{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T20:56:55Z","timestamp":1774904215716,"version":"3.50.1"},"reference-count":50,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"crossref","award":["FT220100391 and DE250100192"],"award-info":[{"award-number":["FT220100391 and DE250100192"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2026,4,30]]},"abstract":"<jats:p>\n                    Static program analysis of real-world software that integrates numerous library Application Programming Interfaces (APIs) faces significant challenges due to inaccessible or highly complex source code. A common workaround is to use specifications that summarize the key behaviors of these APIs for analysis. However, manually writing specifications is labor-intensive and requires a deep understanding of API semantics, while existing automated specification generation techniques struggle when source code is inaccessible or partially available. This article introduces\n                    <jats:sc>Spectre<\/jats:sc>\n                    , an automated framework that leverages fuzzing techniques to generate aliasing specifications for library APIs.\n                    <jats:sc>Spectre<\/jats:sc>\n                    operates efficiently and precisely both with and without source code access. When source code is unavailable,\n                    <jats:sc>Spectre<\/jats:sc>\n                    integrates alias-check observers into the driver program after the API call site and performs black-box fuzzing to explore different API behaviors. If a check is satisfied, the corresponding aliasing specification is generated. When source code is available,\n                    <jats:sc>Spectre<\/jats:sc>\n                    incorporates new grey-box fuzzing features specifically tailored for aliasing specification inference, further enhancing its ability to generate aliasing specifications. We conducted extensive experiments to evaluate the performance of\n                    <jats:sc>Spectre<\/jats:sc>\n                    . Without source code access,\n                    <jats:sc>Spectre<\/jats:sc>\n                    demonstrated its specification generation capability across both Musl, a lightweight C standard library, and eight C third-party libraries. For Musl,\n                    <jats:sc>Spectre<\/jats:sc>\n                    recovered 96.7% of correct manually written specifications and identified 40.0% more aliasing specifications than those written by external experts. For C third-party libraries, all\n                    <jats:sc>Spectre<\/jats:sc>\n                    -generated aliasing specifications were validated as correct through static analysis of the API source code.\n                    <jats:sc>Spectre<\/jats:sc>\n                    is also more complete than other specification inference tools, generating 16.7% more correct specifications for third-party libraries. The practicality of the generated specifications was confirmed, as they improved aliasing analysis in static pointer analysis of client code while maintaining a balance between accuracy and efficiency. The effectiveness of the tailored grey-box fuzzing features was demonstrated by\n                    <jats:sc>Spectre<\/jats:sc>\n                    , identifying 20% more specifications compared to when these features were disabled. These results show that\n                    <jats:sc>Spectre<\/jats:sc>\n                    is an effective tool for inferring aliasing specifications and facilitating static analysis.\n                  <\/jats:p>","DOI":"10.1145\/3725811","type":"journal-article","created":{"date-parts":[[2025,6,2]],"date-time":"2025-06-02T11:49:11Z","timestamp":1748864951000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["<scp>Spectre<\/scp>\n                    : Automated Aliasing Specification Generation for Library APIs with Fuzzing"],"prefix":"10.1145","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2807-1420","authenticated-orcid":false,"given":"Shuangxiang","family":"Kan","sequence":"first","affiliation":[{"name":"University of New South Wales, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4382-0757","authenticated-orcid":false,"given":"Yuekang","family":"Li","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-2086-7034","authenticated-orcid":false,"given":"Weigang","family":"He","sequence":"additional","affiliation":[{"name":"University of Technology Sydney, Sydney, Australia and University of New South Wales, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7663-1421","authenticated-orcid":false,"given":"Zhenchang","family":"Xing","sequence":"additional","affiliation":[{"name":"CSIRO\u2019s Data61, Canberra, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5839-3765","authenticated-orcid":false,"given":"Liming","family":"Zhu","sequence":"additional","affiliation":[{"name":"CSIRO\u2019s Data61 and Australian National University, Canberra, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9510-6574","authenticated-orcid":false,"given":"Yulei","family":"Sui","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,3,12]]},"reference":[{"key":"e_1_3_3_2_2","unstructured":"GitHub. 2024. SVF: Static Value-Flow Analysis Framework for Source Code. Retrieved from https:\/\/github.com\/SVF-tools\/SVF"},{"key":"e_1_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/2914770.2837628"},{"key":"e_1_3_3_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/565816.503275"},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884816"},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594299"},{"key":"e_1_3_3_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2372785"},{"key":"e_1_3_3_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/2676726.2676977"},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3192366.3192383"},{"key":"e_1_3_3_10_2","volume-title":"Proceedings of the 33rd European Conference on Object-Oriented Programming (ECOOP \u201919)","author":"Bastani Osbert","year":"2019","unstructured":"Osbert Bastani, Rahul Sharma, Lazaro Clapp, Saswat Anand, and Alex Aiken. 