Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

David Mitchel Perry

dblp:187/9673 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 2 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
5 papers
Program analysis · 40% Software testing · 27% Debugging and program repair · 16%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 13 heaviest of 17, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery
fuzzing
0.412019
SLF: fuzzing without valid seed inputs · ICSE 2019
Systems and software security
vulnerability discovery
0.412019
SLF: fuzzing without valid seed inputs · ICSE 2019
Software testing
fuzzing
0.412019
SLF: fuzzing without valid seed inputs · ICSE 2019
Software testing › fuzzing › input generation
seed generation
0.412019
SLF: fuzzing without valid seed inputs · ICSE 2019
Program analysis
constraint solving
0.312017
Accelerating array constraints in symbolic execution · ISSTA 2017
Program analysis
static analysis
0.312017
Accelerating array constraints in symbolic execution · ISSTA 2017
Program analysis
symbolic execution
0.312017
Accelerating array constraints in symbolic execution · ISSTA 2017
Software testing
test generation
0.312017
Accelerating array constraints in symbolic execution · ISSTA 2017
Program analysis
dynamic analysis
0.212016
Apex: automatic programming assignment error explanation · OOPSLA 2016
Debugging and program repair › fault localization
failure explanation
0.212016
Apex: automatic programming assignment error explanation · OOPSLA 2016
Debugging and program repair
fault localization
0.212016
Apex: automatic programming assignment error explanation · OOPSLA 2016
Program analysis
type-based analysis
0.112017
UI driven Android application reduction · ASE 2017
Computing education › programming education
programming assignment feedback
0.112016
Apex: automatic programming assignment error explanation · OOPSLA 2016

