{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T08:06:54Z","timestamp":1782547614995,"version":"3.54.5"},"reference-count":95,"publisher":"SAGE Publications","issue":"1","license":[{"start":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T00:00:00Z","timestamp":1757030400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2026,1]]},"abstract":"<jats:p>Database management systems (DBMSs) are vital components in modern data-driven systems. Their complexity often leads to logic bugs, which are implementation errors within the DBMSs that can lead to incorrect query results, data exposure, unauthorized access, etc., without necessarily causing visible system failures. Existing detection employs two strategies: rule-based bug detection and coverage-guided fuzzing. In general, rule specification itself is challenging; as a result, rule-based detection is limited to specific and simple rules. Coverage-guided fuzzing blindly explores code paths or blocks, many of which are unlikely to contain logic bugs; therefore, this strategy is cost-ineffective. In this paper, we design SQLaser, a SQL-clause-guided fuzzer for detecting logic bugs in DBMSs. Through a comprehensive examination of existing logic bugs across four distinct DBMSs, excluding those causing system crashes, we have identified 35 logic-bug patterns. These patterns manifest as certain SQL clause combinations that commonly result in logic bugs, and behind these clause combinations are a sequence of functions. We therefore model logic-bug patterns as error-prone function chains (i.e., sequences of functions). We further develop a directed fuzzer with a new path-to-path distance-calculation mechanism for effectively testing these chains and discovering additional logic bugs. This mechanism enables SQLaser to swiftly navigate to target sites and uncover potential bugs emerging from these paths. Our evaluation, conducted on SQLite, MySQL, PostgreSQL, and TiDB, demonstrates that SQLaser significantly accelerates bug discovery compared to other fuzzing approaches, reducing detection time by approximately 60%. As a standalone fuzzer, SQLaser identified 22 bugs spanning 18 of the 35 logic-bug patterns, outperforming contemporary fuzzers such as SQLRight, which only uncovered two logic bugs across two patterns within the same testing period (i.e., 60 days) when testing SQLite. Notably, four of the bugs discovered by SQLaser are zero-day, all of which have been reported to and confirmed by vendors.<\/jats:p>","DOI":"10.1177\/0926227x251370258","type":"journal-article","created":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T10:19:36Z","timestamp":1757067576000},"page":"3-28","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":1,"title":["SQLaser: Detecting database management system (DBMS) logic bugs with clause-guided fuzzing"],"prefix":"10.1177","volume":"34","author":[{"given":"Jin","family":"Wei","sequence":"first","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"},{"name":"Institute of Big\u00a0Data, Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8517-0580","authenticated-orcid":false,"given":"Ping","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Big\u00a0Data, Fudan University, Shanghai, China"},{"name":"Purple Mountain Laboratories, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kangjie","family":"Lu","sequence":"additional","affiliation":[{"name":"University of Minnesota Twin Cities, Minneapolis, MN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun","family":"Dai","sequence":"additional","affiliation":[{"name":"Worcester Polytechnic Institute, Worcester, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoyan","family":"Sun","sequence":"additional","affiliation":[{"name":"Worcester Polytechnic Institute, Worcester, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","published-online":{"date-parts":[[2025,9,5]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1017\/S147106842100003X"},{"key":"e_1_3_2_3_2","unstructured":"SQLite. SQLite. https:\/\/sqlite.org\/index.html(accessed 18 August 2023)."},{"key":"e_1_3_2_4_2","unstructured":"Liang Y Liu S Hu H. Detecting logical bugs of {DBMS} with coverage-based guidance. In: Proceedings of the 31st USENIX security symposium (USENIX Security 22) August 10\u201312 2022 Boston MA USA pp.4309\u20134326. Berkeley CA: USENIX Association."