Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Guo Lv

dblp:405/6558 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2025
0009-0001-4215-9971ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program analysis · 100%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
constraint solving
0.912025
Backsolver: Adapting Preceding Execution Paths to Solve Constraints for Concolic Execution · ACM Trans. Softw. Eng. Methodol. 2025
Program analysis › symbolic execution
dynamic symbolic execution
0.912025
Backsolver: Adapting Preceding Execution Paths to Solve Constraints for Concolic Execution · ACM Trans. Softw. Eng. Methodol. 2025
Program analysis › constraint solving
path constraint solving
0.912025
Backsolver: Adapting Preceding Execution Paths to Solve Constraints for Concolic Execution · ACM Trans. Softw. Eng. Methodol. 2025
Systems and software security
vulnerability discovery
0.312025
Backsolver: Adapting Preceding Execution Paths to Solve Constraints for Concolic Execution · ACM Trans. Softw. Eng. Methodol. 2025

Methods — techniques the papers use, named apart from their topics

state merging · 1.7concolic execution · 1.7
YearPublicationVenuePosition
2025 Backsolver: Adapting Preceding Execution Paths to Solve Constraints for Concolic Execution
abstract
Concolic execution follows the execution paths of concrete inputs, capable of generating new inputs for unexplored code by solving negated path constraints. However, implicit flows can hinder concolic execution, reducing the code coverage. Implicit flows occur when inputs influence control flow, and the control flow variation affects the values of some variables. During concolic execution, the preceding path selections limit the potential values of these variables. This limitation may result in unsolvable constraints, subsequently restricting the generation of new inputs for unexplored paths. Our insight is that following the same preceding paths is unnecessary, and we can adapt preceding paths to make the latest constraints solvable. We divide states into general states and implicit-flow-solving states (IFSSs). We utilize the general states to perform concolic execution. When solving constraints influenced by implicit flows, we switch to the IFSSs. We use the IFSSs to explore the relevant code region and adapt paths. To mitigate path explosion and construct the relation between inputs and the variables, we merge the IFSSs. State merging does not burden the general states, and we limit the code regions for the IFSSs to minimize the introduced overhead. Finally, we replace the variable symbols in the target constraints with new expressions and attempt to solve the new constraints. We implement our approach in Backsolver and build a test suite to evaluate it. Backsolver successfully identifies all the implicit flows in the test suite and resolves most of them. When evaluated on six real-world binaries, Backsolver resolves the highest number of branches related to implicit flows in total. Besides, Backsolver has the highest code coverage in PlutoSVG and finds a 0-day vulnerability. We reported the vulnerability and obtained a CVE ID.
Yicheng Zeng, Zhanwei Song, Guo Lv, Hongsong Zhu, Limin Sun 0001
ACM Trans. Softw. Eng. Methodol.3