{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T02:35:14Z","timestamp":1784342114011,"version":"3.55.0"},"reference-count":79,"publisher":"Association for Computing Machinery (ACM)","issue":"OOPSLA2","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Program. Lang."],"published-print":{"date-parts":[[2025,10,9]]},"abstract":"<jats:p>\n                    JavaScript (JS) engines implement complex language semantics and optimization strategies to support the dynamic nature of JS, making them difficult to test thoroughly and prone to subtle, security-critical bugs. Existing fuzzers often struggle to generate diverse and valid test cases. They either rely on syntax-level mutations that lack semantic awareness or perform limited, local mutations on concrete code, thus failing to explore deeper, more complex program behaviors. This paper presents\n                    <jats:sc>TemuJs<\/jats:sc>\n                    , a novel fuzzing framework that performs extraction and mutation at a high level, operating on abstract templates derived from real-world JS programs. These templates capture coarse-grained program structures with semantic placeholders, enabling semantics-aware mutations that preserve the high-level intent of the original code while diversifying its behavior. By decoupling mutation from concrete syntax and leveraging a structured intermediate representation for the templates,\n                    <jats:sc>TemuJs<\/jats:sc>\n                    explores a broader and more meaningful space of program behaviors. Evaluated on three major JS engines, namely, V8, SpiderMonkey, and JavaScriptCore,\n                    <jats:sc>TemuJs<\/jats:sc>\n                    discovers 44 bugs and achieves a 10.3% relative increase in edge coverage compared to state-of-the-art fuzzers on average. Our results demonstrate the efficacy of high-level, template-mutation fuzzing in testing JS engines.\n                  <\/jats:p>","DOI":"10.1145\/3763154","type":"journal-article","created":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T08:51:31Z","timestamp":1759999891000},"page":"2898-2926","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Extraction and Mutation at a High Level: Template-Based Fuzzing for JavaScript Engines"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2583-0698","authenticated-orcid":false,"given":"Wai Kin","family":"Wong","sequence":"first","affiliation":[{"name":"Hong Kong University of Science and Technology, Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4680-5715","authenticated-orcid":false,"given":"Dongwei","family":"Xiao","sequence":"additional","affiliation":[{"name":"Hong Kong University of Science and Technology, Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-0941-9791","authenticated-orcid":false,"given":"Cheuk Tung","family":"Lai","sequence":"additional","affiliation":[{"name":"VX Research, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2066-7939","authenticated-orcid":false,"given":"Yiteng","family":"Peng","sequence":"additional","affiliation":[{"name":"Hong Kong University of Science and Technology, Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3752-0718","authenticated-orcid":false,"given":"Daoyuan","family":"Wu","sequence":"additional","affiliation":[{"name":"Lingnan University, Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0866-0308","authenticated-orcid":false,"given":"Shuai","family":"Wang","sequence":"additional","affiliation":[{"name":"Hong Kong University of Science and Technology, Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,10,9]]},"reference":[{"key":"e_1_3_1_2_1","unstructured":"Apple. 2025a. Dispatch | Apple Developer Documentation. https:\/\/developer.apple.com\/documentation\/DISPATCH."},{"key":"e_1_3_1_3_1","unstructured":"Apple. 2025b. JavaScriptCore. https:\/\/developer.apple.com\/documentation\/javascriptcore."},{"key":"e_1_3_1_4_1","unstructured":"Apple. 2025c. JavaScriptCore regression tests. https:\/\/github.com\/WebKit\/WebKit\/tree\/main\/JSTests\/stress."