{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T10:10:11Z","timestamp":1784196611981,"version":"3.55.0"},"reference-count":64,"publisher":"Association for Computing Machinery (ACM)","issue":"PLDI","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Program. Lang."],"published-print":{"date-parts":[[2025,6,10]]},"abstract":"<jats:p>The C and C++ languages define hundreds of cases as having undefined behavior (UB). These include, for example, corner cases where different CPU architectures disagree on the semantics of an instruction and the language does not want to force a specific implementation (e.g., shift by a value larger than the bitwidth). Another class of UB involves errors that the language chooses not to detect because it would be too expensive or impractical, such as dereferencing out-of-bounds pointers.<\/jats:p>\n                  <jats:p>Although there is a common belief within the compiler community that UB enables certain optimizations that would not be possible otherwise, no rigorous large-scale studies have been conducted on this subject. At the same time, there is growing interest in eliminating UB from programming languages to improve security.<\/jats:p>\n                  <jats:p>In this paper, we present the first comprehensive study that examines the performance impact of exploiting UB in C and C++ applications across multiple CPU architectures. Using LLVM, a compiler known for its extensive use of UB for optimizations, we demonstrate that, for the benchmarks and UB categories that we evaluated, the end-to-end performance gains are minimal. Moreover, when performance regresses, it can often be recovered through small improvements to optimization algorithms or by using link-time optimizations.<\/jats:p>","DOI":"10.1145\/3729260","type":"journal-article","created":{"date-parts":[[2025,6,13]],"date-time":"2025-06-13T16:02:27Z","timestamp":1749830547000},"page":"348-371","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Exploiting Undefined Behavior in C\/C++ Programs for Optimization: A Study on the Performance Impact"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-7344-212X","authenticated-orcid":false,"given":"Lucian","family":"Popescu","sequence":"first","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico - University of Lisbon, Lisboa, Portugal"},{"name":"Politehnica University of Bucharest, Bucharest, Romania"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3160-1672","authenticated-orcid":false,"given":"Nuno P.","family":"Lopes","sequence":"additional","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico - University of Lisbon, Lisboa, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,13]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2022.3184867"},{"key":"e_1_3_2_4_2","unstructured":"Periklis Akritidis Manuel Costa Miguel Castro and Steven Hand. 2009. Baggy Bounds Checking: An Efficient and Backwards-Compatible Defense against Out-of-Bounds Errors. In USENIX Security. https:\/\/www.usenix.org\/legacy\/event\/sec09\/tech\/full_papers\/akritidis.pdf"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.15514\/ISPRAS-2021-33(4)-14"},{"key":"e_1_3_2_6_2","unstructured":"JF Bastien. 2023. C++ Proposal P2723R1: Zero-initialize objects of automatic storage duration. http:\/\/wg21.link\/P2723"},{"key":"e_1_3_2_7_2","unstructured":"JF Bastien. 2024. C++ Proposal P2809R3: Trivial infinite loops are not Undefined Behavior. http:\/\/wg21.link\/P2809r3"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2011.5764689"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2017.7863732"},{"key":"e_1_3_2_10_2","unstructured":"ANSI Technical Committee and ISO\/IEC JTC 1 Working Group. 