Lune

ISSTA2026顶会

Testing Static Taint Analyzers with Equivalence Modulo Taint

Maria Christakis, Anastasia Isychev, Samuel Pilz, Florian Tesarek, Valentin Wüstholz

2026年份

摘要

Static taint analyzers are widely used to detect security vulnerabilities, yet their complexity makes them prone to soundness and precision issues. Validating these analyzers is challenging because ground-truth taint flows are rarely available and differential testing requires multiple comparable tools. To address this challenge, we introduce Equivalence Modulo Taint (EMT), a testing oracle for static taint analysis that defines program equivalence in terms of preserved source-sink flows rather than program semantics. EMT enables testing a single analyzer without ground-truth labels by checking consistency of reported flows across equivalentmodulo-taint program variants. Based on EMT, we present TaintCC, a framework that generates equivalentmodulo-taint variants through semantically equivalent, taint-oblivious, and taint-aware transformations targeting recurring difficulty dimensions in taint analysis. We evaluate TaintCC on four widely used analyzers-FlowDroid, Mariana Trench, Pysa, and Semgrep-and uncover 16 unique developer-confirmed issues, showing that even mature analyzers, whether academic or industrial, remain susceptible to reliability issues.

CCS Concepts: • Software and its engineering → Software testing and debugging.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext eda26a43-299d-4b73-ad42-f694fac40763

它引用的顶会 Paper18

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