API-Misuse Detection Driven by Fine-Grained API-Constraint Knowledge Graph
Xiaoxue Ren, Xinyuan Ye, Zhenchang Xing, Xin Xia, Xiwei Xu, Liming Zhu, Jianling Sun
摘要
API misuses cause significant problem in software development. Existing methods detect API misuses against frequent API usage patterns mined from codebase. They make a naive assumption that API usage that deviates from the most-frequent API usage is a misuse. However, there is a big knowledge gap between API usage patterns and API usage caveats in terms of comprehensiveness, explainability and best practices. In this work, we propose a novel approach that detects API misuses directly against the API caveat knowledge, rather than API usage patterns. We develop open information extraction methods to construct a novel API-constraint knowledge graph from API reference documentation. This knowledge graph explicitly models two types of API-constraint relations (call-order and condition-checking) and enriches return and throw relations with return conditions and exception triggers. It empowers the detection of three types of frequent API misuses - missing calls, missing condition checking and missing exception handling, while existing detectors mostly focus on only missing calls. As a proof-of-concept, we apply our approach to Java SDK API Specification. Our evaluation confirms the high accuracy of the extracted API-constraint relations. Our knowledge-driven API misuse detector achieves 0.60 (68/113) precision and 0.28 (68/239) recall for detecting Java API misuses in the API misuse benchmark MuBench. This performance is significantly higher than that of existing pattern-based API misused detectors. A pilot user study with 12 developers shows that our knowledge-driven API misuse detection is very promising in helping developers avoid API misuses and debug the bugs caused by API misuses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper18
- CLEAR: Contrastive Learning for API RecommendationMoshi Wei, Nima Shiri Harzevili, Yuchao Huang, Junjie Wang 等ICSE 2022 · 被引用 43 次
- Prompt-tuned Code Language Model as a Neural Knowledge Base for Type Inference in Statically-Typed Partial CodeQing Huang, Zhiqiang Yuan, Zhenchang Xing, Xiwei Xu 等ASE 2022 · 被引用 40 次
- From Misuse to Mastery: Enhancing Code Generation with Knowledge-Driven AI ChainingXiaoxue Ren, Xinyuan Ye, Dehai Zhao, Zhenchang Xing 等ASE 2023 · 被引用 28 次
- Mining Android API Usage to Generate Unit Test Cases for Pinpointing Compatibility IssuesXiaoyu Sun, Xiao Chen, Yanjie Zhao, Pei Liu 等ASE 2022 · 被引用 16 次
- Conflict-aware Inference of Python Compatible Runtime Environments with Domain Knowledge GraphWei Cheng, Xiangrong Zhu, Wei HuICSE 2022 · 被引用 16 次
它引用的顶会 Paper2
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- Demystify official API usage directives with crowdsourced API misuse scenarios, erroneous code examples and patchesXiaoxue Ren, Jiamou Sun, Zhenchang Xing, Xin Xia 等ICSE 2020 · 被引用 28 次
相关 Paper
- API Misuse Detection via Probabilistic Graphical ModelYunlong Ma, Wentong Tian, Xiang Gao, Hailong Sun 等ISSTA 2024 · 被引用 1 次
- APP-Miner: Detecting API Misuses via Automatically Mining API Path PatternsJiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo 等S&P 2024 · 被引用 8 次
- SFA-Miner: Mining Path-Sensitive API Usage Patterns Via Symbolic Finite AutomataJiasheng Jiang, Mingwei Zheng, Qingkai Shi, Xiangyu ZhangS&P 2026 · 被引用 1 次
- Patch-Guided Vulnerability Detection: Extracting Java API Security Rules via Attack–Defense Cross-AnalysisBofei Chen, Shuang Liao, Lei Zhang, Chibin Zhang 等USENIX Security 2026
- APICAD: Augmenting API Misuse Detection through Specifications from Code and DocumentsXiaoke Wang, Lei ZhaoICSE 2023 · 被引用 7 次
