{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T08:42:28Z","timestamp":1780994548310,"version":"3.54.1"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"ISSTA","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2025,6,22]]},"abstract":"<jats:p>LLVM Intermediate Representation (IR) underpins the LLVM compiler infrastructure, offering a strong type system and a static single-assignment (SSA) form that are well-suited for program analysis. However, its single-type design assigns exactly one type to each IR variable, even when the variable may legitimately correspond to multiple types. The recent introduction of opaque pointers exacerbates this limitation: all pointers in the IR are uniformly represented with a generic pointer type (ptr) that erases concrete pointee type information, making many type-based analyses ineffective.<\/jats:p>\n          <jats:p>To address the limitations of single-type design, we introduce type-alias analysis, a multiple-type design that maintains type-alias sets for IR variables and infers types across IR instructions. We have developed TypeCopilot, a prototype that recovers concrete pointee types for opaque-pointer-enabled LLVM IR generated from C programs. TypeCopilot achieves 98.57% accuracy with 94.98% coverage, allowing existing analysis tools to retain their effectiveness despite the adoption of opaque pointers. To foster further research and security applications, we have open-sourced TypeCopilot, providing the community with a practical foundation for precise, type-aware security analyses on modern LLVM IR.<\/jats:p>","DOI":"10.1145\/3728974","type":"journal-article","created":{"date-parts":[[2025,6,22]],"date-time":"2025-06-22T10:52:56Z","timestamp":1750589576000},"page":"2203-2226","source":"Crossref","is-referenced-by-count":2,"title":["Type-Alias Analysis: Enabling LLVM IR with Accurate Types"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-1725-7371","authenticated-orcid":false,"given":"Jinmeng","family":"Zhou","sequence":"first","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0700-6571","authenticated-orcid":false,"given":"Ziyue","family":"Pan","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2899-6121","authenticated-orcid":false,"given":"Wenbo","family":"Shen","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-3142-8848","authenticated-orcid":false,"given":"Xingkai","family":"Wang","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4763-7354","authenticated-orcid":false,"given":"Kangjie","family":"Lu","sequence":"additional","affiliation":[{"name":"University of Minnesota Twin Cities, Minneapolis, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1506-2522","authenticated-orcid":false,"given":"Zhiyun","family":"Qian","sequence":"additional","affiliation":[{"name":"University of California, Riverside, Riverside, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,22]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Lars Ole Andersen. 1994. Program analysis and specialization for the C programming language. (1994)."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2016.2"},{"key":"e_1_2_1_3_1","volume-title":"Static Detection of Unsafe DMA Accesses in Device Drivers. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Bai Jia-Ju","year":"2021","unstructured":"Jia-Ju Bai, Tuo Li, Kangjie Lu, and Shi-Min Hu. 2021. Static Detection of Unsafe DMA Accesses in Device Drivers. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 1629\u20131645. isbn:978-1-939133-24-3 https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/bai"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-69738-1_1"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53413-7_5"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485547"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88806-0_2"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2896499"},{"key":"e_1_2_1_9_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Cai Yuandao","year":"2024","unstructured":"Yuandao Cai, Yibo Jin, and Charles Zhang. 2024. Unleashing the Power of Type-Based Call Graph Construction by Using Regional Pointer Information. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 1383\u20131400. isbn:978-1-939133-44-1 https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/cai-yuandao"},{"key":"e_1_2_1_10_1","unstructured":"CFI [n. d.]. Control Flow Integrity Design Documentation. https:\/\/clang.llvm.org\/docs\/ControlFlowIntegrityDesign.html. (Accessed on 04\/28\/2024)."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00028"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363212"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3643749"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446695"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2491956.2462165"},{"key":"e_1_2_1_16_1","volume-title":"2017 LLVM Developers\u2019 Meeting. https:\/\/llvm.org\/devmtg\/2017-10\/slides\/Finkel-The (Accessed on 08\/21\/2024)","author":"Finkel Hal","unstructured":"Hal Finkel. [n. d.]. The Type Sanitizer: Free Yourself from -fno-strict-aliasing. 2017 LLVM Developers\u2019 Meeting. https:\/\/llvm.org\/devmtg\/2017-10\/slides\/Finkel-The (Accessed on 08\/21\/2024)."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3622832"},{"key":"e_1_2_1_18_1","unstructured":"The LLVM Compiler Infrastructure. 2024. LLVM. https:\/\/llvm.org\/ [Accessed: 2024-04-27]."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2004.1281665"},{"key":"e_1_2_1_20_1","volume-title":"TIE: Principled Reverse Engineering of Types in Binary Programs. In The Network and Distributed System Security (NDSS) Symposium","author":"Lee JongHyup","year":"2011","unstructured":"JongHyup Lee, Thanassis Avgerinos, and David Brumley. 2011. TIE: Principled Reverse Engineering of Types in Binary Programs. In The Network and Distributed System Security (NDSS) Symposium 2011."},{"key":"e_1_2_1_21_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Li Guoren","year":"2023","unstructured":"Guoren Li, Hang Zhang, Jinmeng Zhou, Wenbo Shen, Yulei Sui, and Zhiyun Qian. 2023. A Hybrid Alias Analysis and Its Application to Global Variable Protection in the Linux Kernel. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 4211\u20134228. isbn:978-1-939133-37-3 https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/li-guoren"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3386020"},{"key":"e_1_2_1_23_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Liljestrand Hans","unstructured":"Hans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez, Jan-Erik Ekberg, and N. Asokan. 2019. PAC it up: Towards Pointer Integrity using ARM Pointer Authentication. