Fuzzing Class Specifications
Facundo Molina, Marcelo d'Amorim, Nazareno Aguirre
摘要
Expressing class specifications via executable constraints is important for various software engineering tasks such as test generation, bug finding and automated debugging, but developers rarely write them. Techniques that infer specifications from code exist to fill this gap, but they are designed to support specific kinds of assertions and are difficult to adapt to support different assertion languages, e.g., to add support for quantification, or additional comparison operators, such as membership or containment. To address the above issue, we present SpecFuzzer, a novel technique that combines grammar-based fuzzing, dynamic invariant detection, and mutation analysis, to automatically produce class specifications. SpecFuzzer uses: (i) a fuzzer as a generator of candidate assertions derived from a grammar that is automatically obtained from the class definition; (ii) a dynamic invariant detector -Daikon-to filter out assertions invalidated by a test suite; and (iii) a mutation-based mechanism to cluster and rank assertions, so that similar constraints are grouped and then the stronger prioritized. Grammar-based fuzzing enables SpecFuzzer to be straightforwardly adapted to support different specification languages, by manipulating the fuzzing grammar, e.g., to include additional operators. We evaluate our technique on a benchmark of 43 Java methods employed in the evaluation of the state-of-the-art techniques GAssert and EvoSpex. Our results show that SpecFuzzer can easily support a more expressive assertion language, over which is more effective than GAssert and EvoSpex in inferring specifications, according to standard performance metrics.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Enchanting Program Specification Synthesis by Large Language Models Using Static Analysis and Program VerificationCheng Wen, Jialun Cao, Jie Su, Zhiwu Xu 等CAV 2024 · 被引用 60 次
- SpecGen: Automated Generation of Formal Program Specifications via Large Language ModelsLezhi Ma, Shangqing Liu, Yi Li, Xiaofei Xie 等ICSE 2025 · 被引用 25 次
- Perfect is the enemy of test oracleAli Reza Ibrahimzada, Yigit Varli, Dilara Tekinoglu, Reyhaneh JabbarvandFSE 2022 · 被引用 23 次
- AGORA: Automated Generation of Test Oracles for REST APIsJuan C. Alonso, Sergio Segura, Antonio Ruiz-CortésISSTA 2023 · 被引用 15 次
- A Generative and Mutational Approach for Synthesizing Bug-Exposing Test Cases to Guide Compiler FuzzingGuixin Ye, Tianmin Hu, Zhanyong Tang, Zhenye Fan 等FSE 2023 · 被引用 14 次
它引用的顶会 Paper3
- On learning meaningful assert statements for unit test casesCody Watson, Michele Tufano, Kevin Moran, Gabriele Bavota 等ICSE 2020 · 被引用 96 次
- Evolutionary improvement of assertion oraclesValerio Terragni, Gunel Jahangirova, Paolo Tonella, Mauro PezzèFSE 2020 · 被引用 50 次
- EvoSpex: An Evolutionary Algorithm for Learning PostconditionsFacundo Molina, Pablo Ponzio, Nazareno Aguirre, Marcelo F. FriasICSE 2021
相关 Paper
- GRIMOIRE: Synthesizing Structure while FuzzingTim Blazytko, Cornelius Aschermann, Moritz Schlögel, Ali Abbasi 等USENIX Security 2019 · 被引用 123 次
- Testing the Compiler for a New-Born Programming Language: An Industrial Case Study (Experience Paper)Yingquan Zhao, Junjie Chen, Ruifeng Fu, Haojie Ye 等ISSTA 2023 · 被引用 9 次
- Fuzzing Java Optimizing Compilers with Complex Inter-Class Structures Guided by Heterogeneous Program GraphsShiyu Qiu, Ming Wen, Zifan Xie, Hai JinICSE 2026
- GraphFuzz: Library API Fuzzing with Lifetime-aware Dataflow GraphsHarrison Green, Thanassis AvgerinosICSE 2022 · 被引用 38 次
- SJFuzz: Seed and Mutator Scheduling for JVM FuzzingMingyuan Wu, Yicheng Ouyang, Minghai Lu, Junjie Chen 等FSE 2023 · 被引用 14 次
