Tina Jung

dblp:306/0498 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2025
0000-0001-8657-7190ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Compilers and program optimization · 62% Program analysis · 19% Program verification · 19%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
memory safety
0.512021
PICO: A Presburger In-bounds Check Optimization for Compiler-based Memory Safety Instrumentations · ACM Trans. Archit. Code Optim. 2021
Compilers and program optimization › program instrumentation
compiler instrumentation
0.512021
PICO: A Presburger In-bounds Check Optimization for Compiler-based Memory Safety Instrumentations · ACM Trans. Archit. Code Optim. 2021
Program verification
presburger arithmetic
0.112021
PICO: A Presburger In-bounds Check Optimization for Compiler-based Memory Safety Instrumentations · ACM Trans. Archit. Code Optim. 2021
Program analysis
static analysis
0.112021
PICO: A Presburger In-bounds Check Optimization for Compiler-based Memory Safety Instrumentations · ACM Trans. Archit. Code Optim. 2021

Methods — techniques the papers use, named apart from their topics

static analysis · 1.0presburger formulas · 1.0LLVM · 1.0
YearPublicationVenuePosition
2025 Memory Safety Instrumentations in Practice: Usability, Performance, and Security Guarantees
abstract
Memory safety violations due to C's undefined behavior, although well researched, still cause security breaches year by year. The most dangerous reported violations are spatial safety violations, where objects are accessed outside of their bounds. A wide variety of spatial safety sanitizers promise easy usage, broad security guarantees, and a low execution time overhead. However, only few of them are actually used. Instead of proposing yet another sanitizer, we dig deep into Low-Fat Pointers and SoftBound, two approaches to generate fast-to-execute safe programs with strong safety guarantees, and identify pain points in their usage. We found that seemingly small simplifying assumptions or limitations of the approaches often lead to spurious error reports. On top of analyzing usability issues, we set up a framework that abstracts common tasks of memory safety instrumentations, such as finding locations for checks and eliminating redundant checks. This abstraction allows us to draw a fair comparison between approaches when it comes to execution time and the number of safe accesses. We use this framework to give novel insights into how many accesses are provably safe, and where to attribute execution time overhead. Our findings help future research on memory safety instrumentations by identifying issues that current approaches face in their practical application. We make our LLVM-based instrumentation framework available to reduce the effort required to implement new instrumentations and to ease comparisons to Low-Fat Pointers and SoftBound.
Tina Jung, Fabian Ritter 0002, Sebastian Hack
CGO1
2021 PICO: A Presburger In-bounds Check Optimization for Compiler-based Memory Safety Instrumentations
abstract
Memory safety violations such as buffer overflows are a threat to security to this day. A common solution to ensure memory safety for C is code instrumentation. However, this often causes high execution-time overhead and is therefore rarely used in production. Static analyses can reduce this overhead by proving some memory accesses in bounds at compile time. In practice, however, static analyses may fail to verify in-bounds accesses due to over-approximation. Therefore, it is important to additionally optimize the checks that reside in the program. In this article, we present PICO, an approach to eliminate and replace in-bounds checks. PICO exactly captures the spatial memory safety of accesses using Presburger formulas to either verify them statically or substitute existing checks with more efficient ones. Thereby, PICO can generate checks of which each covers multiple accesses and place them at infrequently executed locations. We evaluate our LLVM-based PICO prototype with the well-known SoftBound instrumentation on SPEC benchmarks commonly used in related work. PICO reduces the execution-time overhead introduced by SoftBound by 36% on average (and the code-size overhead by 24%). Our evaluation shows that the impact of substituting checks dominates that of removing provably redundant checks.
Tina Jung, Fabian Ritter 0002, Sebastian Hack
ACM Trans. Archit. Code Optim.1