{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:07:15Z","timestamp":1784300835010,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":72,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T00:00:00Z","timestamp":1783209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,7,5]]},"DOI":"10.1145\/3803437.3805225","type":"proceedings-article","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:27:39Z","timestamp":1784298459000},"page":"524-535","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-8880-1061","authenticated-orcid":false,"given":"Yayi","family":"Wang","sequence":"first","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3818-3343","authenticated-orcid":false,"given":"Shenao","family":"Wang","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5716-1462","authenticated-orcid":false,"given":"Jian","family":"Zhao","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8031-8811","authenticated-orcid":false,"given":"Shaosen","family":"Shi","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-4166-2455","authenticated-orcid":false,"given":"Ting","family":"Li","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1025-5965","authenticated-orcid":false,"given":"Yan","family":"Cheng","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-0563-0409","authenticated-orcid":false,"given":"Lizhong","family":"Bian","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-2554-7681","authenticated-orcid":false,"given":"Kan","family":"Yu","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8793-5367","authenticated-orcid":false,"given":"Yanjie","family":"Zhao","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1100-8633","authenticated-orcid":false,"given":"Haoyu","family":"Wang","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,17]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of the 18th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement","author":"Aguiar Lucas","year":"2024","unstructured":"Lucas Aguiar, Matheus Paixao, Rafael Carmo, Edson Soares, Antonio Leal, Matheus Freitas, and Eliakim Gama. 2024. Multi-language Software Development in the LLM Era: Insights from Practitioners' Conversations with ChatGPT. In Proceedings of the 18th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (Barcelona, Spain) (ESEM '24). Association for Computing Machinery, New York, NY, USA, 489\u2013495. 10.1145\/3674805.3690755"},{"key":"e_1_3_2_1_2_1","unstructured":"alipay. 2025. ant-application-security-testing-benchmark. https:\/\/github.com\/alipay\/ant-application-security-testing-benchmark. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_3_1","volume-title":"IEEE Symposium on Security and Privacy, SP 2024","author":"Ami Amit Seal","year":"2024","unstructured":"Amit Seal Ami, Kevin Moran, Denys Poshyvanyk, and Adwait Nadkarni. 2024. \"False negative - that one is going to kill you\": Understanding Industry Perspectives of Static Analysis based Security Testing. In IEEE Symposium on Security and Privacy, SP 2024, San Francisco, CA, USA, May 19\u201323, 2024. IEEE, 3979\u20133997. 10.1109\/SP54263.2024.00019"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation","author":"Arzt Steven","year":"2014","unstructured":"Steven Arzt, Siegfried Rasthofer, Christian Fritz, Eric Bodden, Alexandre Bartel, Jacques Klein, Yves Le Traon, Damien Octeau, and Patrick McDaniel. 2014. FlowDroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. In Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation (Edinburgh, United Kingdom) (PLDI '14). Association for Computing Machinery, New York, NY, USA, 259\u2013269. 10.1145\/2594291.2594299"},{"key":"e_1_3_2_1_5_1","volume-title":"ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI '14","author":"Arzt Steven","year":"2014","unstructured":"Steven Arzt, Siegfried Rasthofer, Christian Fritz, Eric Bodden, Alexandre Bartel, Jacques Klein, Yves Le Traon, Damien Octeau, and Patrick D. McDaniel. 2014. FlowDroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. In ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI '14, Edinburgh, United Kingdom - June 09 - 11, 2014, Michael F. P. O'Boyle and Keshav Pingali (Eds.). ACM, 259\u2013269. 