2019. Eventually sound points-to analysis with specifications. In Proceedings of the 33rd European Conference on Object-Oriented Programming (ECOOP \u201919). Schloss Dagstuhl-Leibniz-Zentrum fuer Informatik."},{"key":"e_1_3_3_11_2","unstructured":"Eli Bendersky. 2023. pycparser. Retrieved from https:\/\/github.com\/eliben\/pycparser"},{"key":"e_1_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978428"},{"key":"e_1_3_3_13_2","first-page":"209","volume-title":"Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","volume":"8","author":"Cadar Cristian","year":"2008","unstructured":"Cristian Cadar, Daniel Dunbar, and Dawson R. Engler. 2008. KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs. In Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation (OSDI), Vol. 8, 209\u2013224."},{"key":"e_1_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250789"},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/2771783.2771810"},{"key":"e_1_3_3_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2019.00015"},{"key":"e_1_3_3_17_2","volume-title":"The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities","author":"Dowd Mark","year":"2006","unstructured":"Mark Dowd, John McDonald, and Justin Schuh. 2006. The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Pearson Education."},{"key":"e_1_3_3_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/SBFT59156.2023.00022"},{"key":"e_1_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3314221.3314640"},{"key":"e_1_3_3_20_2","volume-title":"Proceedings of the 14th USENIX Workshop on Offensive Technologies (WOOT \u201920)","author":"Fioraldi Andrea","year":"2020","unstructured":"Andrea Fioraldi, Dominik Maier, Heiko Ei\u00dffeldt, and Marc Heuse. 2020. AFL++: Combining incremental steps of fuzzing research. In Proceedings of the 14th USENIX Workshop on Offensive Technologies (WOOT \u201920). USENIX Association."},{"key":"e_1_3_3_21_2","unstructured":"Watson Libraries for Analysis. 2018. WALA. Retrieved from https:\/\/github.com\/wala\/WALA"},{"key":"e_1_3_3_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/2093548.2093564"},{"key":"e_1_3_3_23_2","first-page":"151","volume-title":"Proceedings of the Symposium on Network and Distributed System Security (NDSS)","volume":"8","author":"Godefroid Patrice","year":"2008","unstructured":"Patrice Godefroid, Michael Y. Levin, and David A. Molnar. 2008. Automated whitebox fuzz testing. In Proceedings of the Symposium on Network and Distributed System Security (NDSS), Vol. 8, 151\u2013166."},{"key":"e_1_3_3_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2011.5764696"},{"key":"e_1_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/567752.567776"},{"key":"e_1_3_3_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2024.3392254"},{"key":"e_1_3_3_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"e_1_3_3_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416558"},{"key":"e_1_3_3_29_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-018-0002-y"},{"key":"e_1_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338975"},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2018.2834476"},{"key":"e_1_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/1543135.1542485"},{"key":"e_1_3_3_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/2644805"},{"key":"e_1_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/1181775.1181808"},{"key":"e_1_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510120"},{"key":"e_1_3_3_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00112"},{"key":"e_1_3_3_37_2","unstructured":"musl libc Team. 2023. musl C Library. Retrieved from https:\/\/musl.libc.org\/"},{"key":"e_1_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/1273442.1250749"},{"key":"e_1_3_3_39_2","unstructured":"Abhishek Arya Oliver Chang Jonathan Metzman Kostya Serebryany and Dongge Liu. 2023. OSS-Fuzz. Retrieved from https:\/\/github.com\/google\/oss-fuzz"},{"key":"e_1_3_3_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/1273463.1273487"},{"key":"e_1_3_3_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250748"},{"key":"e_1_3_3_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380390"},{"key":"e_1_3_3_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"e_1_3_3_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/2338965.2336784"},{"key":"e_1_3_3_45_2","volume-title":"Fuzzing: Brute Force Vulnerability Discovery","author":"Sutton Michael","year":"2007","unstructured":"Michael Sutton, Adam Greene, and Pedram Amini. 2007. Fuzzing: Brute Force Vulnerability Discovery. Pearson Education."},{"key":"e_1_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.5555\/3275309"},{"key":"e_1_3_3_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3660816"},{"key":"e_1_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-31980-1_30"},{"key":"e_1_3_3_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380396"},{"key":"e_1_3_3_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3178372.3179517"},{"key":"e_1_3_3_51_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-03542-0_21"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3725811","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T15:07:18Z","timestamp":1773328038000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3725811"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,12]]},"references-count":50,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2026,4,30]]}},"alternative-id":["10.1145\/3725811"],"URL":"https:\/\/doi.org\/10.1145\/3725811","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,12]]},"assertion":[{"value":"2024-09-20","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-25","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}