1989. Rationale for International Standard - Programming Language - C. https:\/\/www.open-std.org\/jtc1\/sc22\/wg14\/www\/docs\/n850.pdf"},{"key":"e_1_3_2_11_2","unstructured":"CVE. 2009. CVE-2009-1897: Vulnerability in the linux kernel involving a NULL pointer dereference. https:\/\/www.cve.org\/CVERecord?id=CVE-2009-1897"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70389-3_2"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/2743019"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","unstructured":"Johannes Doerfert Brian Homerding and Hal Finkel. 2019. Performance exploration through optimistic static program annotations. In ISC High Performance 2019. https:\/\/doi.org\/10.1007\/978-3-030-20656-7_13 10.1007\/978-3-030-20656-7_13","DOI":"10.1007\/978-3-030-20656-7_13"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2015.33"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.15514\/ISPRAS-2024-36(4)-3"},{"key":"e_1_3_2_17_2","unstructured":"Hal Finkel. 2017. The Type Sanitizer: Free Yourself from -fno-strict-aliasing. https:\/\/llvm.org\/devmtg\/2017-10\/slides\/Finkel-The%20Type%20Sanitizer.pdf"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","unstructured":"Lang Hames and Bernhard Scholz. 2006. Nearly optimal register allocation with PBQP. In JMLC. https:\/\/doi.org\/10.1007\/11860990_21 10.1007\/11860990_21","DOI":"10.1007\/11860990_21"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","unstructured":"Chris Hathhorn Chucky Ellison and Grigore Ro\u015fu. 2015. Defining the undefinedness of C. In PLDI. https:\/\/doi.org\/10.1145\/2737924.2737979 10.1145\/2737924.2737979","DOI":"10.1145\/2737924.2737979"},{"key":"e_1_3_2_20_2","unstructured":"H. Hinnant R. Orr B. Stroustrup D. Vandevoorde and M. Wong. 2023. C++ document P2759R1: DG Opinion on Safety for ISO C++. https:\/\/www.open-std.org\/JTC1\/SC22\/WG21\/docs\/papers\/2023\/p2759r1.pdf"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","unstructured":"Jan Hueckelheim and Johannes Doerfert. 2023. ORAQL \u2014 Optimistic Responses to Alias Queries in LLVM. In ICPP. https:\/\/doi.org\/10.1145\/3605573.3605644 10.1145\/3605573.3605644","DOI":"10.1145\/3605573.3605644"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","unstructured":"Raphael Isemann Cristiano Giuffrida Herbert Bos Erik van der Kouwe and Klaus von Gleissenthall. 2023. Don\u2019t Look UB: Exposing Sanitizer-Eliding Compiler Optimizations. Proc. ACM Program. Lang. 7 PLDI Article 143 (jun 2023). https:\/\/doi.org\/10.1145\/3591257 10.1145\/3591257","DOI":"10.1145\/3591257"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","unstructured":"Jeehoon Kang Yoonseung Kim Youngju Song Juneyoung Lee Sanghoon Park Mark Dongyeon Shin Yonghyun Kim Sungkeun Cho Joonwon Choi Chung-Kil Hur and Kwangkeun Yi. 2018. Crellvm: verified credible compilation for LLVM. In PLDI. https:\/\/doi.org\/10.1145\/3192366.3192377 10.1145\/3192366.3192377","DOI":"10.1145\/3192366.3192377"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","unstructured":"Andreas D. Kellas Alan Cao Peter Goodman and Junfeng Yang. 2023. Divergent Representations: When Compiler Optimizations Enable Exploitation. In spw. https:\/\/doi.org\/10.1109\/SPW59333.2023.00035 10.1109\/SPW59333.2023.00035","DOI":"10.1109\/SPW59333.2023.00035"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","unstructured":"Robbert Krebbers and Freek Wiedijk. 2015. A Typed C11 Semantics for Interactive Theorem Proving. In CPP. https: \/\/doi.org\/10.1145\/2676724.2693571 10.1145\/2676724.2693571","DOI":"10.1145\/2676724.2693571"},{"key":"e_1_3_2_26_2","unstructured":"Thomas K\u00f6ppe. 2023. Correct and incorrect code and erroneous behaviour. https:\/\/www.open-std.org\/jtc1\/sc22\/wg21\/docs\/papers\/2023\/p2795r0.html"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/2814270.2814319"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3276495"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3062341.3062343"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2020.7"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","unstructured":"Shaohua Li and Zhendong Su. 2023. Finding Unstable Code via Compiler-Driven