming Zhou, Chunrong Fang, Zhenyu Chen 等ASE 2022 · 被引用 8 次
- API-Knowledge Aware Search-Based Software Testing: Where, What, and HowXiaoxue Ren, Xinyuan Ye, Yun Lin, Zhenchang Xing 等FSE 2023 · 被引用 4 次
- June: A Type Testability Transformation for Improved ATG PerformanceDan Bruce, David A. Kelly, Héctor D. Menéndez, Earl T. Barr 等ISSTA 2023 · 被引用 1 次
