Unsupervised learning of API aliasing specifications

Unsupervised learning of API aliasing specifications
复制标题

DOI:
10.1145/3314221.3314640
复制
发表时间:
2019-06
期刊:
Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation
影响因子:
--
通讯作者:
Jan Eberhardt;Samuel Steffen;Veselin Raychev;Martin T. Vechev
Jan Eberhardt;Samuel Steffen;Veselin Raychev;Martin T. Vechev
中科院分区:
其他
文献类型:
--
作者:
Jan Eberhardt;Samuel Steffen;Veselin Raychev;Martin T. Vechev

文献摘要

被引文献

相似文献

现实世界的应用大量使用了强大的库和框架,这对静态分析构成了重大挑战,因为库实施可能非常复杂或不可用。因此,获取总结库行为的规格很重要,因为它使静态分析仪能够精确跟踪API对客户端程序的影响,而无需实际实施。在这项工作中,我们提出了一种新的方法,可以通过从大量程序数据集中学习来发现API的混溶性规格。与先前的工作不同,我们的方法不需要手动注释,访问库的源代码或运行其API的能力。取而代之的是,它通过静态观察数据集中的API使用,以完全无监督的方式学习规格。核心思想是学习API方法与混叠对象之间相互作用的概率模型,从而识别其他可能的混杂关系,然后推断出解释这些关系的API的异叠性规范。然后,使用学习的规范来增强API API API-AWAR APIE分析。我们在一个名为USPEC的工具中实现了方法,并使用它自动从数百万源代码文件中学习混叠规格。 USPEC在此过程中了解了2000年以上各种Java和Python API的规格,以改善点对点分析及其客户的结果。
Real world applications make heavy use of powerful libraries and frameworks, posing a significant challenge for static analysis as the library implementation may be very complex or unavailable. Thus, obtaining specifications that summarize the behaviors of the library is important as it enables static analyzers to precisely track the effects of APIs on the client program, without requiring the actual API implementation. In this work, we propose a novel method for discovering aliasing specifications of APIs by learning from a large dataset of programs. Unlike prior work, our method does not require manual annotation, access to the library's source code or ability to run its APIs. Instead, it learns specifications in a fully unsupervised manner, by statically observing usages of APIs in the dataset. The core idea is to learn a probabilistic model of interactions between API methods and aliasing objects, enabling identification of additional likely aliasing relations, and to then infer aliasing specifications of APIs that explain these relations. The learned specifications are then used to augment an API-aware points-to analysis. We implemented our approach in a tool called USpec and used it to automatically learn aliasing specifications from millions of source code files. USpec learned over 2000 specifications of various Java and Python APIs, in the process improving the results of the points-to analysis and its clients.