VLDB 2026 Research / reviewers in the wild / expert
Kaituo Li
dblp:64/7615
· DBLP profile ↗
6ranked-venue papers
6as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 4 first-authorSystems, architecture and hardware · 1 · 1 first-authorSecurity and privacy · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
4 papers |
Program analysis · 75% Software testing · 15% Program verification · 9% |
Topics — the 9 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis
dynamic analysis |
0.4 | 2 | 2014 | Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014 Second-order constraints in dynamic invariant inference · ESEC/SIGSOFT FSE 2013 |
Program analysis › static analysis
bug detection |
0.3 | 2 | 2014 | Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014 Residual investigation: predictive and precise bug detection · ISSTA 2012 |
Program analysis
static analysis |
0.3 | 2 | 2014 | Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014 Residual investigation: predictive and precise bug detection · ISSTA 2012 |
Program analysis › specification mining
dynamic invariant detection |
0.2 | 1 | 2013 | Second-order constraints in dynamic invariant inference · ESEC/SIGSOFT FSE 2013 |
Program verification
invariant generation |
0.2 | 1 | 2013 | Second-order constraints in dynamic invariant inference · ESEC/SIGSOFT FSE 2013 |
Software testing
test input generation |
0.2 | 1 | 2013 | SEDGE: Symbolic example data generation for dataflow programs · ASE 2013 |
Program analysis
false alarm reduction |
0.1 | 1 | 2012 | Residual investigation: predictive and precise bug detection · ISSTA 2012 |
Software testing
test suite evaluation |
0.1 | 1 | 2014 | Residual Investigation: Predictive and Precise Bug Detection · ACM Trans. Softw. Eng. Methodol. 2014 |
Software testing › structural testing
data flow testing |
0.0 | 1 | 2013 | SEDGE: Symbolic example data generation for dataflow programs · ASE 2013 |
Methods — techniques the papers use, named apart from their topics
dynamic checking · 0.3static analysis · 0.2symbolic execution · 0.2concolic execution · 0.2SMT solving · 0.2residual investigation · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | ReproLite: A Lightweight Tool to Quickly Reproduce Hard System BugsabstractCloud systems have become ubiquitous today -- they are used to store and process the tremendous amounts of data being generated by Internet users. These systems run on hundreds of commodity machines, and have a huge amount of non-determinism (thousands of threads and hundreds of processes) in their execution. Therefore, bugs that occur in cloud systems are hard to understand, reproduce, and fix. The state-of-the-art of debugging in the industry is to log messages during execution, and refer to those messages later in case of errors. In ReproLite, we augment the already widespread process of debugging using logs by enabling testers to quickly and easily specify the conjectures that they form regarding the cause of an error (or bug) from execution logs, and to also automatically validate those conjectures. Kaituo Li, Pallavi Joshi, Aarti Gupta, Malay K. Ganai |
SoCC | 1 |
| 2014 | Residual Investigation: Predictive and Precise Bug DetectionabstractWe introduce the concept of residual investigation for program analysis. A residual investigation is a dynamic check installed as a result of running a static analysis that reports a possible program error. The purpose is to observe conditions that indicate whether the statically predicted program fault is likely to be realizable and relevant. The key feature of a residual investigation is that it has to be much more precise (i.e., with fewer false warnings) than the static analysis alone, yet significantly more general (i.e., reporting more errors) than the dynamic tests in the program's test suite that are pertinent to the statically reported error. That is, good residual investigations encode dynamic conditions that, when considered in conjunction with the static error report, increase confidence in the existence or severity of an error without needing to directly observe a fault resulting from the error. We enhance the static analyzer FindBugs with several residual investigations appropriately tuned to the static error patterns in FindBugs, and apply it to nine large open-source systems and their native test suites. The result is an analysis with a low occurrence of false warnings (false positives) while reporting several actual errors that would not have been detected by mere execution of a program's test suite. Kaituo Li, Christoph Reichenbach, Christoph Csallner, Yannis Smaragdakis |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2013 | SEDGE: Symbolic example data generation for dataflow programsabstractExhaustive, automatic testing of dataflow (esp. mapreduce) programs has emerged as an important challenge. Past work demonstrated effective ways to generate small example data sets that exercise operators in the Pig platform, used to generate Hadoop map-reduce programs. Although such prior techniques attempt to cover all cases of operator use, in practice they often fail. Our SEDGE system addresses these completeness problems: for every dataflow operator, we produce data aiming to cover all cases that arise in the dataflow program (e.g., both passing and failing a filter). SEDGE relies on transforming the program into symbolic constraints, and solving the constraints using a symbolic reasoning engine (a powerful SMT solver), while using input data as concrete aids in the solution process. The approach resembles dynamic-symbolic (a.k.a. “concolic”) execution in a conventional programming language, adapted to the unique features of the dataflow domain. In third-party benchmarks, SEDGE achieves higher coverage than past techniques for 5 out of 20 PigMix benchmarks and 7 out of 11 SDSS benchmarks and (with equal coverage for the rest of the benchmarks). We also show that our targeting of the high-level dataflow language pays off: for complex programs, state-of-the-art dynamic-symbolic execution at the level of the generated map-reduce code (instead of the original dataflow program) requires many more test cases or achieves much lower coverage than our approach. Kaituo Li, Christoph Reichenbach, Yannis Smaragdakis, Yanlei Diao, Christoph Csallner |
ASE | 1 |
| 2013 | Second-order constraints in dynamic invariant inferenceabstractThe current generation of dynamic invariant detectors often produce invariants that are inconsistent with program semantics or programmer knowledge. We improve the consistency of dynamically discovered invariants by taking into account higher-level constraints. These constraints encode knowledge about invariants, even when the invariants themselves are unknown. For instance, even though the invariants describing the behavior of two functions f1 and f2 may be unknown, we may know that any valid input for f1 is also valid for f2, i.e., the precondition of f1 implies that of f2. We explore techniques for expressing and employing such consistency constraints to improve the quality of produced invariants. We further introduce techniques for dynamically discovering potential second-order constraints that the programmer can subsequently approve or reject. Kaituo Li, Christoph Reichenbach, Yannis Smaragdakis, Michal Young |
ESEC/SIGSOFT FSE | 1 |
| 2012 | Residual investigation: predictive and precise bug detectionabstractWe introduce the concept of “residual investigation” for program analysis. A residual investigation is a dynamic check installed as a result of running a static analysis that reports a possible program error. The purpose is to observe conditions that indicate whether the statically predicted program fault is likely to be realizable and relevant. The key feature of a residual investigation is that it has to be much more precise (i.e., with fewer false warnings) than the static analysis alone, yet significantly more general (i.e., reporting more errors) than the dynamic tests in the program's test suite pertinent to the statically reported error. That is, good residual investigations encode dynamic conditions that, when taken in conjunction with the static error report, increase confidence in the existence of an error, as well as its severity, without needing to directly observe a fault resulting from the error. Kaituo Li, Christoph Reichenbach, Christoph Csallner, Yannis Smaragdakis |
ISSTA | 1 |
| 2008 | Exposure Time Change Attack on Image Watermarking Systems
Kaituo Li, Deren Chen |
IWDW | 1 |