{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T20:54:03Z","timestamp":1770238443300,"version":"3.49.0"},"reference-count":55,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2024,7,12]],"date-time":"2024-07-12T00:00:00Z","timestamp":1720742400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"publisher","award":["DP210102409 and DP240103194"],"award-info":[{"award-number":["DP210102409 and DP240103194"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2024,7,12]]},"abstract":"<jats:p>C++ is crucial in software development, providing low-level memory control for performance and supporting object-oriented programming to construct modular, reusable code structures. Consequently, tackling pointer analysis for C++ becomes challenging, given the need to address these two fundamental features. A relatively unexplored research area involves the handling of C++ member function pointers. Previous efforts have tended to either disregard this feature or adopt a conservative approach, resulting in unsound or imprecise results.<\/jats:p>\n                  <jats:p>\n                    C++ member function pointers, handling both virtual (via virtual table indexes) and non-virtual functions (through addresses), pose a significant challenge for pointer analysis due to the mix of integers and pointers, often resulting in unsound or imprecise analysis. We introduce T\n                    <jats:sc>ips<\/jats:sc>\n                    , the first pointer analysis that effectively manages both pointers and integers, offering support for C++ member function pointers by tracking their value flows. Our evaluation on T\n                    <jats:sc>ips<\/jats:sc>\n                    demonstrates its accuracy in identifying C++ member function call targets, a task where other tools falter, across fourteen large C++ programs from SPEC CPU, Qt, LLVM, Ninja, and GoogleTest, while maintaining low analysis overhead. In addition, our micro-benchmark suite, complete with ground truth data, allows for precise evaluation of points-to information for C++ member function pointers across various inheritance scenarios, highlighting T\n                    <jats:sc>ips<\/jats:sc>\n                    \u2019s precision enhancements.\n                  <\/jats:p>","DOI":"10.1145\/3660779","type":"journal-article","created":{"date-parts":[[2024,7,12]],"date-time":"2024-07-12T10:22:09Z","timestamp":1720779729000},"page":"1609-1631","source":"Crossref","is-referenced-by-count":1,"title":["TIPS: Tracking Integer-Pointer Value Flows for C++ Member Function Pointers"],"prefix":"10.1145","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3371-2138","authenticated-orcid":false,"given":"Changwei","family":"Zou","sequence":"first","affiliation":[{"name":"UNSW Sydney, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0304-8942","authenticated-orcid":false,"given":"Dongjie","family":"He","sequence":"additional","affiliation":[{"name":"UNSW Sydney, Sydney, Australia"},{"name":"Chongqing University, Chongqing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9510-6574","authenticated-orcid":false,"given":"Yulei","family":"Sui","sequence":"additional","affiliation":[{"name":"UNSW Sydney, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0380-3506","authenticated-orcid":false,"given":"Jingling","family":"Xue","sequence":"additional","affiliation":[{"name":"UNSW Sydney, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,7,12]]},"reference":[{"key":"e_1_3_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_3_1_3_1","first-page":"111","volume-title":"PhD Dissertation","author":"Andersen Lars Ole","year":"1994","unstructured":"Lars OleAndersen. 1994. Program Analysis and Specialization for the C Programming Language. In PhD Dissertation. University of Copenhagen, Denmank, 111\u2013152."},{"key":"e_1_3_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594299"},{"key":"e_1_3_1_5_1","unstructured":"Avast. 2024. A Retargetable Machine-Code Decompiler Based on LLVM. https:\/\/github.com\/avast\/retdec. Accessed May 10 2024."},{"key":"e_1_3_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53413-7_5"},{"key":"e_1_3_1_7_1","first-page":"209","volume-title":"Symposium on Operating Systems Design and Implementation","author":"Cadar Cristian","year":"2008","unstructured":"CristianCadar, DanielDunbar, Dawson REngler, et al. 2008. KLEE: Unassisted and Automatic Generation of High\u00acCoverage Tests for Complex Systems Programs. In Symposium on Operating Systems Design and Implementation. USENIX Association, USA, 209\u2013224."},{"key":"e_1_3_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3453483.3454099"},{"key":"e_1_3_1_9_1","unstructured":"The GoogleTest Open-Source Community. 2024a. Google Testing and Mocking Framework. https:\/\/github.com\/google\/googletest.Accessed May 10 2024."},{"key":"e_1_3_1_10_1","unstructured":"The LLVM Open-Source Community. 2024b. The LLVM Project. https:\/\/github.com\/llvm\/llvm-project.Accessed May 10 2024."},{"key":"e_1_3_1_11_1","unstructured":"The Ninja Open-Source Community. 2024c. Ninja. https:\/\/github.com\/ninja-build\/ninja.Accessed May 10 2024."},{"key":"e_1_3_1_12_1","unstructured":"The Qt Company. 2024. Qt Base. https:\/\/github.com\/qt\/qtbase.Accessed May 10 2024."