10.1145\/2594291.2594299"},{"key":"e_1_3_2_1_6_1","volume-title":"QL: Object-oriented Queries on Relational Data. In 30th European Conference on Object-Oriented Programming, ECOOP 2016","volume":"25","author":"Avgustinov Pavel","year":"2016","unstructured":"Pavel Avgustinov, Oege de Moor, Michael Peyton Jones, and Max Sch\u00e4fer. 2016. QL: Object-oriented Queries on Relational Data. In 30th European Conference on Object-Oriented Programming, ECOOP 2016, July 18\u201322, 2016, Rome, Italy (LIPIcs, Vol. 56), Shriram Krishnamurthi and Benjamin S. Lerner (Eds.). Schloss Dagstuhl - Leibniz-Zentrum f\u00fcr Informatik, 2:1\u20132:25. 10.4230\/LIPICS.ECOOP.2016.2"},{"key":"e_1_3_2_1_7_1","unstructured":"awslabs. 2025. Argot. https:\/\/github.com\/awslabs\/ar-go-tools. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_8_1","volume-title":"Efficient and Flexible Discovery of PHP Application Vulnerabilities. In 2017 IEEE European Symposium on Security and Privacy (EuroS&P). 334\u2013349","author":"Backes Michael","year":"2017","unstructured":"Michael Backes, Konrad Rieck, Malte Skoruppa, Ben Stock, and Fabian Yamaguchi. 2017. Efficient and Flexible Discovery of PHP Application Vulnerabilities. In 2017 IEEE European Symposium on Security and Privacy (EuroS&P). 334\u2013349. 10.1109\/EuroSP.2017.14"},{"key":"e_1_3_2_1_9_1","volume-title":"2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). 1059\u20131070","author":"Masud Bhuiyan Masudul Hasan","year":"2023","unstructured":"Masudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel, and Cristian-Alexandru Staicu. 2023. SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScript. In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). 1059\u20131070. 10.1109\/ICSE48619.2023.00096"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.TN.1995"},{"key":"e_1_3_2_1_11_1","volume-title":"SAS 2020, Virtual Event, November 18\u201320, 2020, Proceedings (Lecture Notes in Computer Science","volume":"332","author":"Buro Samuele","year":"2020","unstructured":"Samuele Buro, Roy L. Crole, and Isabella Mastroeni. 2020. On Multi-language Abstraction - Towards a Static Analysis of Multi-language Programs. In Static Analysis - 27th International Symposium, SAS 2020, Virtual Event, November 18\u201320, 2020, Proceedings (Lecture Notes in Computer Science, Vol. 12389), David Pichardie and Mihaela Sighireanu (Eds.). Springer, 310\u2013332. 10.1007\/978-3-030-65474-0_14"},{"key":"e_1_3_2_1_12_1","unstructured":"Checkmarx. 2025. 10 Key Considerations When Choosing a SAST Solution. https:\/\/info.checkmarx.com\/hubfs\/SAST.pdf. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_13_1","volume-title":"2024 IEEE Symposium on Security and Privacy (SP). 3961\u20133978","author":"Chen Bofei","year":"2024","unstructured":"Bofei Chen, Lei Zhang, Xinyou Huang, Yinzhi Cao, Keke Lian, Yuan Zhang, and Min Yang. 2024. Efficient Detection of Java Deserialization Gadget Chains via Bottom-up Gadget Search and Dataflow-aided Payload Construction. In 2024 IEEE Symposium on Security and Privacy (SP). 3961\u20133978. 10.1109\/SP54263.2024.00150"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, ICSE 2024","author":"Cheng Xiao","year":"2024","unstructured":"Xiao Cheng, Jiawei Wang, and Yulei Sui. 2024. Precise Sparse Abstract Execution via Cross-Domain Interaction. In Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, ICSE 2024, Lisbon, Portugal, April 14\u201320, 2024. ACM, 109:1\u2013109:12. 10.1145\/3597503.3639220"},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2023","author":"Chow Yiu Wai","year":"2023","unstructured":"Yiu Wai Chow, Max Sch\u00e4fer, and Michael Pradel. 2023. Beware of the Unexpected: Bimodal Taint Analysis. In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2023, Seattle, WA, USA, July 17\u201321, 2023, Ren\u00e9 Just and Gordon Fraser (Eds.). ACM, 211\u2013222. 10.1145\/3597926.3598050"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 31st IEEE\/ACM International Conference on Automated Software Engineering, ASE 2016","author":"Christakis Maria","year":"2016","unstructured":"Maria Christakis and Christian Bird. 2016. What developers want and need from program analysis: an empirical study. In Proceedings of the 31st IEEE\/ACM International Conference on Automated Software Engineering, ASE 2016, Singapore, September 3\u20137, 2016, David Lo, Sven Apel, and Sarfraz Khurshid (Eds.). ACM, 332\u2013343. 