api specification inference

Designs and implements tools and models that analyze observed API interactions (for example request/response logs or network traces) to reconstruct endpoint interfaces, parameter and message schemas, and operation semantics. Develops methods for automatic API discovery and schema inference, including extraction of types, optionality, enumerations, and stateful interaction patterns to produce machine-readable API specifications or service contracts.

apispecificationinference

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.46
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the poor robustness of existing API discovery methods under mixed runtime traffic—such as scenarios where multiple applications share a common observation point—where static approaches suffer from high false-positive rates due to source code dependencies, and dynamic black-box techniques exhibit degraded accuracy in complex environments. To overcome these limitations, we propose APISENSOR, an unsupervised black-box framework that accurately reconstructs Web APIs from mixed traffic through traffic denoising and normalization, graph-based structural modeling, and a two-stage clustering strategy. APISENSOR is the first approach to achieve high robustness in automatic API discovery under mixed traffic, significantly improving both precision and stability while also uncovering inconsistencies in official API documentation. Evaluations on over 10,000 requests across six real-world applications demonstrate an average cluster purity of 95.92% and an F1-score of 94.91%, with the lowest performance variance, substantially outperforming ten baseline methods.

API discoveryblack-box analysisruntime traffic

You Can REST Now: Automated Specification Inference and Black-Box Testing of RESTful APIs with Large Language Models

Feb 07, 2024
AD
Alix Decrop
🏛️ University of Namur | University of Luxembourg

REST API documentation frequently suffers from incompleteness, obsolescence, or inaccessibility, hindering both automated testing efficiency and human comprehension. This paper introduces the first LLM-driven, end-to-end framework for OpenAPI specification inference and black-box API testing—requiring only an API name and an LLM API key. It automatically generates and mutates HTTP requests, then infers specifications and detects defects via response analysis. A novel context-aware prompt masking strategy enables zero-shot discovery of undocumented routes and parameters without model fine-tuning. Evaluated on a standardized benchmark, the framework achieves 85.05% average recall for GET routes and 81.05% for query parameters, successfully uncovering hidden endpoints and diverse server-side errors (e.g., 5xx, logic flaws). The inferred OpenAPI specifications are directly compatible with mainstream API testing tools, enabling seamless integration into existing CI/CD and security validation pipelines.

Automate REST API documentation to reduce errors and save timeEnhance API testing efficiency with minimal user input requiredInfer and validate API routes and parameters using LLMs

This work addresses the challenge of maintaining up-to-date architectural documentation in microservice systems, which is exacerbated by polyglot implementations, multiple repositories, and rapid independent evolution. Existing static refactoring approaches are often limited to single-repository settings or homogeneous technology stacks. To overcome these limitations, we propose a distributed static architecture reconstruction framework that supports multi-language and multi-repository environments. The framework employs pluggable extractor modules for language-specific analysis and introduces mechanisms for cross-repository data propagation and fusion, enabling seamless interoperability with existing static analysis tools. To the best of our knowledge, this is the first framework to enable distributed, collaborative architecture reconstruction, significantly enhancing the scalability and usability of automated documentation generation and maintenance in complex microservice ecosystems.

architecture reconstructionmicroservicemulti-repository

Current RESTful API design quality assessment relies heavily on manual inspection, lacking early, automated validation mechanisms for non-functional requirements—particularly interoperability, modularity, and maintainability. Method: This paper proposes an OpenAPI-based static analysis approach that implements a configurable rule engine. It formalizes 75 design principles derived from scholarly literature and industry standards into structured, machine-checkable constraints, enabling customizable rule activation/deactivation and traceable feedback to align requirements engineering with architectural governance. Contribution/Results: Following the design science research paradigm, we developed and evaluated a prototype tool. Empirical evaluation and expert review demonstrate that the method significantly improves API design compliance and consistency, achieving 82% automation coverage. It effectively supports continuous architectural governance in agile development environments, bridging the gap between design-time assurance and operational API lifecycle management.

Automates validation of API design rules for interoperability and governanceDetects structural violations in OpenAPI specifications using configurable rulesOperationalizes design principles as verifiable constraints for quality assurance

Latest Papers

What's happening recently
View more

This work addresses the challenge of automatically recovering traceability links among software architecture documentation, models, and source code—a longstanding barrier to effective system maintenance and consistency assurance. To bridge this gap, we present the first end-to-end ecosystem for architecture-level traceability recovery, comprising a RESTful API supporting four distinct tracing pipelines, an interactive web-based frontend named TraceView, and TraceViz, an embedded visualization plugin for Visual Studio Code. The system integrates seamlessly into developer workflows through asynchronous task processing and caching optimizations, enabling intuitive exploration of traceability links directly within the IDE. All components are publicly deployed, and preliminary user studies indicate that TraceViz significantly enhances developers’ cognitive efficiency during software comprehension tasks.

consistency checkingsoftware architecturesoftware artifacts

This work addresses the challenges of manual Web API integration testing, which is time-consuming, error-prone, and often misaligned with business requirements. The authors propose a novel approach that synergistically combines large language models (LLMs), retrieval-augmented generation (RAG), and prompt engineering to jointly parse natural language business requirements and OpenAPI specifications, thereby automatically generating executable test scripts that are both semantically meaningful and syntactically correct. Evaluated on ten real-world APIs, the method successfully produced valid tests for 89% of the business requirements within three attempts, uncovered multiple previously unknown integration defects, and substantially reduced the manual effort required for test development.

API integration testsbusiness requirementsmanual testing

Existing tool interfaces based on static endpoints struggle to express long-running workflows involving complex control flows such as loops, conditional branches, and retries. This work proposes replacing static endpoints with executable tool programs, enabling explicit effect typing and sophisticated workflow control through constraint-guided program construction, effect-aware exactly-once replay mechanisms, and configuration-driven execution policies. Implemented atop MCP-style services and a WebAssembly sandbox, the system demonstrates significant performance improvements in real-world scenarios, reducing end-to-end latency by up to 53.4% and client-side traffic by as much as 96.1%, with particularly pronounced gains under high network latency or increased workflow complexity.

agentic web serviceslong-horizon workflowsstatic endpoints

This study addresses the reliability challenges of large language model (LLM) agents in tool invocation, particularly under constrained interaction budgets, where improper interface design often leads to misuse. For the first time, interface format is treated as an independent variable, and a controlled experiment systematically compares three contract representations—free-form documentation, JSON Schema, and schema augmented with structured diagnostic feedback—while holding semantic content constant. The evaluation employs a deterministic sandbox environment, structured validation diagnostics, and a fully crossed design across multiple models, random seeds, and budget levels. Results show that structured schemas significantly reduce syntactic misuse but fail to mitigate semantic errors. Critically, task success rates remain at zero across all conditions, revealing that semantic misjudgment and time constraints constitute the primary bottlenecks in current LLM-based tool use.

interaction budgetsinterface designLLM agents

Hot Scholars

TZ

Ting Zhang

Monash University
Software EngineeringCyber SecurityInformation Retrieval
AR

Abhik Roychoudhury

Professor of Computer Science, National University of Singapore
Program AnalysisSoftware SecurityAI Agents
DL

David Lo

Professor of Computer Science, Singapore Management University
AI4SESoftware AnalyticsSE4AISoftware Maintenance
SD

Serge Demeyer

University of Antwerp
Software EngineeringSoftware EvolutionTest Automation