Lune

ISSTA2026顶会

Mathematically-Guided Detection of Floating-Point Errors

Youshuai Tan, Zhanwei Zhang, Haonan Zhang, Lianyu Zheng, Zishuo Ding, Jinfu Chen, Weiyi Shang

2026年份

摘要

Floating-point computations are important for modern scientific and engineering software, especially for safety-critical systems, yet only a small subset of inputs typically trigger substantial numerical errors. Detecting such error-inducing inputs and the underlying bugs is therefore essential for improving their security and reliability. Existing techniques commonly rely on either oracle-driven exploration that repeatedly compares against high-precision references or search-driven heuristics. Despite the improvements made, they remain limited by (1) Expensive computation of high-precision oracles and (2) Lack of long-range convergence , which often requires dense probing near narrow error-inducing regions and expensive computation. We propose MGDE ( M athematically- G uided D etection of floating-point E rrors), a method that replaces trial-and-error exploration with mathematically defined targets and directed convergence. MGDE first uses condition-number theory to identify numerically unstable atomic operations without invoking expensive high-precision oracles during exploration. MGDE exploits the observation that extreme condition numbers occur near structured boundaries (e.g., cancellation points and singularities), reformulating detection as a numerical root-finding problem. By solving the resulting objectives with the Newton–Raphson method, MGDE can steer inputs toward error-prone regions from far-away initializations. We evaluate MGDE on GNU Scientific Library (GSL) functions and compare against two state-of-the-art baselines, ATOMU and FPCC, using triggered bugs as the primary metric. On 88 single-input functions, MGDE triggers 80 numerically validated bugs across 47 functions, outperforming ATOMU (70 bugs in 46 functions) and FPCC (53 bugs in 42 functions). MGDE is also faster: ATOMU and FPCC require 42.71× and 11.17× the exploration time of MGDE, respectively. Regarding multi-input functions, we evaluate MGDE under two complementary settings. On the native multi-input dataset of FPCC, MGDE detects 28 triggered bugs, while FPCC finds 23 bugs. MGDE also takes 8.91 seconds in total, compared with 2,100 seconds used by FPCC. On an additional external benchmark of 18 dual-input GSL functions, MGDE detects nine bugs not found by FPCC. Overall, MGDE substantially advances the state-of-the-art in both effectiveness and efficiency, and we report 16 previously unknown GSL bugs, which have been confirmed by the GSL community.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