10.1145\/2970276.2970347"},{"key":"e_1_3_2_1_17_1","volume-title":"Seventh IEEE International Workshop on Source Code Analysis and Manipulation (SCAM 2007","author":"de Moor Oege","year":"2007","unstructured":"Oege de Moor, Mathieu Verbaere, Elnar Hajiyev, Pavel Avgustinov, Torbj\u00f6rn Ekman, Neil Ongkingco, Damien Sereni, and Julian Tibble. 2007. Keynote Address: .QL for Source Code Analysis. In Seventh IEEE International Workshop on Source Code Analysis and Manipulation (SCAM 2007), September 30 - October 1, 2007, Paris, France. IEEE Computer Society, 3\u201316. 10.1109\/SCAM.2007.31"},{"key":"e_1_3_2_1_18_1","unstructured":"facebook. 2025. infer. https:\/\/github.com\/facebook\/infer. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_19_1","unstructured":"facebook. 2025. Pyre-check. https:\/\/github.com\/facebook\/pyre-check. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_20_1","volume-title":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event, Republic of Korea, November 15 - 19","author":"Fass Aurore","year":"2021","unstructured":"Aurore Fass, Doli\u00e8re Francis Som\u00e9, Michael Backes, and Ben Stock. 2021. DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale. In CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event, Republic of Korea, November 15 - 19, 2021, Yongdae Kim, Jong Kim, Giovanni Vigna, and Elaine Shi (Eds.). ACM, 1789\u20131804. 10.1145\/3460120.3484745"},{"key":"e_1_3_2_1_21_1","volume-title":"Proc. ACM Program. Lang. 8, PLDI","author":"Ferreira Mafalda","year":"2024","unstructured":"Mafalda Ferreira, Miguel Monteiro, Tiago Brito, Miguel E. Coimbra, Nuno Santos, Limin Jia, and Jos\u00e9 Fragoso Santos. 2024. Efficient Static Vulnerability Analysis for JavaScript with Multiversion Dependency Graphs. Proc. ACM Program. Lang. 8, PLDI (2024), 417\u2013441. 10.1145\/3656394"},{"key":"e_1_3_2_1_22_1","unstructured":"GitHub. 2025. CodeQL. https:\/\/github.com\/github\/codeql. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_23_1","volume-title":"Information Flow Analysis of Android Applications in DroidSafe. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015","author":"Gordon Michael I.","year":"2015","unstructured":"Michael I. Gordon, Deokhwan Kim, Jeff H. Perkins, Limei Gilham, Nguyen Nguyen, and Martin C. Rinard. 2015. Information Flow Analysis of Android Applications in DroidSafe. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015, San Diego, California, USA, February 8\u201311, 2015. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss2015\/information-flow-analysis-android-applications-droidsafe"},{"key":"e_1_3_2_1_24_1","volume-title":"Proc. ACM Program. Lang. 1, OOPSLA","author":"Grech Neville","year":"2017","unstructured":"Neville Grech and Yannis Smaragdakis. 2017. P\/Taint: unified points-to and taint analysis. Proc. ACM Program. Lang. 1, OOPSLA (2017), 102:1\u2013102:28. 10.1145\/3133926"},{"key":"e_1_3_2_1_25_1","unstructured":"Jinyao Guo Chengpeng Wang Xiangzhe Xu Zian Su and Xiangyu Zhang. 2025. RepoAudit: An Autonomous LLM-Agent for Repository-Level Code Auditing. (2025). https:\/\/proceedings.mlr.press\/v267\/guo25n.html"},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, CCS 2024","author":"Guo Zhiyong","year":"2024","unstructured":"Zhiyong Guo, Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo, and Yinzhi Cao. 2024. ReactAppScan: Mining React Application Vulnerabilities via Component Graph. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, CCS 2024, Salt Lake City, UT, USA, October 14\u201318, 2024, Bo Luo, Xiaojing Liao, Jun Xu, Engin Kirda, and David Lie (Eds.). ACM, 585\u2013599. 10.1145\/3658644.3670331"},{"key":"e_1_3_2_1_27_1","volume-title":"16th International Symposium, SAS 2009, Los Angeles, CA, USA, August 9\u201311, 2009. Proceedings (Lecture Notes in Computer Science","volume":"255","author":"Jensen Simon Holm","year":"2009","unstructured":"Simon Holm Jensen, Anders M\u00f8ller, and Peter Thiemann. 