},{"key":"e_1_3_2_5_2","doi-asserted-by":"crossref","unstructured":"Rigger M Su Z. Detecting optimization bugs in database engines via non-optimizing reference engine construction. In: Proceedings of the 28th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering November 8\u201313 2020 pp.1140\u20131152. New York NY: Association for Computing Machinery.","DOI":"10.1145\/3368089.3409710"},{"key":"e_1_3_2_6_2","doi-asserted-by":"crossref","unstructured":"Rigger M Su Z. Finding bugs in database systems via query partitioning. In: Proceedings of the ACM on programming languages November 15\u201320 2020 Chicago IL USA. Vol. 4 pp.1\u201330. New York NY USA: ACM.","DOI":"10.1145\/3428279"},{"key":"e_1_3_2_7_2","unstructured":"Rigger M Su Z. Testing database engines via pivoted query synthesis. In: Proceedings of 14th USENIX symposium on operating systems design and implementation (OSDI 20) \u00a0November 4\u20136 2020 Virtual Event pp. 667\u2013682. Berkeley CA: USENIX Association."},{"key":"e_1_3_2_8_2","first-page":"100","article-title":"Differential testing for software","volume":"10","author":"McKeeman WM","year":"1998","unstructured":"McKeeman WM. Differential testing for software. Digit Tech J 1998; 10: 100\u2013107.","journal-title":"Digit Tech J"},{"key":"e_1_3_2_9_2","unstructured":"Bugs found in database management systems. https:\/\/www.manuelrigger.at\/dbms-bugs\/ (accessed 18 August 2023)."},{"key":"e_1_3_2_10_2","unstructured":"SQLancer. Accessed: Aug. 18 2023. https:\/\/github.com\/sqlancer\/sqlancer."},{"key":"e_1_3_2_11_2","doi-asserted-by":"crossref","unstructured":"Chen P Chen H. Angora: Efficient fuzzing by principled search. In: Proceedings of the 2018 IEEE symposium on security and privacy (SP) 21\u201323 May 2018 San Francisco CA USA 2018 pp. 711\u2013725. Los Alamitos CA: IEEE Computer Society.","DOI":"10.1109\/SP.2018.00046"},{"key":"e_1_3_2_12_2","unstructured":"Gan S Zhang C Chen P et al. GREYONE: Data flow sensitive fuzzing. In: Proceedings of the 29th USENIX security symposium (USENIX Security 20) August 12\u201314 2020 Boston MA USA pp.2577\u20132594. Berkeley CA: USENIX Association."},{"key":"e_1_3_2_13_2","unstructured":"Google. Accessed: Aug. 18 2023. Honggfuzz. https:\/\/google.github.io\/honggfuzz\/."},{"key":"e_1_3_2_14_2","doi-asserted-by":"crossref","unstructured":"Li Y Chen B Chandramohan M et al. Steelix: program-state based binary fuzzing. In: Proceedings of the 2017 11th joint meeting on foundations of software engineering September 4\u20138 2017 Paderborn Germany pp.627\u2013637. New York NY: Association for Computing Machinery (ACM).","DOI":"10.1145\/3106237.3106295"},{"key":"e_1_3_2_15_2","unstructured":"LLVM. A library for coverage-guided fuzz testing. http:\/\/llvm.org\/docs\/LibFuzzer.html (18 Aug. 2023)."},{"key":"e_1_3_2_16_2","volume-title":"Sanitize, fuzz, and harden your C++ code","author":"Serebryany K","year":"2016","unstructured":"Serebryany K. Sanitize, fuzz, and harden your C++ codeSEP, 2016. San Francisco, CA: UNISEX."},{"key":"e_1_3_2_17_2","doi-asserted-by":"crossref","unstructured":"Stephens N Grosen J Salls C et al. Driller: Augmenting fuzzing through selective symbolic execution. In: NDSS February 21\u201324 2016 San Diego CA Vol. 16 pp.1\u201316. Reston VA: Internet Society.","DOI":"10.14722\/ndss.2016.23368"},{"key":"e_1_3_2_18_2","unstructured":"Yun I Lee S Xu M et al. QSYM: A practical concolic execution engine tailored for hybrid fuzzing. In: Proceedings of the 27th USENIX security symposium (USENIX Security 18) August 15\u201317 2018 Baltimore MD USA pp.745\u2013761. Berkeley CA: USENIX Association."},{"key":"e_1_3_2_19_2","unstructured":"Zalewski M. American fuzzy lop. https:\/\/github.com\/google\/AFL (accessed 18 August 2023)."},{"key":"e_1_3_2_20_2","unstructured":"SQLite bug 5351e920\u00a0https:\/\/www.sqlite.org\/src\/info\/5351e920. (accessed 18 August 2023)."},{"key":"e_1_3_2_21_2","doi-asserted-by":"crossref","unstructured":"B\u00f6hme M Pham V-T Nguyen M-D et al. Directed greybox fuzzing. