Zvonimir Pavlinovic

dblp:152/5859 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
1since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 4 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
4 papers
Program verification · 35% Programming languages and type systems · 32% Program analysis · 27%
Network and information security
1 paper
Privacy and data protection · 100%
Databases, data mining, and information retrieval
1 paper
Data mining · 100%

Topics — the 12 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis › static analysis
abstract interpretation
0.512021
Data flow refinement type inference · Proc. ACM Program. Lang. 2021
Programming languages and type systems › type systems
refinement types
0.512021
Data flow refinement type inference · Proc. ACM Program. Lang. 2021
Program verification › type-based verification
refinement type inference
0.512021
Data flow refinement type inference · Proc. ACM Program. Lang. 2021
Privacy and data protection › privacy analysis › privacy models
contextual integrity
0.412019
VACCINE: Using Contextual Integrity For Data Leakage Detection · WWW 2019
Privacy and data protection › information leakage
data leakage detection
0.412019
VACCINE: Using Contextual Integrity For Data Leakage Detection · WWW 2019
Privacy and data protection › privacy policy
privacy policy enforcement
0.412019
VACCINE: Using Contextual Integrity For Data Leakage Detection · WWW 2019
Data mining › statistical analysis
dependency analysis
0.312017
Static analysis for optimizing big data queries · ESEC/SIGSOFT FSE 2017
Program verification
annotation inference
0.212016
Inferring annotations for device drivers from verification histories · ASE 2016
Programming languages and type systems › type checking
type error localization
0.212014
Finding minimum type error sources · OOPSLA 2014
Program analysis
static analysis
0.112017
Static analysis for optimizing big data queries · ESEC/SIGSOFT FSE 2017
Operating systems › i/o › i/o subsystem › device drivers
device driver verification
0.112016
Inferring annotations for device drivers from verification histories · ASE 2016
Debugging and program repair
fault localization
0.112014
Finding minimum type error sources · OOPSLA 2014