2009. Type Analysis for JavaScript. In Static Analysis, 16th International Symposium, SAS 2009, Los Angeles, CA, USA, August 9\u201311, 2009. Proceedings (Lecture Notes in Computer Science, Vol. 5673), Jens Palsberg and Zhendong Su (Eds.). Springer, 238\u2013255. 10.1007\/978-3-642-03237-0_17"},{"key":"e_1_3_2_1_28_1","volume-title":"Proc. ACM Program. Lang. 9, OOPSLA1 (2025","author":"Ji Yuchen","year":"2025","unstructured":"Yuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang, and Jingzhu He. 2025. Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint Analysis. Proc. ACM Program. Lang. 9, OOPSLA1 (2025), 1349\u20131377. 10.1145\/3720488"},{"key":"e_1_3_2_1_29_1","volume-title":"35th International Conference on Software Engineering, ICSE '13","author":"Johnson Brittany","year":"2013","unstructured":"Brittany Johnson, Yoonki Song, Emerson R. Murphy-Hill, and Robert W. Bowdidge. 2013. Why don't software developers use static analysis tools to find bugs?. In 35th International Conference on Software Engineering, ICSE '13, San Francisco, CA, USA, May 18\u201326, 2013, David Notkin, Betty H. C. Cheng, and Klaus Pohl (Eds.). IEEE Computer Society, 672\u2013681. 10.1109\/ICSE.2013.6606613"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2009-0385"},{"key":"e_1_3_2_1_31_1","volume-title":"44th IEEE Symposium on Security and Privacy, SP 2023","author":"Kang Mingqing","year":"2023","unstructured":"Mingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo, Jianwei Hou, V. N. Venkatakrishnan, and Yinzhi Cao. 2023. Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style Vulnerability. In 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, May 21\u201325, 2023. IEEE, 1059\u20131076. 10.1109\/SP46215.2023.10179352"},{"key":"e_1_3_2_1_32_1","first-page":"10","volume-title":"Proc. ACM Program. Lang. 8, PLDI, Article 194 (June","author":"Laursen Mathias Rud","year":"2024","unstructured":"Mathias Rud Laursen, Wenyuan Xu, and Anders M\u00f8ller. 2024. Reducing Static Analysis Unsoundness with Approximate Interpretation. Proc. ACM Program. Lang. 8, PLDI, Article 194 (June 2024), 24 pages. 10.1145\/3656424"},{"key":"e_1_3_2_1_33_1","volume-title":"ESEC\/FSE '21: 29th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Li Song","year":"2021","unstructured":"Song Li, Mingqing Kang, Jianwei Hou, and Yinzhi Cao. 2021. Detecting Node.js prototype pollution vulnerabilities via object lookup analysis. In ESEC\/FSE '21: 29th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Athens, Greece, August 23\u201328, 2021, Diomidis Spinellis, Georgios Gousios, Marsha Chechik, and Massimiliano Di Penta (Eds.). ACM, 268\u2013279. 10.1145\/3468264.3468542"},{"key":"e_1_3_2_1_34_1","volume-title":"31st USENIX Security Symposium, USENIX Security 2022","author":"Li Song","year":"2022","unstructured":"Song Li, Mingqing Kang, Jianwei Hou, and Yinzhi Cao. 2022. Mining Node.js Vulnerabilities via Object Dependence Graph and Query. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10\u201312, 2022, Kevin R. B. Butler and Kurt Thomas (Eds.). USENIX Association, 143\u2013160. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/li-song"},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC\/FSE 2022","author":"Li Wen","year":"2022","unstructured":"Wen Li, Li Li, and Haipeng Cai. 2022. On the vulnerability proneness of multilingual code. In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC\/FSE 2022, Singapore, Singapore, November 14\u201318, 2022, Abhik Roychoudhury, Cristian Cadar, and Miryung Kim (Eds.). ACM, 847\u2013859. 10.1145\/3540250.3549173"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3631967"},{"key":"e_1_3_2_1_37_1","volume-title":"Understanding Language Selection in Multi-language Software Projects on GitHub. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering: Companion Proceedings (ICSE-Companion). 256\u2013257","author":"Li Wen","year":"2021","unstructured":"Wen Li, Na Meng, Li Li, and Haipeng Cai. 2021. Understanding Language Selection in Multi-language Software Projects on GitHub. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering: Companion Proceedings (ICSE-Companion). 256\u2013257. 