Haonan Li 0009

dblp:322/6789 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0003-0357-0888ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 LLMBisect: Breaking Barriers in Bug Bisection with A Comparative Analysis Pipeline
Zheng Zhang 0058, Haonan Li 0009, Hang Zhang 0012, Zhiyun Qian
NDSS2
2025 Towards More Accurate Static Analysis for Taint-Style Bug Detection in Linux Kernel
abstract
Static analysis plays a crucial role in software vulnerability detection, yet faces a persistent precision-scalability trade-off. In large codebases like the Linux kernel, traditional static analysis tools often generate excessive false positives due to simplified vulnerability modeling and over-approximation of path and data constraints. While Large Language Models (LLMs) demonstrate promising code understanding capabilities, their direct application to program analysis remains unreliable due to inherent reasoning limitations.We introduce BugLens, a post-refinement framework that significantly enhances static analysis precision for bug detection. BugLens guides LLMs through structured reasoning steps to assess security impact and validate constraints from the source code. When evaluated on Linux kernel’s taint-style bugs detected by static analysis tools, BugLens improves precision approximately 7-fold (from 0.10 to 0.72), substantially reducing false positives while uncovering four previously unreported vulnerabilities. Our results demonstrate that a well-structured, fully-automated LLM-based workflow can effectively complement and enhance traditional static analysis techniques.
Haonan Li 0009, Hang Zhang 0012, Kexin Pei, Zhiyun Qian
ASE1
2024 SymBisect: Accurate Bisection for Fuzzer-Exposed Vulnerabilities
Zheng Zhang 0058, Yu Hao 0006, Weiteng Chen, Xiaochen Zou, Haonan Li 0009, Yizhuo Zhai, Zhiyun Qian, Billy Lau
USENIX Security Symposium6
2024 Enhancing Static Analysis for Practical Bug Detection: An LLM-Integrated Approach
abstract
While static analysis is instrumental in uncovering software bugs, its precision in analyzing large and intricate codebases remains challenging. The emerging prowess of Large Language Models (LLMs) offers a promising avenue to address these complexities. In this paper, we present LLift, a pioneering framework that synergizes static analysis and LLMs, with a spotlight on identifying use-before-initialization (UBI) bugs within the Linux kernel. Drawing from our insights into variable usage conventions in Linux, we enhance path analysis using post-constraint guidance. This approach, combined with our methodically crafted procedures, empowers LLift to adeptly handle the challenges of bug-specific modeling, extensive codebases, and the unpredictable nature of LLMs. Our real-world evaluations identified four previously undiscovered UBI bugs in the mainstream Linux kernel, which the Linux community has acknowledged. This study reaffirms the potential of marrying static analysis with LLMs, setting a compelling direction for future research in this area.
Haonan Li 0009, Yu Hao 0006, Yizhuo Zhai, Zhiyun Qian
Proc. ACM Program. Lang.1
2023 Alligator in Vest: A Practical Failure-Diagnosis Framework via Arm Hardware Features
abstract
Failure diagnosis in practical systems is difficult, and the main obstacle is that the information a developer has access to is limited. This information is usually not enough to help developers fix or even locate the related bug. Moreover, due to the vast difference between the development and production environments, it is not trivial to reproduce failures from the production environment in the development environment. When failures are caused by non-deterministic events such as race conditions or unforeseen inputs, reproducing them is even more challenging.
Yiming Zhang 0030, Haonan Li 0009, Zhenyu Ning, Xiapu Luo, Fengwei Zhang
ISSTA3
2023 Assisting Static Analysis with Large Language Models: A ChatGPT Experiment
abstract
Recent advances of Large Language Models (LLMs), e.g., ChatGPT, exhibited strong capabilities of comprehending and responding to questions across a variety of domains. Surprisingly, ChatGPT even possesses a strong understanding of program code. In this paper, we investigate where and how LLMs can assist static analysis by asking appropriate questions. In particular, we target a specific bug-finding tool, which produces many false positives from the static analysis. In our evaluation, we find that these false positives can be effectively pruned by asking carefully constructed questions about function-level behaviors or function summaries. Specifically, with a pilot study of 20 false positives, we can successfully prune 8 out of 20 based on GPT-3.5, whereas GPT-4 had a near-perfect result of 16 out of 20, where the four failed ones are not currently considered/supported by our questions, e.g., involving concurrency. Additionally, it also identified one false negative case (a missed bug). We find LLMs a promising tool that can enable a more effective and efficient program analysis.
Haonan Li 0009, Yu Hao 0006, Yizhuo Zhai, Zhiyun Qian
ESEC/SIGSOFT FSE1