Striking a Balance: Pruning False-Positives from Static Call Graphs
Akshay Utture, Shuyang Liu, Christian Gram Kalhauge, Jens Palsberg
摘要
Researchers have reported that static analysis tools rarely achieve a false-positive rate that would make them attractive to developers. We overcome this problem by a technique that leads to reporting fewer bugs but also much fewer false positives. Our technique prunes the static call graph that sits at the core of many static analyses. Specifically, static call-graph construction proceeds as usual, after which a call-graph pruner removes many false-positive edges but few true edges. The challenge is to strike a balance between being aggressive in removing false-positive edges but not so aggressive that no true edges remain. We achieve this goal by automatically producing a call-graph pruner through an automatic, ahead-of-time learning process. We added such a call-graph pruner to a software tool for null-pointer analysis and found that the falsepositive rate decreased from 73% to 23%. This improvement makes the tool more useful to developers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- AutoPruner: transformer-based call graph pruningThanh Le-Cong, Hong Jin Kang, Truong Giang Nguyen, Stefanus Agus Haryono 等FSE 2022 · 被引用 21 次
- Beware of the Unexpected: Bimodal Taint AnalysisYiu Wai Chow, Max Schäfer, Michael PradelISSTA 2023 · 被引用 13 次
- AutoLog: A Log Sequence Synthesis Framework for Anomaly DetectionYintong Huo, Yichen Li, Yuxin Su, Pinjia He 等ASE 2023 · 被引用 12 次
- That's a Tough Call: Studying the Challenges of Call Graph Construction for WebAssemblyDaniel Lehmann, Michelle Thalakottur, Frank Tip, Michael PradelISSTA 2023 · 被引用 11 次
- DyPyBench: A Benchmark of Executable Python SoftwareIslem Bouzenia, Bajaj Piyush Krishan, Michael PradelFSE 2024 · 被引用 8 次
它引用的顶会 Paper4
- Learning semantic program embeddings with graph interval neural networkYu Wang, Ke Wang, Fengjuan Gao, Linzhang WangOOPSLA 2020 · 被引用 61 次
- On the recall of static call graph construction in practiceLi Sui, Jens Dietrich, Amjed Tahir, George FourtounisICSE 2020 · 被引用 34 次
- Learning graph-based heuristics for pointer analysis without handcrafting application-specific featuresMinseok Jeon, Myungho Lee, Hakjoo OhOOPSLA 2020 · 被引用 29 次
- Boosting static analysis accuracy with instrumented test executionsTianyi Chen, Kihong Heo, Mukund RaghothamanFSE 2021 · 被引用 18 次
相关 Paper
- Is Call Graph Pruning Really Effective?: An Empirical Re-evaluationMohammad Rafieian, Vlad Birsan, Kunal Katiyar, Dylan Zhong 等ICSE 2026 · 被引用 1 次
- Learning to Reduce False Positives in Analytic Bug DetectorsAnant Kharkar, Roshanak Zilouchian Moghaddam, Matthew Jin, Xiaoyu Liu 等ICSE 2022 · 被引用 33 次
- Tailoring programs for static analysis via program transformationRijnard van Tonder, Claire Le GouesICSE 2020 · 被引用 6 次
- Redefining Indirect Call Analysis with KallGraphGuoren Li, Manu Sridharan, Zhiyun QianS&P 2025
- Bridging Coverage and Confidence: Reliable Static False Alarm Elimination via Input-AgnosticityJiayi Wang, Yu Wang, Linzhang Wang, Ke WangPLDI 2026