10.1109\/ICSE-Companion52605.2021.00119"},{"key":"e_1_3_2_1_38_1","volume-title":"Multi-Programming-Language Commits in OSS: An Empirical Study on Apache Projects. In 2021 IEEE\/ACM 29th International Conference on Program Comprehension (ICPC). 219\u2013229","author":"Li Zengyang","year":"2021","unstructured":"Zengyang Li, Xiaoxiao Qi, Qinyi Yu, Peng Liang, Ran Mo, and Chen Yang. 2021. Multi-Programming-Language Commits in OSS: An Empirical Study on Apache Projects. In 2021 IEEE\/ACM 29th International Conference on Program Comprehension (ICPC). 219\u2013229. 10.1109\/ICPC52881.2021.00029"},{"key":"e_1_3_2_1_39_1","volume-title":"Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications. In 2025 IEEE Symposium on Security and Privacy (SP). 972\u2013990","author":"Liu Fengyu","year":"2025","unstructured":"Fengyu Liu, Yuan Zhang, Tian Chen, Youkun Shi, Guangliang Yang, Zihan Lin, Min Yang, Junyao He, and Qi Li. 2025. Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications. In 2025 IEEE Symposium on Security and Privacy (SP). 972\u2013990. 10.1109\/SP61157.2025.00137"},{"key":"e_1_3_2_1_40_1","volume-title":"Lam","author":"Livshits Benjamin","year":"2005","unstructured":"Benjamin Livshits and Monica S. Lam. 2005. Securibench Micro: A Benchmark Suite for Static Security Analyzers. https:\/\/too4words.github.io\/securibench-micro\/ Developed as part of the Griffin Application Security Project at Stanford University. It contains 123 Java test cases designed to evaluate static and dynamic analysis tools for vulnerabilities like SQL injection, XSS, and path traversal attacks.."},{"key":"e_1_3_2_1_41_1","volume-title":"Sam Guyer, Uday Khedker, Anders M\u00f8ller, and Dimitrios Vardoulakis.","author":"Livshits Ben","year":"2015","unstructured":"Ben Livshits, Manu Sridharan, Yannis Smaragdakis, Ond\u0159ej Lhot\u00e1k, J. Nelson Amaral, Bor-Yuh Evan Chang, Sam Guyer, Uday Khedker, Anders M\u00f8ller, and Dimitrios Vardoulakis. 2015. In Defense of Soundiness: A Manifesto. Commun. ACM (Feb. 2015). https:\/\/yanniss.github.io\/Soundiness-CACM.pdf Accessed: 2026-01-24."},{"key":"e_1_3_2_1_42_1","unstructured":"llvm. 2025. llvm-project. https:\/\/github.com\/llvm\/llvm-project. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","author":"Luo Changhua","year":"2022","unstructured":"Changhua Luo, Penghui Li, and Wei Meng. 2022. TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP Applications. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (Los Angeles, CA, USA) (CCS '22). Association for Computing Machinery, New York, NY, USA, 2175\u20132188. 10.1145\/3548606.3559391"},{"key":"e_1_3_2_1_44_1","volume-title":"33rd European Conference on Object-Oriented Programming, ECOOP 2019","volume":"25","author":"Luo Linghui","year":"2019","unstructured":"Linghui Luo, Julian Dolby, and Eric Bodden. 2019. MagpieBridge: A General Approach to Integrating Static Analyses into IDEs and Editors (Tool Insights Paper). In 33rd European Conference on Object-Oriented Programming, ECOOP 2019, July 15\u201319, 2019, London, United Kingdom (LIPIcs, Vol. 134), Alastair F. Donaldson (Ed.). Schloss Dagstuhl - Leibniz-Zentrum f\u00fcr Informatik, 21:1\u201321:25. 10.4230\/LIPICS.ECOOP.2019.21"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/S10664-021-10013-5"},{"key":"e_1_3_2_1_46_1","volume-title":"Proceedings of the 19th International Conference on Evaluation and Assessment in Software Engineering","author":"Mayer Philip","year":"2015","unstructured":"Philip Mayer and Alexander Bauer. 2015. An empirical analysis of the utilization of multiple programming languages in open source projects. In Proceedings of the 19th International Conference on Evaluation and Assessment in Software Engineering (Nanjing, China) (EASE '15). Association for Computing Machinery, New York, NY, USA, Article 4, 10 pages. 10.1145\/2745802.2745805"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1186\/S40411-017-0035-Z"},{"key":"e_1_3_2_1_48_1","volume-title":"ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Muralee Siddharth","year":"2023","unstructured":"Siddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl, Brad Reaves, Antonio Bianchi, William Enck, Alexandros Kapravelos, and Aravind Machiry. 2023. ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 6983\u20137000. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/muralee"},{"key":"e_1_3_2_1_49_1","volume-title":"ISSTA '22: 31st ACM SIGSOFT International Symposium on Software Testing and Analysis","author":"Nachtigall Marcus","year":"2022","unstructured":"Marcus Nachtigall, Michael Schlichtig, and Eric Bodden. 2022. A large-scale study of usability criteria addressed by static analysis tools. In ISSTA '22: 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, Virtual Event, South Korea, July 18 - 22, 2022, Sukyoung Ryu and Yannis Smaragdakis (Eds.). ACM, 532\u2013543. 10.1145\/3533767.3534374"},{"key":"e_1_3_2_1_50_1","unstructured":"OWASP. 2025. OWASP Benchmark. https:\/\/owasp.org\/www-project-benchmark\/. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_51_1","volume-title":"PFortifier: Mitigating PHP Object Injection Through Automatic Patch Generation. In IEEE Symposium on Security and Privacy, SP 2025","author":"Pang Bo","year":"2025","unstructured":"Bo Pang, Yiheng Zhang, Mingzhe Gao, Junzhe Zhang, Ligeng Chen, Mingxue Zhangt, and Gang Liang. 2025. PFortifier: Mitigating PHP Object Injection Through Automatic Patch Generation. In IEEE Symposium on Security and Privacy, SP 2025, San Francisco, CA, USA, May 12\u201315, 2025, Marina Blanton, William Enck, and Cristina Nita-Rotaru (Eds.). IEEE, 956\u2013971. 10.1109\/SP61157.2025.00136"},{"key":"e_1_3_2_1_52_1","volume-title":"2nd USENIX Conference on Web Application Development, WebApps'11","author":"Papagiannis Ioannis","year":"2011","unstructured":"Ioannis Papagiannis, Matteo Migliavacca, and Peter R. Pietzuch. 2011. PHP Aspis: Using Partial Taint Tracking to Protect Against Injection Attacks. In 2nd USENIX Conference on Web Application Development, WebApps'11, Portland, Oregon, USA, June 15\u201316, 2011, Armando Fox (Ed.). USENIX Association. https:\/\/www.usenix.org\/conference\/webapps11\/php-aspis-using-partial-taint-tracking-protect-against-injection-attacks"},{"key":"e_1_3_2_1_53_1","unstructured":"python security. 2020. PyT. https:\/\/github.com\/python-security\/pyt. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3188720"},{"key":"e_1_3_2_1_55_1","volume-title":"Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Joanna C.","year":"2022","unstructured":"Joanna C. S. Santos and Julian Dolby. 2022. Program analysis using WALA (tutorial). In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (Singapore, Singapore) (ESEC\/FSE 2022). Association for Computing Machinery, New York, NY, USA, 1819. 10.1145\/3540250.3569449"},{"key":"e_1_3_2_1_56_1","unstructured":"Full Scale. 2025. Top 8 Tech Stacks: Choosing the Right Tech Stack. https:\/\/fullscale.io\/blog\/top-5-tech-stacks\/. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_57_1","unstructured":"semgrep. 2025. semgrep. https:\/\/github.com\/semgrep\/semgrep. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3296979.3192418"},{"key":"e_1_3_2_1_59_1","volume-title":"Towards Multi-Language Static Code Analysis. In 2023 IEEE 34th International Symposium on Software Reliability Engineering Workshops (ISSREW). 81\u201382","author":"Siddiqui Sanaa","year":"2023","unstructured":"Sanaa Siddiqui, Ravindra Metta, and Kumar Madhukar. 2023. Towards Multi-Language Static Code Analysis. In 2023 IEEE 34th International Symposium on Software Reliability Engineering Workshops (ISSREW). 81\u201382. 10.1109\/ISSREW60843.2023.00051"},{"key":"e_1_3_2_1_60_1","unstructured":"Adam Spanier and William Mahoney. [n. d.]. Static Analysis Using Intermediate Representations: A Literature Review. ([n. d.]). https:\/\/par.nsf.gov\/biblio\/10519999"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/2480741.2480743"},{"key":"e_1_3_2_1_62_1","volume-title":"Proceedings of the 25th International Conference on Compiler Construction, CC 2016","author":"Sui Yulei","year":"2016","unstructured":"Yulei Sui and Jingling Xue. 2016. SVF: interprocedural static value-flow analysis in LLVM. In Proceedings of the 25th International Conference on Compiler Construction, CC 2016, Barcelona, Spain, March 12\u201318, 2016, Ayal Zaks and Manuel V. Hermenegildo (Eds.). ACM, 265\u2013266. 