Static program analysis plays an essential role in program optimization, bug detection, and debugging. However, reliance on compilation and limited customization hinder its adoption in the real world. This paper presents a compositional neuro-symbolic approach named NESA that facilitates compilation-free and customizable static program analysis using large language models (LLMs) with mitigated hallucinations. Specifically, we propose an analysis policy language, a restricted form of Datalog, to support users decomposing a static program analysis problem into several sub-problems that target simpler syntactic or semantic properties upon smaller code snippets. The problem decomposition enables the LLMs to target more manageable semantic-related sub-problems with reduced hallucinations, while the syntactic ones are resolved by parsing-based analysis without hallucinations. An analysis policy then is evaluated with lazy and incremental prompting, which significantly mitigates the hallucinations and improves the performance. We evaluate NESA for program slicing and bug detection upon benchmark and real-world programs. Evaluation results show that while NESA supports compilation-free and customizable analysis, it can still achieve comparable and even better performance than existing techniques. In a customized taint vulnerability detection upon TaintBench, for example, NESA achieves a precision of 66.27%, a recall of 78.57%, and an F1 score of 0.72, surpassing an industrial approach by 0.20 in F1 score. NESA also detects 13 real-world memory leak bugs, which have been fixed by developers.
Tue 7 JulDisplayed time zone: Eastern Time (US & Canada) change
11:00 - 12:30 | Program Analysis 1Research Papers / Tool Demonstrations at MB 5.215 Chair(s): Martin Kellogg New Jersey Institute of Technology | ||
11:00 20mTalk | NESA: Relational Neuro-Symbolic Static Program Analysis Research Papers Chengpeng Wang National University of Singapore, Yifei Gao Purdue University, Wuqi Zhang MegaETH, Xuwei Liu Purdue University, USA, Jinyao Guo Purdue University, Mingwei Zheng Purdue University, Qingkai Shi Nanjing University, Xiangyu Zhang Purdue University | ||
11:20 10mTalk | Path-Guider: An IDE-based Agentic AI Tool for Path-based COBOL Program Analysis Tool Demonstrations Sameer Pimparkhede IBM Research, Pankaj Kumar Kalita IBM Research, Diptikalyan Saha IBM Research, Toshiaki Yasue IBM Research - Tokyo, Fumiko Satoh IBM Research - Tokyo | ||
11:30 20mTalk | JavaScript Pointer Analysis with Adaptive Heap Abstraction Research Papers Pre-print | ||
11:50 20mTalk | Large Language Models for Opaque Predicate Resolution: A Universal Control Flow Deobfuscation Framework Research Papers Xiao Chen , Wang Qiuyun Institute of Information Engineering, Chinese Academy of Sciences;and University of Chinese Academy of Sciences, Wang Shuwei Institute of Information Engineering, Chinese Academy of Sciences;and University of Chinese Academy of Sciences, Zhang Weize Institute of Information Engineering, Chinese Academy of Sciences;and University of Chinese Academy of Sciences, Yuling Liu Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences} \city{Beijing, Baoxu Liu Institute of Information Engineering, Chinese Academy of Sciences, Jiang Zhengwei Institute of Information Engineering, Chinese Academy of Sciences;and University of Chinese Academy of Sciences | ||
12:10 20mTalk | GPU-Accelerated Flow-Sensitive Pointer Analysis for C/C++ Programs Research Papers | ||