},{"key":"e_1_3_1_5_1","unstructured":"Apple. 2025d. Swift.org - Welcome to Swift.org. https:\/\/www.swift.org\/."},{"key":"e_1_3_1_6_1","doi-asserted-by":"publisher","unstructured":"Lukas Bernhard Tobias Scharnowski Moritz Schloegel Tim Blazytko and Thorsten Holz. 2022. JIT-picking: Differential fuzzing of JavaScript engines. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 351\u2013364. doi:10.1145\/3548606.3560624","DOI":"10.1145\/3548606.3560624"},{"key":"e_1_3_1_7_1","article-title":"Metamorphic testing: a new approach for generating next test cases","author":"Chen Tsong Y","year":"2020","unstructured":"Tsong Y Chen, Shing C Cheung, and Shiu Ming Yiu. 2020. Metamorphic testing: a new approach for generating next test cases. arXiv preprint arXiv:2002.12543 (2020).","journal-title":"arXiv preprint arXiv:2002.12543"},{"key":"e_1_3_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00127"},{"key":"e_1_3_1_9_1","doi-asserted-by":"publisher","unstructured":"Yuting Chen Ting Su Chengnian Sun Zhendong Su and Jianjun Zhao. 2016. Coverage-directed differential testing of JVM implementations. In proceedings of the 37th ACM SIGPLAN Conference on Programming Language Design and Implementation. 85\u201399. doi:10.1145\/2908080.2908095","DOI":"10.1145\/2908080.2908095"},{"key":"e_1_3_1_10_1","unstructured":"Gemma Crawford. 2024. A Critical Vulnerability in Chrome\u2019s V8 JavaScript Engine - CommuniCloud. https:\/\/www.communicloud.com\/blog\/chrome-v8-security-exploit\/."},{"key":"e_1_3_1_11_1","unstructured":"Cyble. 2024. Urgent Fix Needed For Chrome V8 Engine CVE-2024-7965. https:\/\/cyble.com\/blog\/high-risk-cve-2024-7965-vulnerability-in-chromes-v8-engine-requires-quick-fix\/."},{"key":"e_1_3_1_12_1","unstructured":"Dev Learning Daily. 2024. Role of JavaScript engines in browser architecture. https:\/\/learningdaily.dev\/role-of-javascript-engines-in-browser-architecture-ba63c3dceb05."},{"key":"e_1_3_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133917"},{"key":"e_1_3_1_14_1","unstructured":"Ecma. 2025. ECMAScript 2025 Language Specification. https:\/\/tc39.es\/ecma262\/."},{"key":"e_1_3_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3680389"},{"key":"e_1_3_1_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/3488877.3488887"},{"key":"e_1_3_1_17_1","unstructured":"Google. 2016. V8 parser fuzzer. https:\/\/source.chromium.org\/chromium\/chromium\/src\/+\/main:v8\/test\/fuzzer\/parser.cc."},{"key":"e_1_3_1_18_1","unstructured":"Google. 2025a. A Brief JavaScriptCore RCE Story. https:\/\/qriousec.github.io\/post\/jsc-uninit\/."},{"key":"e_1_3_1_19_1","unstructured":"Google. 2025b. Code base of V8. https:\/\/chromium.googlesource.com\/v8\/v8.git\/."},{"key":"e_1_3_1_20_1","unstructured":"Google. 2025c. Public v8CTF sbumissions. https:\/\/docs.google.com\/spreadsheets\/d\/e\/2PACX-1vTWvO0tFNl8fJbOmTV1nwGJi4fAy5pDg-6DsHARRubj8I6c7_11RQ36Jv735zj9EQggz6AWjAOaebJh\/pubhtml."},{"key":"e_1_3_1_21_1","unstructured":"Google. 2025d. V8 JavaScript engine. https:\/\/v8.dev\/."},{"key":"e_1_3_1_22_1","unstructured":"Google. 2025e. V8 regression tests. https:\/\/github.com\/v8\/v8\/tree\/main\/test\/mjsunit\/regress."},{"key":"e_1_3_1_23_1","unstructured":"GraffersID. 2025. What is JavaScript And Why JavaScript Is So Popular? https:\/\/graffersid.com\/why-javascript-is-popular\/."},{"key":"e_1_3_1_24_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24290"},{"key":"e_1_3_1_25_1","doi-asserted-by":"publisher","unstructured":"HyungSeok Han DongHyeon Oh and Sang Kil Cha. 2019. CodeAlchemist: Semantics-aware code generation to find vulnerabilities in JavaScript engines.. In NDSS. doi:10.14722\/ndss.2019.23263","DOI":"10.14722\/ndss.2019.23263"},{"key":"e_1_3_1_26_1","doi-asserted-by":"publisher","unstructured":"Xiaoyu He Xiaofei Xie Yuekang Li Jianwen Sun Feng Li Wei Zou Yang Liu Lei Yu Jianhua Zhou Wenchang Shi et al. 2021. Sofi: Reflection-augmented fuzzing for javascript engines. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2229\u20132242. doi:10.1145\/3460120.3484823","DOI":"10.1145\/3460120.3484823"},{"key":"e_1_3_1_27_1","doi-asserted-by":"publisher","unstructured":"Adrian Herrera Hendra Gunadi Shane Magrath Michael Norrish Mathias Payer and Antony L Hosking. 2021. Seed selection for successful fuzzing. In Proceedings of the 30th ACM SIGSOFT international symposium on software testing and analysis. 230\u2013243. doi:10.1145\/3460319.3464795","DOI":"10.1145\/3460319.3464795"},{"key":"e_1_3_1_28_1","unstructured":"Ariya Hidayat. 2025. Esprima. https:\/\/esprima.org\/."},{"key":"e_1_3_1_29_1","doi-asserted-by":"publisher","unstructured":"Christian Holler Kim Herzig and Andreas Zeller. 2012. Fuzzing with code fragments. In 21st USENIX Security Symposium (USENIX Security 12). 445\u2013458. doi:10.5555\/2362793.2362831","DOI":"10.5555\/2362793.2362831"},{"key":"e_1_3_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00016"},{"key":"e_1_3_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04898-2_645"},{"key":"e_1_3_1_32_1","doi-asserted-by":"publisher","unstructured":"Seungwan Kwon Jaeseong Kwon Wooseok Kang Juneyoung Lee and Kihong Heo. 2024. Translation validation for JIT compiler in the V8 JavaScript engine. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering. 1\u201312. doi:10.1145\/3597503.3639189","DOI":"10.1145\/3597503.3639189"},{"key":"e_1_3_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2004.1281665"},{"key":"e_1_3_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594334"},{"key":"e_1_3_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2858965.2814319"},{"key":"e_1_3_1_36_1","doi-asserted-by":"publisher","unstructured":"Suyoung Lee HyungSeok Han Sang Kil Cha and Sooel Son. 2020. Montage: A Neural Network Language Model-Guided JavaScript Engine Fuzzer. In 29th USENIX Security Symposium (USENIX Security 20). 2613\u20132630. doi:10.5555\/3489212.3489359","DOI":"10.5555\/3489212.3489359"},{"key":"e_1_3_1_37_1","doi-asserted-by":"publisher","unstructured":"Cong Li Yanyan Jiang Chang Xu and Zhendong Su. 2023. Validating JIT compilers via compilation space exploration. In Proceedings of the 29th Symposium on Operating Systems Principles. 66\u201379. doi:10.1145\/3715102","DOI":"10.1145\/3715102"},{"key":"e_1_3_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3643781"},{"key":"e_1_3_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3354789"},{"key":"e_1_3_1_40_1","doi-asserted-by":"publisher","unstructured":"Zhibo Liu and Shuai Wang. 2020. How far we have come: Testing decompilation correctness of C decompilers. In Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis. 475\u2013487. doi:10.1145\/3395363.3397370","DOI":"10.1145\/3395363.3397370"},{"key":"e_1_3_1_41_1","doi-asserted-by":"publisher","unstructured":"Zhibo Liu Dongwei Xiao Zongjie Li Shuai Wang and Wei Meng. 2023. Exploring missed optimizations in webassembly optimizers. In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis. 436\u2013448. doi:10.1145\/3597926.3598068","DOI":"10.1145\/3597926.3598068"},{"key":"e_1_3_1_42_1","doi-asserted-by":"publisher","unstructured":"Haoyang Ma Qingchao Shen Yongqiang Tian Junjie Chen and Shing-Chi Cheung. 2023. Fuzzing deep learning compilers with hirgen. In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis. 248\u2013260. doi:10.1145\/3597926.3598053","DOI":"10.1145\/3597926.3598053"},{"issue":"1","key":"e_1_3_1_43_1","first-page":"100","article-title":"Differential testing for software","volume":"10","author":"McKeeman William M","year":"1998","unstructured":"William M McKeeman. 1998. Differential testing for software. Digital Technical Journal 10, 1 (1998), 100\u2013107.","journal-title":"Digital Technical Journal"},{"key":"e_1_3_1_44_1","unstructured":"Mozilla. 2023. GitHub - MozillaSecurity\/funfuzz: A collection of fuzzers in a harness for testing the SpiderMonkey JavaScript engine. https:\/\/github.com\/MozillaSecurity\/funfuzz\/tree\/master."},{"key":"e_1_3_1_45_1","unstructured":"Mozilla. 2025a. Nullish coalescing operator (??) - JavaScript | MDN. