Kaituo Li

dblp:64/7615 · DBLP profile ↗
← Back
6ranked-venue papers
6as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 4 first-authorSystems, architecture and hardware · 1 · 1 first-authorSecurity and privacy · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
4 papers
Program analysis · 75% Software testing · 15% Program verification · 9%

Topics — the 9 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
dynamic analysis
0.422014
Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014
Second-order constraints in dynamic invariant inference · ESEC/SIGSOFT FSE 2013
Program analysis › static analysis
bug detection
0.322014
Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014
Residual investigation: predictive and precise bug detection · ISSTA 2012
Program analysis
static analysis
0.322014
Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014
Residual investigation: predictive and precise bug detection · ISSTA 2012
Program analysis › specification mining
dynamic invariant detection
0.212013
Second-order constraints in dynamic invariant inference · ESEC/SIGSOFT FSE 2013
Program verification
invariant generation
0.212013
Second-order constraints in dynamic invariant inference · ESEC/SIGSOFT FSE 2013
Software testing
test input generation
0.212013
SEDGE: Symbolic example data generation for dataflow programs · ASE 2013
Program analysis
false alarm reduction
0.112012
Residual investigation: predictive and precise bug detection · ISSTA 2012
Software testing
test suite evaluation
0.112014
Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014
Software testing › structural testing
data flow testing
0.012013
SEDGE: Symbolic example data generation for dataflow programs · ASE 2013

Methods — techniques the papers use, named apart from their topics

dynamic checking · 0.3static analysis · 0.2symbolic execution · 0.2concolic execution · 0.2SMT solving · 0.2residual investigation · 0.1
YearPublicationVenuePosition
2014 ReproLite: A Lightweight Tool to Quickly Reproduce Hard System Bugs
abstract
Cloud systems have become ubiquitous today -- they are used to store and process the tremendous amounts of data being generated by Internet users. These systems run on hundreds of commodity machines, and have a huge amount of non-determinism (thousands of threads and hundreds of processes) in their execution. Therefore, bugs that occur in cloud systems are hard to understand, reproduce, and fix. The state-of-the-art of debugging in the industry is to log messages during execution, and refer to those messages later in case of errors. In ReproLite, we augment the already widespread process of debugging using logs by enabling testers to quickly and easily specify the conjectures that they form regarding the cause of an error (or bug) from execution logs, and to also automatically validate those conjectures.
Kaituo Li, Pallavi Joshi, Aarti Gupta, Malay K. Ganai
SoCC1
2014 Residual Investigation: Predictive and Precise Bug Detection
abstract
We introduce the concept of residual investigation for program analysis. A residual investigation is a dynamic check installed as a result of running a static analysis that reports a possible program error. The purpose is to observe conditions that indicate whether the statically predicted program fault is likely to be realizable and relevant. The key feature of a residual investigation is that it has to be much more precise (i.e., with fewer false warnings) than the static analysis alone, yet significantly more general (i.e., reporting more errors) than the dynamic tests in the program's test suite that are pertinent to the statically reported error. That is, good residual investigations encode dynamic conditions that, when considered in conjunction with the static error report, increase confidence in the existence or severity of an error without needing to directly observe a fault resulting from the error. We enhance the static analyzer FindBugs with several residual investigations appropriately tuned to the static error patterns in FindBugs, and apply it to nine large open-source systems and their native test suites. The result is an analysis with a low occurrence of false warnings (false positives) while reporting several actual errors that would not have been detected by mere execution of a program's test suite.
Kaituo Li, Christoph Reichenbach, Christoph Csallner, Yannis Smaragdakis
ACM Trans. Softw. Eng. Methodol.1
2013 SEDGE: Symbolic example data generation for dataflow programs
abstract
Exhaustive, automatic testing of dataflow (esp. mapreduce) programs has emerged as an important challenge. Past work demonstrated effective ways to generate small example data sets that exercise operators in the Pig platform, used to generate Hadoop map-reduce programs. Although such prior techniques attempt to cover all cases of operator use, in practice they often fail. Our SEDGE system addresses these completeness problems: for every dataflow operator, we produce data aiming to cover all cases that arise in the dataflow program (e.g., both passing and failing a filter). SEDGE relies on transforming the program into symbolic constraints, and solving the constraints using a symbolic reasoning engine (a powerful SMT solver), while using input data as concrete aids in the solution process. The approach resembles dynamic-symbolic (a.k.a. “concolic”) execution in a conventional programming language, adapted to the unique features of the dataflow domain. In third-party benchmarks, SEDGE achieves higher coverage than past techniques for 5 out of 20 PigMix benchmarks and 7 out of 11 SDSS benchmarks and (with equal coverage for the rest of the benchmarks). We also show that our targeting of the high-level dataflow language pays off: for complex programs, state-of-the-art dynamic-symbolic execution at the level of the generated map-reduce code (instead of the original dataflow program) requires many more test cases or achieves much lower coverage than our approach.
Kaituo Li, Christoph Reichenbach, Yannis Smaragdakis, Yanlei Diao, Christoph Csallner
ASE1
2013 Second-order constraints in dynamic invariant inference
abstract
The current generation of dynamic invariant detectors often produce invariants that are inconsistent with program semantics or programmer knowledge. We improve the consistency of dynamically discovered invariants by taking into account higher-level constraints. These constraints encode knowledge about invariants, even when the invariants themselves are unknown. For instance, even though the invariants describing the behavior of two functions f1 and f2 may be unknown, we may know that any valid input for f1 is also valid for f2, i.e., the precondition of f1 implies that of f2. We explore techniques for expressing and employing such consistency constraints to improve the quality of produced invariants. We further introduce techniques for dynamically discovering potential second-order constraints that the programmer can subsequently approve or reject.
Kaituo Li, Christoph Reichenbach, Yannis Smaragdakis, Michal Young
ESEC/SIGSOFT FSE1
2012 Residual investigation: predictive and precise bug detection
abstract
We introduce the concept of “residual investigation” for program analysis. A residual investigation is a dynamic check installed as a result of running a static analysis that reports a possible program error. The purpose is to observe conditions that indicate whether the statically predicted program fault is likely to be realizable and relevant. The key feature of a residual investigation is that it has to be much more precise (i.e., with fewer false warnings) than the static analysis alone, yet significantly more general (i.e., reporting more errors) than the dynamic tests in the program's test suite pertinent to the statically reported error. That is, good residual investigations encode dynamic conditions that, when taken in conjunction with the static error report, increase confidence in the existence of an error, as well as its severity, without needing to directly observe a fault resulting from the error.
Kaituo Li, Christoph Reichenbach, Christoph Csallner, Yannis Smaragdakis
ISSTA1
2008 Exposure Time Change Attack on Image Watermarking Systems
Kaituo Li, Deren Chen
IWDW1