Detecting Simulink compiler bugs via controllable zombie blocks mutation
Shikai Guo, He Jiang, Zhihao Xu, Xiaochen Li, Zhilei Ren, Zhide Zhou, Rong Chen
摘要
As a popular Cyber-Physical System (CPS) development tool chain, MathWorks Simulink is widely used to prototype CPS models in safety-critical applications, e.g., aerospace and healthcare. It is crucial to ensure the correctness and reliability of Simulink compiler (i.e., the compiler module of Simulink) in practice since all CPS models depend on compilation. However, Simulink compiler testing is challenging due to millions of lines of source code and the lack of the complete formal language specification. Although several methods have been proposed to automatically test Simulink compiler, there still remains two challenges to be tackled, namely the limited variant space and the insufficient mutation diversity. To address these challenges, we propose COMBAT, a new differential testing method for Simulink compiler testing. COMBAT includes an EMI (Equivalence Modulo Input) mutation component and a diverse variant generation component. The EMI mutation component inserts assertion statements (e.g., If /While blocks) at arbitrary points of the seed CPS model. These statements break each insertion point into true and false branches. Then, COMBAT feeds all the data passed through the insertion point into the true branch to preserve the equivalence of CPS variants. In such a way, the body of the false branch could be viewed as a new variant space, thus addressing the first challenge. The diverse variant generation component uses Markov chain Monte Carlo optimization to sample the seed CPS model and generate complex mutations of long sequences of blocks in the variant space, thus addressing the second challenge. Experiments demonstrate that COMBAT significantly outperforms the state-of-the-art approaches in Simulink compiler testing. Within five months, COMBAT has reported 16 valid bugs for Simulink R2021b, of which 11 bugs have been confirmed as new bugs by MathWorks Support.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Rust-twins: Automatic Rust Compiler Testing through Program Mutation and Dual Macros GenerationWenzhang Yang, Cuifeng Gao, Xiaoyuan Liu, Yuekang Li 等ASE 2024 · 被引用 5 次
- PhyFu: Fuzzing Modern Physics Simulation EnginesDongwei Xiao, Zhibo Liu, Shuai WangASE 2023 · 被引用 1 次
- 3D Software Synthesis Driven by Constraint-Expressive Intermediate RepresentationShuqing Li, Anson Y. Lam, Yun Peng, Wenxuan Wang 等ICSE 2026
它引用的顶会 Paper2
- A comprehensive study of deep learning compiler bugsQingchao Shen, Haoyang Ma, Junjie Chen, Yongqiang Tian 等FSE 2021 · 被引用 123 次
- SLEMI: equivalence modulo input (EMI) based mutation of CPS models for finding compiler bugs in SimulinkShafiul Azam Chowdhury, Sohil Lal Shrestha, Taylor T. Johnson, Christoph CsallnerICSE 2020 · 被引用 35 次
相关 Paper
- Live Region Mutation Testing for Commercial Cyber-Physical System Development Tool ChainLehuan Zhang, Shikai Guo, Zixuan Wang, Xiaoyu Wang 等DAC 2025
- Partition Based Differential Testing for Finding Embedded Code Generation Bugs in SimulinkHe Jiang, Hongyi Cheng, Shikai Guo, Xiaochen LiDAC 2023 · 被引用 2 次
- Fuzzing for CPS Mutation TestingJaekwon Lee, Enrico Viganò, Oscar Cornejo, Fabrizio Pastore 等ASE 2023 · 被引用 4 次
- CFTCG: Test Case Generation for Simulink Model through Code Based FuzzingZhuo Su, Zehong Yu, Dongyan Wang, Rui Wang 等DAC 2024 · 被引用 1 次
- Test Case Generation for Simulink Models using Model Fuzzing and State SolvingZhuo Su, Zehong Yu, Dongyan Wang, Wanli Chang 等ASE 2024 · 被引用 1 次