Methods — techniques the papers use, named apart from their topics

symbolic execution · 1.3mutation · 0.8multi-goal search · 0.8vector representation · 0.4model counting · 0.4data flow abstraction · 0.4type system · 0.3static analysis · 0.3semantics-preserving transformation · 0.3constraint solving · 0.3trace matching · 0.2
YearPublicationVenuePosition
2019 SLF: fuzzing without valid seed inputs
abstract
Fuzzing is an important technique to detect software bugs and vulnerabilities. It works by mutating a small set of seed inputs to generate a large number of new inputs. Fuzzers' performance often substantially degrades when valid seed inputs are not available. Although existing techniques such as symbolic execution can generate seed inputs from scratch, they have various limitations hindering their applications in real-world complex software. In this paper, we propose a novel fuzzing technique that features the capability of generating valid seed inputs. It piggy-backs on AFL to identify input validity checks and the input fields that have impact on such checks. It further classifies these checks according to their relations to the input. Such classes include arithmetic relation, object offset, data structure length and so on. A multi-goal search algorithm is developed to apply class-specific mutations in order to satisfy inter-dependent checks all together. We evaluate our technique on 20 popular benchmark programs collected from other fuzzing projects and the Google fuzzer test suite, and compare it with existing fuzzers AFL and AFLFast, symbolic execution engines KLEE and S2E, and a hybrid tool Driller that combines fuzzing with symbolic execution. The results show that our technique is highly effective and efficient, out-performing the other tools.
Wei You 0001, Xuwei Liu, Shiqing Ma, David Mitchel Perry, Xiangyu Zhang 0001, Bin Liang 0002
ICSE4
2019 SemCluster: clustering of imperative programming assignments based on quantitative semantic features
abstract
A fundamental challenge in automated reasoning about programming assignments at scale is clustering student submissions based on their underlying algorithms. State-of-the-art clustering techniques are sensitive to control structure variations, cannot cluster buggy solutions with similar correct solutions, and either require expensive pair-wise program analyses or training efforts. We propose a novel technique that can cluster small imperative programs based on their algorithmic essence: (A) how the input space is partitioned into equivalence classes and (B) how the problem is uniquely addressed within individual equivalence classes. We capture these algorithmic aspects as two quantitative semantic program features that are merged into a program's vector representation. Programs are then clustered using their vector representations. The computation of our first semantic feature leverages model counting to identify the number of inputs belonging to an input equivalence class. The computation of our second semantic feature abstracts the program's data flow by tracking the number of occurrences of a unique pair of consecutive values of a variable during its lifetime. The comprehensive evaluation of our tool SemCluster on benchmarks drawn from solutions to small programming assignments shows that SemCluster (1) generates far fewer clusters than other clustering techniques, (2) precisely identifies distinct solution strategies, and (3) boosts the performance of clustering-based program repair, all within a reasonable amount of time.
David Mitchel Perry, Dohyeong Kim, Roopsha Samanta, Xiangyu Zhang 0001
PLDI1
2017 Accelerating array constraints in symbolic execution
abstract
Despite significant recent advances, the effectiveness of symbolic execution is limited when used to test complex, real-world software. One of the main scalability challenges is related to constraint solving: large applications and long exploration paths lead to complex constraints, often involving big arrays indexed by symbolic expressions. In this paper, we propose a set of semantics-preserving transformations for array operations that take advantage of contextual information collected during symbolic execution. Our transformations lead to simpler encodings and hence better performance in constraint solving. The results we obtain are encouraging: we show, through an extensive experimental analysis, that our transformations help to significantly improve the performance of symbolic execution in the presence of arrays. We also show that our transformations enable the analysis of new code, which would be otherwise out of reach for symbolic execution.
David Mitchel Perry, Andrea Mattavelli, Xiangyu Zhang 0001, Cristian Cadar
ISSTA1
2017 UI driven Android application reduction
abstract
While smartphones and mobile apps have been an integral part of our life, modern mobile apps tend to contain a lot of rarely used functionalities. For example, applications contain advertisements and offer extra features such as recommended news stories in weather apps. While these functionalities are not essential to an app, they nonetheless consume power, CPU cycles and bandwidth. In this paper, we design a UI driven approach that allows customizing an Android app by removing its unwanted functionalities. In particular, our technique displays the UI and allows the user to select elements denoting functionalities that she wants to remove. Using this information, our technique automatically removes all the code elements related to the selected functionalities, including all the relevant background tasks. The underlying analysis is a type system, in which each code element is tagged with a type indicating if it should be removed. From the UI hints, our technique infers types for all other code elements and reduces the app accordingly. We implement a prototype and evaluate it on 10 real-world Android apps. The results show that our approach can accurately discover the removable code elements and lead to substantial resource savings in the reduced apps.
Jianjun Huang 0001, Yousra Aafer, David Mitchel Perry, Xiangyu Zhang 0001, Chen Tian 0002
ASE3
2016 Apex: automatic programming assignment error explanation
abstract
This paper presents Apex, a system that can automatically generate explanations for programming assignment bugs, regarding where the bugs are and how the root causes led to the runtime failures. It works by comparing the passing execution of a correct implementation (provided by the instructor) and the failing execution of the buggy implementation (submitted by the student). The technique overcomes a number of technical challenges caused by syntactic and semantic differences of the two implementations. It collects the symbolic traces of the executions and matches assignment statements in the two execution traces by reasoning about symbolic equivalence. It then matches predicates by aligning the control dependences of the matched assignment statements, avoiding direct matching of path conditions which are usually quite different. Our evaluation shows that Apex is every effective for 205 buggy real world student submissions of 4 programming assignments, and a set of 15 programming assignment type of buggy programs collected from stackoverflow.com, precisely pinpointing the root causes and capturing the causality for 94.5% of them. The evaluation on a standard benchmark set with over 700 student bugs shows similar results. A user study in the classroom shows that Apex has substantially improved student productivity.
Dohyeong Kim, Yonghwi Kwon 0001, Peng Liu 0010, I Luk Kim, David Mitchel Perry, Xiangyu Zhang 0001, Gustavo Rodriguez-Rivera
OOPSLA5