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 177\u2013194. isbn:978-1-939133-06-9 https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/liljestrand"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560585"},{"key":"e_1_2_1_25_1","volume-title":"CAMP: Compiler and Allocator-based Heap Memory Protection. In 33rd USENIX Security Symposium (USENIX Security 24)","author":"Lin Zhenpeng","year":"2024","unstructured":"Zhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni, Peter Dinda, and Xinyu Xing. 2024. CAMP: Compiler and Allocator-based Heap Memory Protection. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 4015\u20134032. isbn:978-1-939133-44-1 https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/lin-zhenpeng"},{"key":"e_1_2_1_26_1","unstructured":"LLVM. 2024. LLVM Language Reference Manual. https:\/\/llvm.org\/docs\/LangRef.html [Accessed: 2024-01-15]."},{"key":"e_1_2_1_27_1","unstructured":"LLVM. 2024. Migration Instructions. https:\/\/llvm.org\/docs\/OpaquePointers.html#migration-instructions [Accessed: 2024-04-02]."},{"key":"e_1_2_1_28_1","unstructured":"LLVM. 2024. \u2019tbaa\u2019 Metadata. https:\/\/llvm.org\/docs\/LangRef.html#tbaa-metadata [Accessed: 2024-04-02]."},{"key":"e_1_2_1_29_1","unstructured":"LLVMLangRef:online [n. d.]. LLVM Language Reference Manual \u2014 LLVM 19.0.0git documentation. https:\/\/llvm.org\/docs\/LangRef.html. (Accessed on 04\/27\/2024)."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179412"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354244"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627113"},{"key":"e_1_2_1_33_1","volume-title":"DR. CHECKER: A Soundy Analysis for Linux Kernel Drivers. In 26th USENIX Security Symposium (USENIX Security 17)","author":"Machiry Aravind","year":"2017","unstructured":"Aravind Machiry, Chad Spensky, Jake Corina, Nick Stephens, Christopher Kruegel, and Giovanni Vigna. 2017. DR. CHECKER: A Soundy Analysis for Linux Kernel Drivers. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, BC, 1007\u20131024. isbn:978-1-931971-40-9 https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/machiry"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806596.1806631"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833675"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666620.2666632"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594295"},{"key":"e_1_2_1_38_1","unstructured":"opaque [n. d.]. Opaque Pointers \u2014 LLVM 19.0.0 git documentation. https:\/\/llvm.org\/docs\/OpaquePointers.html. (Accessed on 01\/08\/2024)."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468607"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394451.3397204"},{"key":"e_1_2_1_41_1","volume-title":"Control-flow analysis of higher-order languages or taming lambda","author":"Shivers Olin Grigsby","unstructured":"Olin Grigsby Shivers. 1991. Control-flow analysis of higher-order languages or taming lambda. Carnegie Mellon University."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/237721.237727"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3428301"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"e_1_2_1_46_1","volume-title":"Rap: Rip rop. In Hackers 2 Hackers Conference (H2HC).","author":"Team X","year":"2015","unstructured":"PaX Team. 2015. Rap: Rip rop. In Hackers 2 Hackers Conference (H2HC)."},{"key":"e_1_2_1_47_1","volume-title":"Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM. In 23rd USENIX Security Symposium (USENIX Security 14)","author":"Tice Caroline","year":"2014","unstructured":"Caroline Tice, Tom Roeder, Peter Collingbourne, Stephen Checkoway, \u00dalfar Erlingsson, Luis Lozano, and Geoff Pike. 2014. Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM. In 23rd USENIX Security Symposium (USENIX Security 14). USENIX Association, San Diego, CA, 941\u2013955. isbn:978-1-931971-15-7 https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/tice"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274705"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/996841.996859"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3489517.3530549"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180178"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3334268"},{"key":"e_1_2_1_53_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Yoo Sungbae","year":"2022","unstructured":"Sungbae Yoo, Jinbum Park, Seolheui Kim, Yeji Kim, and Taesoo Kim. 2022. In-Kernel Control-Flow Integrity on Commodity OSes using ARM Pointer Authentication. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA, 89\u2013106. isbn:978-1-939133-31-1 https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/yoo"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176309"},{"key":"e_1_2_1_55_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Zhai Yizhuo","unstructured":"Yizhuo Zhai, Zhiyun Qian, Chengyu Song, Manu Sridharan, Trent Jaeger, Paul Yu, and Srikanth V. Krishnamurthy. 2024. Dont Waste My Efforts: Pruning Redundant Sanitizer Checks by Developer-Implemented Type Checks. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 1419\u20131434. isbn:978-1-939133-44-1 https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/zhai"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484798"},{"key":"e_1_2_1_57_1","volume-title":"PeX: A Permission Check Analysis Framework for Linux Kernel. In 28th USENIX Security Symposium (USENIX Security 19)","author":"Zhang Tong","year":"2019","unstructured":"Tong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung, Ahmed M. Azab, and Ruowen Wang. 2019. PeX: A Permission Check Analysis Framework for Linux Kernel. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 1205\u20131220. isbn:978-1-939133-06-9 https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/zhang-tong"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3620665.3640382"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","unstructured":"Jinmeng Zhou Ziyue Pan Wenbo Shen Xingkai Wang Kangjie Lu and Zhiyun Qian. 2025. Artifact Evaluation Instructions for Type-Alias Analysis: Enabling LLVM IR with Accurate Types. https:\/\/doi.org\/10.5281\/zenodo.15182810 10.5281\/zenodo.15182810","DOI":"10.5281\/zenodo.15182810"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3165368"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2020.110884"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3728974","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,16]],"date-time":"2025-07-16T16:45:44Z","timestamp":1752684344000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3728974"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,22]]},"references-count":61,"journal-issue":{"issue":"ISSTA","published-print":{"date-parts":[[2025,6,22]]}},"alternative-id":["10.1145\/3728974"],"URL":"https:\/\/doi.org\/10.1145\/3728974","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,22]]}}}