Methods — techniques the papers use, named apart from their topics

static analysis · 0.8predicate abstraction · 0.5polyhedra · 0.5octagons · 0.5constrained horn clauses · 0.5temporal reasoning · 0.4invariant inference · 0.2maximum satisfiability modulo theories · 0.2SMT · 0.2
YearPublicationVenuePosition
2021 Data flow refinement type inference
abstract
Refinement types enable lightweight verification of functional programs. Algorithms for statically inferring refinement types typically work by reduction to solving systems of constrained Horn clauses extracted from typing derivations. An example is Liquid type inference, which solves the extracted constraints using predicate abstraction. However, the reduction to constraint solving in itself already signifies an abstraction of the program semantics that affects the precision of the overall static analysis. To better understand this issue, we study the type inference problem in its entirety through the lens of abstract interpretation. We propose a new refinement type system that is parametric with the choice of the abstract domain of type refinements as well as the degree to which it tracks context-sensitive control flow information. We then derive an accompanying parametric inference algorithm as an abstract interpretation of a novel data flow semantics of functional programs. We further show that the type system is sound and complete with respect to the constructed abstract semantics. Our theoretical development reveals the key abstraction steps inherent in refinement type inference algorithms. The trade-off between precision and efficiency of these abstraction steps is controlled by the parameters of the type system. Existing refinement type systems and their respective inference algorithms, such as Liquid types, are captured by concrete parameter instantiations. We have implemented our framework in a prototype tool and evaluated it for a range of new parameter instantiations (e.g., using octagons and polyhedra for expressing type refinements). The tool compares favorably against other existing tools. Our evaluation indicates that our approach can be used to systematically construct new refinement type inference algorithms that are both robust and precise.
Zvonimir Pavlinovic, Yusen Su, Thomas Wies
Proc. ACM Program. Lang.1
2019 VACCINE: Using Contextual Integrity For Data Leakage Detection
abstract
Modern enterprises rely on Data Leakage Prevention (DLP) systems to enforce privacy policies that prevent unintentional flow of sensitive information to unauthorized entities. However, these systems operate based on rule sets that are limited to syntactic analysis and therefore completely ignore the semantic relationships between participants involved in the information exchanges. For similar reasons, these systems cannot enforce complex privacy policies that require temporal reasoning about events that have previously occurred.
Yan Shvartzshnaider, Zvonimir Pavlinovic, Ananth Balashankar, Thomas Wies, Lakshminarayanan Subramanian, Helen Nissenbaum, Prateek Mittal
WWW2
2018 The Impact of Program Transformations on Static Program Analysis
Kedar S. Namjoshi, Zvonimir Pavlinovic
SAS2
2017 Static analysis for optimizing big data queries
abstract
Query languages for big data analysis provide user extensibility through a mechanism of user-defined operators (UDOs). These operators allow programmers to write proprietary functionalities on top of a relational query skeleton. However, achieving effective query optimization for such languages is extremely challenging since the optimizer needs to understand data dependencies induced by UDOs. SCOPE, the query language from Microsoft, allows for hand coded declarations of UDO data dependencies. Unfortunately, most programmers avoid using this facility since writing and maintaining the declarations is tedious and error-prone. In this work, we designed and implemented two sound and robust static analyses for computing UDO data dependencies. The analyses can detect what columns of an input table are never used or pass-through a UDO unchanged. This information can be used to significantly improve execution of SCOPE scripts. We evaluate our analyses on thousands of real-world queries and show we can catch many unused and pass-through columns automatically without relying on any manually provided declarations.
Diego Garbervetsky, Zvonimir Pavlinovic, Michael Barnett 0001, Madan Musuvathi, Todd Mytkowicz, Edgardo Zoppi
ESEC/SIGSOFT FSE2
2016 Inferring annotations for device drivers from verification histories
abstract
This paper studies and optimizes automated program verification. Detailed reasoning about software behavior is often facilitated by program invariants that hold across all program executions. Finding program invariants is in fact an essential step in automated program verification. Automatic discovery of precise invariants, however, can be very difficult in practice. The problem can be simplified if one has access to a candidate set of assertions (or annotations) and the search for invariants is limited over the space defined by these annotations. Then, the main challenge is to automatically generate quality program annotations. We present an approach that infers program annotations automatically by leveraging the history of verifying related programs. Our algorithm extracts high-quality annotations from previous verification attempts, and then applies them for verifying new programs. We present a case study where we applied our algorithm to Microsoft’s Static Driver Verifier (SDV). SDV is an industrial-strength tool for verification of Windows device drivers that uses manually-tuned heuristics for obtaining a set of annotations. Our technique inferred program annotations comparable in performance to the existing annotations used in SDV that were devised manually by human experts over years. Additionally, the inferred annotations together with the existing ones improved the performance of SDV overall, proving correct 47% of drivers more while running 22% faster in our experiments.
Zvonimir Pavlinovic, Akash Lal, Rahul Sharma 0001
ASE1
2015 Practical SMT-based type error localization
abstract
Compilers for statically typed functional programming languages are notorious for generating confusing type error messages. When the compiler detects a type error, it typically reports the program location where the type checking failed as the source of the error. Since other error sources are not even considered, the actual root cause is often missed. A more adequate approach is to consider all possible error sources and report the most useful one subject to some usefulness criterion. In our previous work, we showed that this approach can be formulated as an optimization problem related to satisfiability modulo theories (SMT). This formulation cleanly separates the heuristic nature of usefulness criteria from the underlying search problem. Unfortunately, algorithms that search for an optimal error source cannot directly use principal types which are crucial for dealing with the exponential-time complexity of the decision problem of polymorphic type checking. In this paper, we present a new algorithm that efficiently finds an optimal error source in a given ill-typed program. Our algorithm uses an improved SMT encoding to cope with the high complexity of polymorphic typing by iteratively expanding the typing constraints from which principal types are derived. The algorithm preserves the clean separation between the heuristics and the actual search. We have implemented our algorithm for OCaml. In our experimental evaluation, we found that the algorithm reduces the running times for optimal type error localization from minutes to seconds and scales better than previous localization algorithms.
Zvonimir Pavlinovic, Tim King 0001, Thomas Wies
ICFP1
2014 Finding minimum type error sources
abstract
Automatic type inference is a popular feature of functional programming languages. If a program cannot be typed, the compiler typically reports a single program location in its error message. This location is the point where the type inference failed, but not necessarily the actual source of the error. Other potential error sources are not even considered. Hence, the compiler often misses the true error source, which increases debugging time for the programmer. In this paper, we present a general framework for automatic localization of type errors. Our algorithm finds all minimum error sources, where the exact definition of minimum is given in terms of a compiler-specific ranking criterion. Compilers can use minimum error sources to produce more meaningful error reports, and for automatic error correction. Our approach works by reducing the search for minimum error sources to an optimization problem that we formulate in terms of weighted maximum satisfiability modulo theories (MaxSMT). The reduction to weighted MaxSMT allows us to build on SMT solvers to support rich type systems and at the same time abstract from the concrete criterion that is used for ranking the error sources. We have implemented an instance of our framework targeted at Hindley-Milner type systems and evaluated it on existing OCaml benchmarks for type error localization. Our evaluation shows that our approach has the potential to significantly improve the quality of type error reports produced by state of the art compilers.
Zvonimir Pavlinovic, Tim King 0001, Thomas Wies
OOPSLA1