Project-Level Resource Leak Detection through Agent-based Ownership Analysis and Repair Pattern Verification
Resource leaks cause system performance degradation and crashes. Traditional static analysis approaches rely on predefined rules, limiting their ability to find unknown leaks. Emerging LLM-based methods can locate APIs but face challenges in large-scale projects, including high costs and numerous false positives. To address these limitations, we propose AROP, the first project-level resource leak detection framework integrating LLM-based agents. AROP first extracts project-level metadata to efficiently filter resource-related files. It then employs a detection agent to identify acquisition/release operations, followed by a validation agent and data-flow dependency analysis to reduce false positives. Finally, it determines leaks through leak repair pattern analysis.
We evaluated the effectiveness of our tool on the JLeaks benchmark and 6 large-scale real-world open-source projects. On JLeaks, AROP achieved a recall of 66.1% with a precision of 91.0%, which outperformed the current state-of-the-art, INFERROI, surpassing it by 18.2% in precision while maintaining a comparable recall. In evaluation on real-world projects, AROP discovered 106 previously unknown resource leak defects with a precision of 71.3%. We submitted patches for 28 of these defects, all of which have been confirmed and merged by developers.
Thu 16 AprDisplayed time zone: Brasilia, Distrito Federal, Brazil change
16:00 - 17:30 | Dependability and Security 7Research Track at Oceania X Chair(s): Kaixuan Li Nanyang Technological University | ||
16:00 15mTalk | WhisperCatcher: Demystifying Unauthorized and Encrypted Private Data Transmission in Android ApplicationsDistinguished Paper Award Research Track Zhaoyu Qiu Xi'an Jiaotong University, Ming Fan Xi'an Jiaotong University, Bocan Ma Xi'an Jiaotong University, Yutian Tang University of Glasgow, United Kingdom, Lei Xue Sun Yat-Sen University, Haijun Wang Xi'an Jiaotong University, Ting Liu Xi'an Jiaotong University | ||
16:15 15mTalk | Exploring and Improving Real-World Vulnerability Data Generation via Prompting Large Language Models Research Track Guangbei Yi Washington State University, Yu Nong University at Buffalo, SUNY, Minzhang Li Washington State University, Haipeng Cai University at Buffalo, SUNY DOI Pre-print Media Attached File Attached | ||
16:30 15mTalk | TaintP2X: Detecting Taint-Style Prompt-to-Anything Injection Vulnerabilities in LLM-Integrated Applications Research Track HeJunjie , Shenao Wang Huazhong University of Science and Technology, Yanjie Zhao Huazhong University of Science and Technology, Xinyi Hou Huazhong University of Science and Technology, Zhao Liu 360 AI Security Lab, Quanchen Zou 360 AI Security Lab, Haoyu Wang Huazhong University of Science and Technology | ||
16:45 15mTalk | CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web Applications Research Track Yichao Xu , Mingqing Kang Johns Hopkins University, Neil Thimmaiah University of Illinois Chicago, Rigel Gjomemo University of Illinois Chicago, V. N. Venkatakrishnan University of Illinois Chicago, Yinzhi Cao Johns Hopkins University | ||
17:00 15mTalk | Project-Level Resource Leak Detection through Agent-based Ownership Analysis and Repair Pattern Verification Research Track Chengxin Xu Institute of Information Engineering, Chinese Academy of Sciences, xiu zhang Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China, Xiaorui Gong Institute of Information Engineering, Chinese Academy of Science Media Attached | ||
17:15 15mTalk | Understanding DevOps Security of Google Workspace Apps Research Track Liuhuo Wan , Chuan Yan University of Queensland, Zicong Liu University of Queensland, Haoyu Wang Huazhong University of Science and Technology, Guangdong Bai City University of Hong Kong Media Attached | ||