},{"key":"e_1_3_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417251"},{"key":"e_1_3_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3092703.3092729"},{"key":"e_1_3_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395363.3397368"},{"key":"e_1_3_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236028"},{"key":"e_1_3_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1594834.1480911"},{"key":"e_1_3_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2011.5764696"},{"key":"e_1_3_1_19_1","doi-asserted-by":"publisher","DOI":"10.4230\/DARTS.8.2.6"},{"key":"e_1_3_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3498720"},{"key":"e_1_3_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134062"},{"key":"e_1_3_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2813885.2738005"},{"key":"e_1_3_1_23_1","first-page":"5055","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"Koschel Jakob","year":"2023","unstructured":"JakobKoschel, PietroBorrello, Daniele ConoD\u2019Elia, HerbertBos, and CristianoGiuffrida. 2023. Uncontained: Uncovering Container Confusion in the Linux Kernel. In Proceedings of the 32nd USENIX Security Symposium. USENIX Association, USA, 5055\u20135072."},{"key":"e_1_3_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950291"},{"key":"e_1_3_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/977395.977673"},{"key":"e_1_3_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1273442.1250766"},{"key":"e_1_3_1_27_1","first-page":"153","volume-title":"Proceedings of the 12th International Conference on Compiler Construction","author":"Lhot\u00e1 Ond\u0159ej","year":"2003","unstructured":"Ond\u0159ejLhot\u00e1 and LaurieHendren. 2003. Scaling Java Points-To Analysis using Spark. In Proceedings of the 12th International Conference on Compiler Construction. Springer, USA, 153\u2013169."},{"key":"e_1_3_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3276988"},{"key":"e_1_3_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3571228"},{"key":"e_1_3_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3527332"},{"key":"e_1_3_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510075"},{"key":"e_1_3_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2931037"},{"key":"e_1_3_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/940071"},{"key":"e_1_3_1_34_1","unstructured":"LLVM. 2024. LLVM Language Reference Manual. https:\/\/llvm.org\/docs\/LangRef.html. Accessed May 10 2024."},{"key":"e_1_3_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360574"},{"key":"e_1_3_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3591242"},{"key":"e_1_3_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1044834.1044835"},{"key":"e_1_3_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594318"},{"key":"e_1_3_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1290520.1290524"},{"key":"e_1_3_1_40_1","unstructured":"TristanRavitch. 2024. Whole Program LLVM. https:\/\/github.com\/travitch\/whole-program-llvm.Accessed May 10 2024."},{"key":"e_1_3_1_41_1","first-page":"393","volume-title":"International Conference on Tools and Algorithms for the Construction and Analysis of Systems","author":"Schubert Philipp Dominik","year":"2019","unstructured":"Philipp DominikSchubert, BenHermann, and EricBodden. 2019. PhASAR: An Inter-Procedural Static Analysis Framework for C\/C++. In International Conference on Tools and Algorithms for the Construction and Analysis of Systems. Springer, USA, 393\u2013410."},{"key":"e_1_3_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3192366.3192418"},{"key":"e_1_3_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1925844.1926390"},{"key":"e_1_3_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2013.6494978"},{"key":"e_1_3_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950296"},{"key":"e_1_3_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"e_1_3_1_47_1","unstructured":"YuleiSui and JinglingXue. 2024. SVF. https:\/\/github.com\/SVF-tools\/SVF.Accessed May 10 2024."},{"key":"e_1_3_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2338965.2336784"},{"key":"e_1_3_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2302311"},{"key":"e_1_3_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3410246"},{"key":"e_1_3_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180251"},{"key":"e_1_3_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00208"},{"key":"e_1_3_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180178"},{"key":"e_1_3_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772954.1772985"},{"key":"e_1_3_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3178372.3179517"},{"key":"e_1_3_1_56_1","unstructured":"ChangweiZou. 2024. Tips. https:\/\/github.com\/sheisc\/Tips.git.Accessed May 10 2024."}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3660779","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3660779","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T08:02:36Z","timestamp":1770192156000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3660779"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,12]]},"references-count":55,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2024,7,12]]}},"alternative-id":["10.1145\/3660779"],"URL":"https:\/\/doi.org\/10.1145\/3660779","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7,12]]}}}