10.1145\/2892208.2892235"},{"key":"e_1_3_2_1_63_1","volume-title":"Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2023","author":"Tan Tian","year":"2023","unstructured":"Tian Tan and Yue Li. 2023. Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of Classics. In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2023, Seattle, WA, USA, July 17\u201321, 2023, Ren\u00e9 Just and Gordon Fraser (Eds.). ACM, 1093\u20131105. 10.1145\/3597926.3598120"},{"key":"e_1_3_2_1_64_1","volume-title":"Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering","author":"Tomassetti Federico","year":"2014","unstructured":"Federico Tomassetti and Marco Torchiano. 2014. An empirical assessment of polyglot-ism in GitHub. In Proceedings of the 18th International Conference on Evaluation and Assessment in Software Engineering (London, England, United Kingdom) (EASE '14). Association for Computing Machinery, New York, NY, USA, Article 17, 4 pages. 10.1145\/2601248.2601269"},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the 2009 ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2009","author":"Tripp Omer","year":"2009","unstructured":"Omer Tripp, Marco Pistoia, Stephen J. Fink, Manu Sridharan, and Omri Weisman. 2009. TAJ: effective taint analysis of web applications. In Proceedings of the 2009 ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2009, Dublin, Ireland, June 15\u201321, 2009, Michael Hind and Amer Diwan (Eds.). ACM, 87\u201397. 10.1145\/1542476.1542486"},{"key":"e_1_3_2_1_66_1","unstructured":"WALA. 2025. WALA. https:\/\/github.com\/wala\/WALA. Accessed: 2026-01-23."},{"key":"e_1_3_2_1_67_1","volume-title":"LLMDFA: Analyzing Dataflow in Code with Large Language Models. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024","author":"Wang Chengpeng","year":"2024","unstructured":"Chengpeng Wang, Wuqi Zhang, Zian Su, Xiangzhe Xu, Xiaoheng Xie, and Xiangyu Zhang. 2024. LLMDFA: Analyzing Dataflow in Code with Large Language Models. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024, NeurIPS 2024, Vancouver, BC, Canada, December 10 - 15, 2024, Amir Globersons, Lester Mackey, Danielle Belgrave, Angela Fan, Ulrich Paquet, Jakub M. Tomczak, and Cheng Zhang (Eds.). http:\/\/papers.nips.cc\/paper_files\/paper\/2024\/hash\/ed9dcde1eb9c597f68c1d375bbecf3fc-Abstract-Conference.html"},{"key":"e_1_3_2_1_68_1","volume-title":"Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Wang Jie","year":"2020","unstructured":"Jie Wang, Yunguang Wu, Gang Zhou, Yiming Yu, Zhenyu Guo, and Yingfei Xiong. 2020. Scaling static taint analysis to industrial SOA applications: a case study at Alibaba. In Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (Virtual Event, USA) (ESEC\/FSE 2020). Association for Computing Machinery, New York, NY, USA, 1477\u20131486. 10.1145\/3368089.3417059"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183575"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2401.01571"},{"key":"e_1_3_2_1_71_1","volume-title":"Modeling and Discovering Vulnerabilities with Code Property Graphs. In 2014 IEEE Symposium on Security and Privacy, SP 2014","author":"Yamaguchi Fabian","year":"2014","unstructured":"Fabian Yamaguchi, Nico Golde, Daniel Arp, and Konrad Rieck. 2014. Modeling and Discovering Vulnerabilities with Code Property Graphs. In 2014 IEEE Symposium on Security and Privacy, SP 2014, Berkeley, CA, USA, May 18\u201321, 2014. IEEE Computer Society, 590\u2013604. 10.1109\/SP.2014.44"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2024.3358258"}],"event":{"name":"FSE Companion '26: 34th ACM International Conference on the Foundations of Software Engineering","location":"Concordia University Montreal QC Canada","acronym":"FSE Companion '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3803437.3805225","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:43:26Z","timestamp":1784299406000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3803437.3805225"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,5]]},"references-count":72,"alternative-id":["10.1145\/3803437.3805225","10.1145\/3803437"],"URL":"https:\/\/doi.org\/10.1145\/3803437.3805225","relation":{},"subject":[],"published":{"date-parts":[[2026,7,5]]},"assertion":[{"value":"2026-07-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}