Score
Designs and builds tools and techniques to insert hooks, probes, and code transformations into compiled programs and their execution environments so practitioners can observe, measure, modify, or emulate program behavior at runtime. This encompasses static and dynamic binary and compiler instrumentation, lightweight/low‑overhead logging and tracing, timing and pipeline probes, sandbox and simulator hooks, environment and hardware fault emulation, and mechanisms to alter memory or data layouts for experiments.
Existing debugging tools excel at verifying hypotheses but struggle to support hypothesis generation, as programmers must manually reconstruct the program’s state evolution. This work proposes a novel debugging paradigm centered on complete execution traces, leveraging program tracing techniques to record and temporally visualize the actual code paths executed, rather than relying on the static structure of the source code. By presenting runtime behavior in a chronological and contextualized manner, this approach significantly enhances the comprehensibility of program execution, thereby facilitating more efficient hypothesis generation during debugging. We implement a prototype system and conduct preliminary experiments that demonstrate its effectiveness in improving program understanding efficiency, while also uncovering key challenges and promising directions for future research.
WebAssembly debugging and monitoring face three key challenges: tool fragmentation, high overhead from generic instrumentation frameworks, and the labor-intensive development of low-level, high-performance probes. This paper introduces Whamm—the first declarative instrumentation DSL tailored for WebAssembly—unifying bytecode rewriting and engine-internal support to jointly optimize abstraction and performance. Its core contributions are: (1) a programming model based on declarative matching rules, static/dynamic predicates, and automatic state reporting; and (2) deep integration with Wasm runtimes, enabling inline probes and intrinsification optimizations. Evaluated across diverse monitoring tasks, Whamm delivers expressive power comparable to manual implementations while achieving near-native performance, significantly reducing instrumentation overhead. It maintains compatibility with mainstream Wasm runtimes and supports seamless cross-platform deployment.
Debugging embedded programs is notoriously challenging due to tight software-hardware coupling, and existing tools often rely on external hardware probes or serial logging, resulting in low efficiency. This work proposes Inline, a novel programming tool that, for the first time, enables real-time inline visualization of hardware logs directly within source code. It introduces a domain-specific expression language to support programmable manipulation of logs, allowing developers to intuitively trace execution flow and precisely localize faults. Seamlessly integrated into standard embedded development environments, Inline significantly lowers the barrier to effective debugging. A user study with twelve participants demonstrates marked improvements in both debugging efficiency and accuracy when using the tool.
Dynamic binary instrumentation (DBI) techniques suffer from heterogeneous implementation mechanisms and a lack of unified evaluation frameworks, making it difficult to balance applicability and performance in practice. Method: This paper proposes the first cross-layer DBI taxonomy, systematically unifying process-level and full-system-level approaches. It decomposes DBI into core building blocks—such as instruction rewriting and transparent instrumentation—and characterizes their capabilities for instrumenting critical runtime events (e.g., function calls, exceptions, memory accesses). A standardized performance evaluation model is developed to empirically benchmark mainstream DBI tools across multiple scenarios, measuring overhead, coverage, and compatibility. Contribution/Results: Empirical analysis reveals clear performance trade-offs among DBI paradigms, with no universally optimal solution. The study establishes a theoretical foundation and empirical benchmark for informed DBI tool selection, enabling precise deployment in security analysis, performance debugging, and related domains.
Programming heterogeneous exascale HPC systems is hindered by the proliferation of complex, incompatible programming models (e.g., CUDA, SYCL, OpenMP) and the lack of traceability across CPU/GPU execution contexts. Method: We propose the first semantic-aware, full-stack API tracing framework built upon LTTng kernel tracing, integrating user-space dynamic instrumentation with multi-model API signature parsing to capture fine-grained, low-overhead, configurable API call chains across hardware and programming abstractions. Contribution/Results: Unlike conventional tracers logging only function names and timestamps, our framework enables cross-vendor, cross-abstraction behavioral correlation and end-to-end call-chain reconstruction in real HPC applications. It accurately identifies cross-model performance bottlenecks and implementation flaws, improving debugging efficiency by over 3× and significantly enhancing portability and debuggability of heterogeneous programming models.
This work proposes the SpaceTime programming model to address the longstanding disconnect between static code and dynamic execution in conventional programming environments, which hinders simultaneous exploration of code modifications and runtime behavior. SpaceTime unifies, for the first time, three major paradigms—exploratory programming, live programming, and omniscient debugging—by capturing fine-grained traces that jointly record code variants and execution states. This enables bidirectional, traceable linkage across both spatial (code) and temporal (execution) dimensions. Implemented as a Python library, SpaceTimePy, the approach is validated through five real-world projects, successfully supporting an omniscient debugger and a Pygame-based game development tool. Empirical evaluation shows a performance overhead of 35%–150% across test suites, demonstrating its practical feasibility.
This work addresses the limitations of traditional structural coverage metrics in embedded software testing, which are often confined to the unit level and fail to reflect true coverage completeness in integration and system testing. Instrumentation-based approaches risk perturbing runtime behavior, while pure tracing techniques suffer from unreliability under high compiler optimization. To overcome these challenges, the paper proposes an integration-test-driven coverage strategy featuring a novel “integration-first” closed-loop workflow. By synergistically combining embedded tracing with hybrid runtime analysis (hRA) to preserve semantic boundaries, and leveraging source-to-target mapping for evidential traceability alongside Hyper Coverage for cross-variant merging, the approach establishes a unified evidence-integration mechanism. Evaluated on -O3-optimized release binaries, it reliably achieves branch, condition, and MC/DC coverage measurements and precisely identifies source code lines consistently uncovered across all variants, thereby significantly enhancing confidence in the test completeness of embedded systems.
Traditional static analysis struggles to balance precision, reliability, and automation, limiting its practical applicability. This work proposes a novel parameterized static analysis approach that introduces user-provided local assumptions at selected program locations and incorporates them via a nondeterministic semantics, thereby constructing a mapping from sets of assumptions to analysis results. This formulation enables optimization-based search over large assumption spaces, overcoming conventional precision bottlenecks. The method’s effectiveness is demonstrated through experiments in two representative scenarios, significantly enhancing the adaptability and flexibility of static analysis in real-world applications.
This work addresses the unreliability of disassembly caused by the absence of compiler-intended semantic information in stripped binary executables. To overcome this limitation, the authors propose a novel lightweight metadata embedding mechanism that explicitly encodes critical semantics—such as code regions and memory boundaries—directly into the binary. This approach yields a decidable intermediate representation situated between raw binaries and source code. For the first time, it enables disassembly that is both decidable and recompilable, facilitating precise lifting to high-level intermediate representations. Experimental evaluation demonstrates that the embedded metadata incurs only 17% of the size overhead of DWARF debug information, introduces no runtime performance penalty, and successfully supports behavior-preserving binary lifting, instrumentation, and recompilation across a wide range of real-world C/C++ programs.
Existing Datalog engines struggle to simultaneously achieve efficiency, scalability, and extensible semantics in static analysis, while also lacking robust support for rule debugging and incremental updates. This work proposes a novel approach that compiles Soufflé-style Datalog programs into executable Differential Dataflow programs, yielding a high-performance, memory-efficient static analysis framework capable of millisecond-scale incremental recomputation. The framework natively supports non-standard semantics—such as k-core analysis—and integrates in-browser performance profiling and rule-tuning capabilities. Evaluated on 24 real-world static analysis benchmarks, the system outperforms state-of-the-art engines in both runtime performance and scalability.