Dissecting Widening: Separating Termination from Information
Widening ensures or accelerates convergence of an analysis, and sometimes contributes a guarantee of soundness that would otherwise be absent. In this paper we propose a generalised view of widening, in which widening operates on values that are not necessarily elements of the given abstract domain, although they must be in a correspondence, the details of which we spell out. We show that the new view generalizes the traditional view, and that at least three distinct advantages flow from the generalization. First, it gives a handle on ``compositional safety'', the problem of creating widening operators for product domains. Second, it adds a degree of flexibility, allowing us to define variants of widening, such as delayed widening, without resorting to intrusive surgery on an underlying fixpoint engine. Third, it adds a degree of robustness, by making it difficult for an analysis implementor to make certain subtle (syntactic vs semantic) category mistakes. The paper supports these claims with examples. Our proposal has been implemented in a state-of-the-art abstract interpreter, and we briefly report on the changes that the revised view necessitated.
Mon 2 DecDisplayed time zone: Beijing, Chongqing, Hong Kong, Urumqi change
13:30 - 15:00
|Dissecting Widening: Separating Termination from Information|
|A Type-Based HFL Model Checking Algorithm|
|Reducing Static Analysis Alarms based on Non-impacting Control Dependencies|