Score
Designs and implements tools and analyses that collect runtime execution traces and inspect data and control flows to identify dependencies among program entities (for example events, callbacks, functions, or modules). Produces dependency graphs and impact reports that recommend which targets are affected by changes and reveal dependencies that static analyses miss.
Traditional impact analysis approaches rely on heuristic coupling metrics, which are often hindered by fragility, high execution overhead, or dependence on extensive change histories, limiting their ability to accurately predict the scope of code changes. This work proposes Athena, the first method to integrate program dependence graphs with Transformer-based deep semantic code representations to enable automated impact analysis without requiring execution traces or historical data. We introduce Alexandria, a high-quality benchmark dataset comprising 25 open-source projects, and train and evaluate our model on fine-grained bug-fixing commits. Experimental results demonstrate that Athena significantly outperforms existing methods on Alexandria, achieving a mean reciprocal rank (mRR) of 60.32%, mean average precision (mAP) of 35.19%, and HIT@10 of 81.48%—representing performance gains of 9.55% to 11.68%.
Existing program behavior prediction models struggle to effectively capture dynamic inter-statement dependencies, limiting their performance in code coverage prediction and runtime error detection. To address this, we propose a dual-path joint modeling framework: (1) a static path that encodes control dependencies via control flow graphs (CFGs) and graph neural networks; and (2) a dynamic path that learns temporal execution dependencies from program execution traces. Crucially, we introduce node-level dual-path embedding to enable fine-grained, unified representation of both static and dynamic dependencies. To the best of our knowledge, this is the first work to jointly and coherently model static control-flow dependencies and dynamic execution-time dependencies within a single framework. Evaluated on code coverage prediction and runtime error localization tasks, our approach achieves significant improvements over state-of-the-art methods—yielding a 12.3% gain in prediction accuracy and an 18.7% increase in error localization precision.
Existing program comprehension tools struggle to balance scalability and precision in static analysis. This paper addresses C# programs by proposing an interactive, progressive analysis framework: developers first employ lightweight interprocedural data-flow analysis to rapidly identify critical code subregions; subsequently, high-precision symbolic execution is selectively applied to those regions. The framework introduces a novel composable analysis and visualization architecture—inspired by Moldable Development—that enables on-demand assembly of customized comprehension tools directly within Visual Studio. Evaluated on real-world industrial case studies, the approach maintains analytical efficiency while significantly improving precision, thereby enhancing reasoning about complex code behaviors. Key contributions include (1) a progressive, developer-guided analysis paradigm that bridges coarse-grained scalability and fine-grained accuracy; (2) a modular, extensible architecture supporting tool composition without recompilation; and (3) empirical validation demonstrating substantial precision gains—up to 3.2× improvement in path-sensitive defect detection—without compromising analysis throughput.
Industrial applications heavily rely on open-source libraries, yet stalled community maintenance frequently leaves vulnerabilities unpatched for extended periods, posing critical software supply chain security risks. Existing approaches suffer from label scarcity, sparse feature representations, and incomplete modeling of transitive dependency relationships, hindering practical deployment in industrial settings. This paper proposes the first maintenance-activity monitoring framework that jointly models direct and transitive dependencies. It constructs fine-grained maintenance metrics from multi-source repository metadata—including commits, releases, issues, and pull requests—and introduces a graph propagation model to quantify the cross-dependency transmission of maintenance decay. Crucially, the method operates without manual labeling. Evaluated across multiple enterprise projects, it achieves early warning of high-risk stagnant libraries 3–6 months in advance, substantially reducing manual auditing effort and significantly enhancing the security and maintainability of open-source dependency ecosystems.
Java lacks runtime dependency introspection capabilities, hindering dynamic integrity verification in software supply chain security. To address this, we propose Classport, the first Java platform solution enabling configuration-free runtime dependency awareness. Classport leverages bytecode instrumentation to embed dependency metadata into class files at compile time and exploits the JVM’s class loading mechanism to dynamically extract and query actually loaded dependencies at runtime. This approach avoids false positives from static analysis and false negatives caused by reflection-based invocations, supporting fine-grained, on-demand dependency provenance. Evaluated on six real-world projects, Classport achieves 100% accuracy in identifying actively loaded runtime dependencies. It provides a lightweight, reliable, and deployable runtime assurance mechanism for software supply chain security—requiring no external configuration, toolchain modifications, or developer intervention.
Existing change impact analysis approaches rely solely on semantic similarity or structural dependencies, limiting their ability to comprehensively identify affected artifacts across heterogeneous software assets such as requirements, configurations, services, and tests. This work proposes a novel, training-free, and interpretable method that uniquely integrates semantic priors with multi-hop graph propagation. Specifically, it constructs a typed heterogeneous graph via static analysis, derives semantic priors from embedding-based cosine similarity, and diffuses impact through a row-normalized, decay-weighted propagation matrix controlled by a single parameter λ to balance precision and recall. Evaluation on five real-world change scenarios in a payment subsystem demonstrates the method’s capability to capture both structurally reachable yet textually disjoint artifacts and semantically related but structurally isolated ones, with demonstrated extensibility to operational assets such as container images and monitoring metrics.
This work addresses the challenge of accurately predicting downstream impacts of code changes in JavaScript, a language whose dynamic nature limits the effectiveness of traditional change impact analysis methods in both coverage and precision. To overcome these limitations, the authors propose Caprese, a novel framework that systematically integrates historical co-change mining with runtime dynamic dependency analysis, revealing their complementary strengths in change impact prediction. Caprese employs a hybrid recommendation strategy that fuses co-change patterns, dynamic program analysis, and multi-source signals. Evaluation on ten open-source Node.js projects demonstrates that while dynamic analysis achieves higher precision, historical analysis captures additional relevant changes missed by dynamic methods; their combination significantly enhances both the completeness and practical utility of impact recommendations.
Rust lacks a general-purpose dynamic analysis framework capable of supporting diverse runtime analyses. This work proposes DMIR, the first natively Rust-based, event-driven dynamic analysis infrastructure, which captures MIR-level semantics through compiler instrumentation and, for the first time, integrates high-level language features—such as ownership, types, and the memory model—into dynamic analysis. Runtime behaviors are exposed as structured event streams, enabling rich semantic introspection. Leveraging DMIR, we implement three classes of analysis tools: concolic execution, Rust-specific checkers, and control-flow tracing, demonstrating its expressiveness and practicality while maintaining acceptable runtime overhead.
Existing Datalog engines struggle to simultaneously achieve efficiency, scalability, and extensible semantics in static analysis, while also lacking robust support for rule debugging and incremental updates. This work proposes a novel approach that compiles Soufflé-style Datalog programs into executable Differential Dataflow programs, yielding a high-performance, memory-efficient static analysis framework capable of millisecond-scale incremental recomputation. The framework natively supports non-standard semantics—such as k-core analysis—and integrates in-browser performance profiling and rule-tuning capabilities. Evaluated on 24 real-world static analysis benchmarks, the system outperforms state-of-the-art engines in both runtime performance and scalability.