Jiahao Yuan 0001

dblp:219/2225-1 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2026
0009-0003-6904-6285ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Studying and Improving the Soundness of Input-Based Feature-Oriented Debloating
abstract
The paper consists of two parts: a study of the soundness of feature-oriented debloating techniques that use inputs as the feature specification and a new blocking method BLOCKAUGwe proposed for soundness improvement. Feature-oriented debloating techniques aim to eliminate code bloat related to unneeded program features. Many of these techniques rely on a usage profile, typically provided as a set of inputs, for specification. Such input-based techniques tend to produce debloated programs that are overfitted to the inputs provided, introducing soundness issues often as bugs and vulnerabilities that pose severe threats to the program correctness and security. No prior work has systematically investigated the soundness of current debloating techniques and analyzed the types and causes of the soundness issues they introduce. To fill this gap, we conducted a study in which we applied 7 input-based techniques to 18 programs from two existing benchmarks for debloating and used three fuzzers with various sanitizers to detect soundness issues introduced by these techniques. Our results show that current techniques are highly unsound, as they can introduce a number of issues that lead to program crashes. A key reason for the issue introduction is the inappropriate deletion of soundness-related code such as conditional statements checking invalid cases, which, if missing, can result in unexpected program state and unconditioned execution.To improve the soundness of input-based debloating, we explored a blocking method that can be applied to coverage-based debloating. The core idea is to identify every deleted branch resulted from coverage-based code pruning and, instead of leaving the branch as empty, augment it to prevent any execution from passing through the branch and causing problems. To assess the effectiveness of the method, we used it to augment the debloated programs generated by four coverage-based techniques and evaluated the soundness and generality of the augmented programs. We found that the blocking method can significantly improve soundness, at the cost of only slightly increasing the program size. Although it can change program semantics, it does not significantly affect the generality by weakening the program’s ability in handling other feature-related inputs not seen while debugging. Moreover, the blocking method can forbid unexpected execution of any inputs the program should not have processed, thereby improving the program trustworthiness.
Jiahao Yuan 0001, Weinuo Leng, Xuan Wei 0002, Qi Xin 0001, Xiaoyuan Xie, Jifeng Xuan
IEEE Trans. Software Eng.1
2025 ROSE: An IDE-Based Interactive Repair Framework for Debugging
abstract
Debugging is costly. Automated program repair (APR) holds the promise of reducing its cost by automatically fixing errors. However, current techniques are not easily applicable in a realistic debugging scenario because they assume a high-quality test suite and frequent program re-execution, have low repair efficiency, and only handle a limited set of errors. To improve the practicality of APR for debugging, we propose ROSE, an interactive repair framework that is able to suggest quick and effective repairs of semantic errors while debugging in an Integrated Development Environment (IDE). ROSE allows an easy integration of existing APR patch generators and can do program repair without assuming the existence of a test suite and without requiring program re-execution. It works in conjunction with an IDE debugger and assumes a debugger stopping point where a problem symptom is observed. ROSE asks the developer to quickly describe the symptom. Then it uses the stopping point, the identified symptom, and the current environment to identify potentially faulty lines, uses a variety of APR techniques to suggest repairs at those lines, and validates those repairs without re-executing the program. Finally, it presents the results so the developer can examine, select, and make the appropriate repair. ROSE uses novel approaches to achieve effective fault localization and patch validation without a test suite or program re-execution. For fault localization, ROSE builds on a fast abstract interpretation-based flow analysis to compute a static backward slice approximating the real dynamic slice while taking into account the symptom and the current execution. For patch validation without re-running the program, ROSE generates simulated traces based on a live-programming system for both the original and repaired executions and compares the traces with respect to the problem symptoms to infer patch correctness. We implemented a prototype of ROSE that works in an Eclipse-based IDE and evaluated its potency and utility with an effectiveness study and a user study. We found that ROSE’s fault localization and validation are highly effective and a ROSE-based tool using existing APR patch generators generated correct repair suggestions for many errors in only seconds. Moreover, the user study demonstrated that ROSE was helpful for debugging and developers liked to use it.
Steven P. Reiss, Xuan Wei 0002, Jiahao Yuan 0001, Qi Xin 0001
ACM Trans. Softw. Eng. Methodol.3