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/JavaScript\/Reference\/Operators\/Nullish_coalescing."},{"key":"e_1_3_1_46_1","unstructured":"Mozilla. 2025b. Reflect - JavaScript | MDN. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/JavaScript\/Reference\/Global_Objects\/Reflect."},{"key":"e_1_3_1_47_1","unstructured":"Mozilla. 2025c. SpiderMonkey. https:\/\/spidermonkey.dev\/."},{"key":"e_1_3_1_48_1","unstructured":"Mozilla. 2025d. SpiderMonkey regression tests. https:\/\/github.com\/mozilla\/gecko-dev\/tree\/master\/js\/src\/jit-test\/tests."},{"key":"e_1_3_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00015"},{"key":"e_1_3_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00067"},{"key":"e_1_3_1_51_1","unstructured":"Pramod Pawar and Rohan Jambhale. 2024. JavaScript Statistics By Usage and Facts. https:\/\/electroiq.com\/stats\/javascript-statistics\/."},{"key":"e_1_3_1_52_1","first-page":"2795","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Salls Christopher","year":"2021","unstructured":"Christopher Salls, Chani Jindal, Jake Corina, Christopher Kruegel, and Giovanni Vigna. 2021. Token-Level Fuzzing. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2795\u20132809. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/salls"},{"key":"e_1_3_1_53_1","doi-asserted-by":"publisher","unstructured":"Konstantin Serebryany Derek Bruening Alexander Potapenko and Dmitriy Vyukov. 2012. {AddressSanitizer}: A fast address sanity checker. In 2012 USENIX annual technical conference (USENIX ATC 12). 309\u2013318. doi:10.5555\/2342821.2342849","DOI":"10.5555\/2342821.2342849"},{"key":"e_1_3_1_54_1","unstructured":"StatCounter. 2024. Browser Market Share Worldwide | Statcounter Global Stats. https:\/\/gs.statcounter.com\/browser-market-share."},{"key":"e_1_3_1_55_1","doi-asserted-by":"publisher","unstructured":"Chengnian Sun Vu Le and Zhendong Su. 2016. Finding compiler bugs via live code mutation. In Proceedings of the 2016 ACM SIGPLAN International Conference on Object-Oriented Programming Systems Languages and Applications. 849\u2013863. doi:10.1145\/2983990.2984038","DOI":"10.1145\/2983990.2984038"},{"key":"e_1_3_1_56_1","unstructured":"Coding Temple. 2024. Why is JavaScript So Popular? Key Factors Explained | Coding Temple. https:\/\/www.codingtemple.com\/blog\/why-has-javascript-become-so-popular-exploring-key-factors\/."},{"key":"e_1_3_1_57_1","doi-asserted-by":"publisher","unstructured":"Theodoros Theodoridis Manuel Rigger and Zhendong Su. 2022. Finding missed optimizations through the lens of dead code elimination. In Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems. 697\u2013709. doi:10.1145\/3503222.3507764","DOI":"10.1145\/3503222.3507764"},{"key":"e_1_3_1_58_1","unstructured":"TrueFort. 2024. 8 Chrome Vulnerabilities that Caused Risk in 2024. https:\/\/truefort.com\/8-dangerous-chrome-vulnerabilities\/."},{"key":"e_1_3_1_59_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.241411"},{"key":"e_1_3_1_60_1","unstructured":"Liam Wachter Julian Gremminger Christian Wressnegger Mathias Payer and Flavio Toffalini. 2025b. Dumpling V8 patch. https:\/\/github.com\/two-heart\/dumpling-artifact-evaluation\/blob\/main\/bug_finding_and_overhead\/dumpling_v8.patch."},{"key":"e_1_3_1_61_1","doi-asserted-by":"publisher","unstructured":"Junjie Wang Bihuan Chen Lei Wei and Yang Liu. 2019. Superion: Grammar-Aware Greybox Fuzzing. In 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE). 724\u2013735. doi:10.1109\/ICSE.2019.00081","DOI":"10.1109\/ICSE.2019.00081"},{"key":"e_1_3_1_62_1","doi-asserted-by":"publisher","DOI":"10.5555\/3698900.3698949"},{"key":"e_1_3_1_63_1","doi-asserted-by":"publisher","unstructured":"Junjie Wang Zhiyi Zhang Shuang Liu Xiaoning Du and Junjie Chen. 2023. FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT Compiler. In 32nd USENIX Security Symposium (USENIX Security 23). 