ASE 2025
Sun 16 - Thu 20 November 2025 Seoul, South Korea
Wed 19 Nov 2025 16:40 - 16:50 at Grand Hall 2 - Testing & Analysis 4 Chair(s): Fabrizio Pastore

Database connectors are critical components that enable applications to interact with database management systems (DBMS) but their security vulnerabilities are often neglected. Unlike traditional software defects, connector vulnerabilities exhibit subtle behavioral patterns and are inherently challenging to detect. Moreover, non-standardized implementation of connectors leaves potential risks (\ie unsafe implementations) but is more elusive. As a result, existing fuzzing methods are ineffective in finding such vulnerabilities. Even large language model (LLM)-based methods are still incapable of generating test cases that can invoke all the interface and internal logic of database connectors due to a lack of domain knowledge.

In this paper, we propose a new LLM-based test case generation method guided by reinforcement learning (RL) for database connector testing. Specifically, to equip the LLM with sufficient and appropriate domain knowledge, a parameterized template is composed for prompt construction. The LLM then generates test cases instructed by the constructed prompts, which are dynamically evaluated through differential testing across multiple connectors. The testing process is carried out iteratively, where RL is adopted to select the optimal prompt in each round based on behavioral feedback from the previous rounds, in order to maximize the efficiency of discovering inconsistencies. We implement the aforementioned methodology and evaluate it on two widely used JDBC connectors: MySQL Connector/J and OceanBase Connector/J. In the preliminary results, we have reported 16 bugs, among which 10 are officially confirmed, and the rest are acknowledged as unsafe implementations.

Wed 19 Nov

Displayed time zone: Seoul change

16:00 - 17:00
Testing & Analysis 4Industry Showcase / NIER at Grand Hall 2
Chair(s): Fabrizio Pastore University of Luxembourg
16:00
10m
Talk
Minuku: Detecting Diverse Display Issues in Mobile Apps with Small-scale Dataset
Industry Showcase
Yongxiang Hu Fudan University, Ke Liu College of Computer Science and Artificial Intelligence, Fudan University, Hailiang Jin Meituan Inc., Shiyu Guo Meituan, Juxing Yuan Meituan Inc., Xin Wang Fudan University, Yangfan Zhou Fudan University
16:10
10m
Talk
HarmoBridge: Bridging ArkTS and C/C++ for Cross-Language Static Analysis on HarmonyOS
Industry Showcase
Jiale Wu Huazhong University of Science and Technology, Jiapeng Deng Huazhong University of Science and Technology, Yanjie Zhao Huazhong University of Science and Technology, Li Li Beihang University, Haoyu Wang Huazhong University of Science and Technology
16:20
10m
Talk
From Redundancy to Efficiency: Exploiting Shared UI Interactions towards Efficient LLM-Based Testing
Industry Showcase
Xuan Wang Fudan University, Yingchuan Wang School of Computer Science, Fudan University, Yongxiang Hu Fudan University, Yu Zhang Meituan, Hailiang Jin Meituan Inc., Shiyu Guo Meituan, Juxing Yuan Meituan Inc., Yangfan Zhou Fudan University
16:30
10m
Talk
Securing Millions of Decentralized Identities in Alipay Super App with End-to-End Formal Verification
Industry Showcase
Ziyu Mao Zhejiang University, Xiaolin Ma Zhejiang University, Lin Huang Ant Group, Huan Yang Ant Group, Wu Zhang Ant Group, Weichao Sun Ant Group, Yongtao Wang Ant Group, Jingling Xue University of New South Wales, Jingyi Wang Zhejiang University
16:40
10m
Talk
LLM-based Dynamic Differential Testing for Database Connectors with Reinforcement Learning-Guided Prompt Selection
NIER
Ce Lyu East China Normal University, Yanhao Wang East China Normal University, Jie Liang Beihang University, Minghao Zhao East China Normal University
16:50
10m
Talk
LLM-assisted Industrial-Scale Differential Testing of Package Incompatibilities in Linux Distributions
Industry Showcase
Yuhao Yang Central South University, Chijin Zhou East China Normal University, Runzhe Wang Alibaba Group, Weibo Zhang Central South University, Yuheng Shen Tsinghua University, Xiaohai Shi Alibaba Group, Tao Ma Alibaba Group, Chang Gao Alibaba Group, Zhe Wang Institute of Computing Technology at Chinese Academy of Sciences; Zhongguancun Laboratory, Ying Fu Tsinghua University, Heyuan Shi Central South University