Differential Testing. In ASPLOS. https:\/\/doi.org\/10.1145\/3582016.3582053 10.1145\/3582016.3582053","DOI":"10.1145\/3582016.3582053"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","unstructured":"Shaohua Li and Zhendong Su. 2024. UBFuzz: Finding Bugs in Sanitizer Implementations. In ASPLOS. https:\/\/doi.org\/10.1145\/3617232.3624874 10.1145\/3617232.3624874","DOI":"10.1145\/3617232.3624874"},{"key":"e_1_3_2_33_2","unstructured":"Changming Liu Yaohui Chen and Long Lu. 2021. KUBO: Precise and Scalable Detection of User-triggerable Undefined Behavior Bugs in OS Kernel. In NDSS. https:\/\/www.ndss-symposium.org\/wp-content\/uploads\/ndss2021_1B-5_24461_paper.pdf"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3689766"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453483.3454030"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/2737924.2737965"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","unstructured":"Kangjie Lu Chengyu Song Taesoo Kim and Wenke Lee. 2016. UniSan: Proactive Kernel Memory Initialization to Eliminate Data Leakages. In CCS. https:\/\/doi.org\/10.1145\/2976749.2978366 10.1145\/2976749.2978366","DOI":"10.1145\/2976749.2978366"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","unstructured":"Kayvan Memarian Justus Matthiesen James Lingard Kyndylan Nienhuis David Chisnall Robert N. M. Watson and Peter Sewell. 2016. Into the depths of C: elaborating the de facto standards. In PLDI. https:\/\/doi.org\/10.1145\/2908080.2908081 10.1145\/2908080.2908081","DOI":"10.1145\/2908080.2908081"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3649837"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","unstructured":"Todd Mytkowicz Amer Diwan Matthias Hauswirth and Peter F. Sweeney. 2009. Producing wrong data without doing anything obviously wrong!. In ASPLOS. https:\/\/doi.org\/10.1145\/1508244.1508275 10.1145\/1508244.1508275","DOI":"10.1145\/1508244.1508275"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250746"},{"key":"e_1_3_2_42_2","unstructured":"Thomas Neumann. 2023. C++ Proposal R2771R1: Towards memory safety in C++. https:\/\/wg21.link\/R2771\/1"},{"key":"e_1_3_2_43_2","unstructured":"Alexander Potapenko. 2020. Fighting Uninitialized Memory in the Kernel. In Clang-Built Linux Meetup. https:\/\/clangbuiltlinux.github.io\/CBL-meetup-2020-slides\/glider\/Fighting_uninitialized_memory_%40_CBL_Meetup_2020.pdf"},{"key":"e_1_3_2_44_2","unstructured":"Raimondas Sasnauskas Yang Chen Peter Collingbourne Jeroen Ketema Gratian Lup Jubi Taneja and John Regehr. 2018. Souper: A Synthesizing Superoptimizer. arXiv:1711.04422"},{"key":"e_1_3_2_45_2","unstructured":"Konstantin Serebryany Derek Bruening Alexander Potapenko and Dmitry Vyukov. 2012. AddressSanitizer: a fast address sanity checker. In USENIX ATC. https:\/\/www.usenix.org\/system\/files\/conference\/atc12\/atc12-final39.pdf"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","unstructured":"Konstantin Serebryany and Timur Iskhodzhanov. 2009. ThreadSanitizer: data race detection in practice. In WBIA. https:\/\/doi.org\/10.1145\/1791194.1791203 10.1145\/1791194.1791203","DOI":"10.1145\/1791194.1791203"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","unstructured":"Kostya Serebryany Chris Kennelly Mitch Phillips Matt Denton Marco Elver Alexander Potapenko Matt Morehouse Vlad Tsyrklevich Christian Holler Julian Lettner David Kilzer and Lander Brandt. 2024. GWP-ASan: Sampling-Based Detection of Memory-Safety Bugs in Production. In ICSE-SEIP. https:\/\/doi.org\/10.1145\/3639477.3640328 10.1145\/3639477.3640328","DOI":"10.1145\/3639477.3640328"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","unstructured":"Zefan Shen. 2022. The Impact of Undefined Behavior on Compiler Optimization. In ESSE. https:\/\/doi.org\/10.1145\/3501774.3501781 10.1145\/3501774.3501781","DOI":"10.1145\/3501774.3501781"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00009"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3356842"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","unstructured":"Dokyung Song Julian Lettner Prabhu Rajasekaran Yeoul Na Stijn Volckaert Per Larsen and Michael Franz. 