1865\u20131882. doi:10.5555\/3620237.3620342","DOI":"10.5555\/3620237.3620342"},{"key":"e_1_3_1_64_1","doi-asserted-by":"publisher","unstructured":"Wai Kin Wong Huaijin Wang Zongjie Li and Shuai Wang. 2024. Binaug: Enhancing binary similarity analysis with low-cost input repairing. In Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering. 1\u201313. doi:10.1145\/3597503.3623328","DOI":"10.1145\/3597503.3623328"},{"key":"e_1_3_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME55016.2022.00019"},{"key":"e_1_3_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3728958"},{"key":"e_1_3_1_67_1","unstructured":"Wai Kin Wong Dongwei Xiao Cheuk Tung Lai Yiteng Peng Daoyuan Wu and Shuai Wang. 2025b. List of bugs found by TemuJs. https:\/\/sites.google.com\/view\/temujs\/bugs."},{"key":"e_1_3_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00017"},{"key":"e_1_3_1_69_1","doi-asserted-by":"publisher","unstructured":"Dongwei Xiao Zhibo Liu Yiteng Peng and Shuai Wang. 2025a. Mtzk: Testing and exploring bugs in zero-knowledge (zk) compilers. In NDSS. doi:10.14722\/ndss.2025.230530","DOI":"10.14722\/ndss.2025.230530"},{"key":"e_1_3_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00201"},{"key":"e_1_3_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3508035"},{"key":"e_1_3_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3729305"},{"key":"e_1_3_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690336"},{"key":"e_1_3_1_74_1","doi-asserted-by":"publisher","unstructured":"Xuejun Yang Yang Chen Eric Eide and John Regehr. 2011. Finding and understanding bugs in C compilers. In Proceedings of the 32nd ACM SIGPLAN conference on Programming language design and implementation. 283\u2013294. doi:10.1145\/1993316.1993532","DOI":"10.1145\/1993316.1993532"},{"key":"e_1_3_1_75_1","doi-asserted-by":"publisher","unstructured":"Guixin Ye Zhanyong Tang Shin Hwei Tan Songfang Huang Dingyi Fang Xiaoyang Sun Lizhong Bian Haibo Wang and Zheng Wang. 2021. Automated conformance testing for JavaScript engines via deep compiler fuzzing. In Proceedings of the 42nd ACM SIGPLAN international conference on programming language design and implementation. 435\u2013450. doi:10.1145\/3453483.3454054","DOI":"10.1145\/3453483.3454054"},{"key":"e_1_3_1_76_1","unstructured":"Michal Zalewski. 2025. afl-cmin. https:\/\/github.com\/AFLplusplus\/AFLplusplus\/blob\/stable\/afl-cmin."},{"key":"e_1_3_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3643777"},{"key":"e_1_3_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-Companion58688.2023.00014"},{"key":"e_1_3_1_79_1","doi-asserted-by":"publisher","unstructured":"Yingquan Zhao Zan Wang Junjie Chen Ruifeng Fu Yanzhou Lu Tianchang Gao and Haojie Ye. 2024. Program Ingredients Abstraction and Instantiation for Synthesis-based JVM Testing. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. 3943\u20133957. doi:10.1145\/3658644.3690366","DOI":"10.1145\/3658644.3690366"},{"key":"e_1_3_1_80_1","doi-asserted-by":"publisher","unstructured":"Yingquan Zhao Zan Wang Junjie Chen Mengdi Liu Mingyuan Wu Yuqun Zhang and Lingming Zhang. 2022. History-driven test program synthesis for JVM testing. In Proceedings of the 44th International Conference on Software Engineering. 1133\u20131144. doi:10.1145\/3510003.3510059","DOI":"10.1145\/3510003.3510059"}],"container-title":["Proceedings of the ACM on Programming Languages"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3763154","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T10:16:19Z","timestamp":1784196979000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3763154"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,9]]},"references-count":79,"journal-issue":{"issue":"OOPSLA2","published-print":{"date-parts":[[2025,10,9]]}},"alternative-id":["10.1145\/3763154"],"URL":"https:\/\/doi.org\/10.1145\/3763154","relation":{},"ISSN":["2475-1421"],"issn-type":[{"value":"2475-1421","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,9]]},"assertion":[{"value":"2025-03-25","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-12","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}