2019. SoK: Sanitizing for security. In. https:\/\/doi.org\/10.1109\/SP.2019.00010 10.1109\/SP.2019.00010","DOI":"10.1109\/SP.2019.00010"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","unstructured":"Evgeniy Stepanov and Konstantin Serebryany. 2015. MemorySanitizer: Fast detector of uninitialized memory use in C++. In CGO. https:\/\/doi.org\/10.1109\/CGO.2015.7054186 10.1109\/CGO.2015.7054186","DOI":"10.1109\/CGO.2015.7054186"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/2983990.2984038"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3656404"},{"key":"e_1_3_2_55_2","unstructured":"Caroline Tice Tom Roeder Peter Collingbourne Stephen Checkoway \u00dalfar Erlingsson Luis Lozano and Geoff Pike. 2014. Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM. In USENIX Security. https:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity14\/sec14-paper-tice.pdf"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","unstructured":"Xi Wang Haogang Chen Alvin Cheung Zhihao Jia Nickolai Zeldovich and M. Frans Kaashoek. 2012. Undefined behavior: what happened to my code?. In APSYS. https:\/\/doi.org\/10.1145\/2349896.2349905 10.1145\/2349896.2349905","DOI":"10.1145\/2349896.2349905"},{"key":"e_1_3_2_57_2","unstructured":"Xi Wang Haogang Chen Zhihao Jia Nickolai Zeldovich and M Frans Kaashoek. 2012. Improving Integer Security for Systems with KINT. In OSDI. https:\/\/www.usenix.org\/system\/files\/conference\/osdi12\/osdi12-final-88.pdf"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/2517349.2522728"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/2699678"},{"key":"e_1_3_2_60_2","unstructured":"Zekai Wu Wei Liu Mingyue Liang and Kai Song. 2020. Finding Bugs Compiler Knows but Doesn\u2019t Tell You: Dissecting Undefined Behavior Optimizations in LLVM. BlackHat Europe (2020). https:\/\/i.blackhat.com\/eu-20\/Wednesday\/eu-20-Wu-Finding-Bugs-Compiler-Knows-But-Does-Not-Tell-You-Dissecting-Undefined-Behavior-Optimizations-In-LLVM.pdf"},{"key":"e_1_3_2_61_2","unstructured":"Jianhao Xu Kangjie Lu Zhengjie Du Zhu Ding Linke Li Qiushi Wu Mathias Payer and Bing Mao. 2023. Silent Bugs Matter: A Study of Compiler-Introduced Security Bugs. In USENIX Security. https:\/\/www.usenix.org\/system\/files\/usenixsecurity23-xu-jianhao.pdf"},{"key":"e_1_3_2_62_2","unstructured":"Shafik Yaghmour. 2019. C++ Proposal P1705R1: Enumerating Core Undefined Behavior. https:\/\/wg21.link\/P1705"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/2048066.2048092"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","unstructured":"Xuejun Yang Yang Chen Eric Eide and John Regehr. 2011. Finding and understanding bugs in C compilers. In PLDI. https:\/\/doi.org\/10.1145\/1993498.1993532 10.1145\/1993498.1993532","DOI":"10.1145\/1993498.1993532"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3473572"}],"container-title":["Proceedings of the ACM on Programming Languages"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3729260","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T10:01:39Z","timestamp":1784196099000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3729260"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,10]]},"references-count":64,"journal-issue":{"issue":"PLDI","published-print":{"date-parts":[[2025,6,10]]}},"alternative-id":["10.1145\/3729260"],"URL":"https:\/\/doi.org\/10.1145\/3729260","relation":{},"ISSN":["2475-1421"],"issn-type":[{"value":"2475-1421","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,10]]},"assertion":[{"value":"2024-11-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-03-06","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-06-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}