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security Oct. 30\u2013Nov. 3 2017 Dallas TX USA pp.2329\u20132344. New York NY USA: ACM.","DOI":"10.1145\/3133956.3134020"},{"key":"e_1_3_2_22_2","doi-asserted-by":"crossref","unstructured":"Chen H Xue Y Li Y et al. Hawkeye: Towards a desired directed grey-box fuzzer. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security Oct. 15\u201319 2018 Toronto ON Canada pp.2095\u20132108. New York NY USA: ACM.","DOI":"10.1145\/3243734.3243849"},{"key":"e_1_3_2_23_2","doi-asserted-by":"crossref","unstructured":"Du X Chen B Li Y et al. Leopard: Identifying vulnerable code for vulnerability assessment through program metrics. In: Proceedings of the 2019 IEEE\/ACM 41st international conference on software engineering (ICSE) May 25\u201331 2019 Montreal QC Canada pp.2095\u20132108. Piscataway NJ USA: IEEE.","DOI":"10.1109\/ICSE.2019.00024"},{"key":"e_1_3_2_24_2","doi-asserted-by":"crossref","unstructured":"Du Z Li Y Liu Y et al. WindRanger: a directed greybox fuzzer driven by deviation basic blocks. In: Proceedings of the 44th international conference on software engineering May 21\u201329 2022 Pittsburgh PA USA pp.2440\u20132451. New York NY USA: ACM.","DOI":"10.1145\/3510003.3510197"},{"key":"e_1_3_2_25_2","unstructured":"Lee G Shim W Lee B. Constraint-guided directed greybox fuzzing. In: Proceedings of the 30th USENIX security symposium (USENIX Security 21) Aug. 11\u201313 2021 Virtual Event (originally Vancouver BC Canada) pp.3559\u20133576. Berkeley CA: USENIX Association."},{"key":"e_1_3_2_26_2","unstructured":"\u00d6sterlund S Razavi K Bos H et al. {ParmeSan}: Sanitizer-guided greybox fuzzing. In: Proceedings of the 29th USENIX security symposium (USENIX Security 20) Aug. 12\u201314 2020 Virtual Event (originally Boston MA USA) pp.2289\u20132306. Berkeley CA: USENIX Association."},{"key":"e_1_3_2_27_2","unstructured":"Zong P Lv T Wang D et al. FuzzGuard: Filtering out unreachable inputs in directed grey-box fuzzing through deep learning. In: Proceedings of the 29th USENIX security symposium (USENIX security 20) Aug. 12\u201314 2020 Virtual Event (originally Boston MA USA) pp.2255\u20132269. Berkeley CA: USENIX Association."},{"key":"e_1_3_2_28_2","unstructured":"MySQL. MySQL customers. https:\/\/www.mysql.com\/ (accessed 20 August 2023)."},{"key":"e_1_3_2_29_2","unstructured":"Group PD. PostgreSQL. https:\/\/www.postgresql.org\/ (accessed 20 August 2023)."},{"key":"e_1_3_2_30_2","unstructured":"Foundation P. TiDB. https:\/\/www.pingcap.com\/ (accessed 20 August 2023)."},{"key":"e_1_3_2_31_2","unstructured":"Bug CVE-2012-2081. National Vulnerability Database (NVD) https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2012-208 (accessed August 18 2025)."},{"key":"e_1_3_2_32_2","unstructured":"Bug CVE-2012-4987. National Vulnerability Database (NVD) https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-4987 (accessed August 18 2025)."},{"key":"e_1_3_2_33_2","doi-asserted-by":"crossref","unstructured":"Ghit B Poggi N Rosen J et al. SparkFuzz: Searching correctness regressions in modern query engines. In: Proceedings of the workshop on testing database systems June 19 2020 Portland OR USA pp.1\u20136. New York NY USA: ACM.","DOI":"10.1145\/3395032.3395327"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-009-0157-y"},{"key":"e_1_3_2_35_2","unstructured":"Slutz DR. Massive stochastic testing of SQL. In: VLDB Aug. 24\u201327 1998 pp. 618\u2013622 New York City NY USA pp. 618\u2013622. Burlington MA USA: Morgan Kaufmann."},{"key":"e_1_3_2_36_2","doi-asserted-by":"crossref","unstructured":"Ding ZY Goues CL. An empirical study of OSS-Fuzz bugs. In: Proceedings of the 2021 IEEE\/ACM 18th international conference on mining software repositories (MSR) May 17\u201319 2021 virtual (co-located with ICSE 2021) pp.131\u2013142. New York NY USA: ACM (IEEE\/ACM).","DOI":"10.1109\/MSR52588.2021.00026"},{"key":"e_1_3_2_37_2","doi-asserted-by":"crossref","unstructured":"Choi J Kim K Lee D et al. NTFuzz: Enabling type-aware kernel fuzzing on windows with static binary analysis. In: Proceedings of the 2021 IEEE symposium on security and privacy (SP) May 23\u201327 2021 virtual (planned in San Francisco CA USA) pp.677\u2013693. Piscataway NJ USA: IEEE.","DOI":"10.1109\/SP40001.2021.00114"},{"key":"e_1_3_2_38_2","doi-asserted-by":"crossref","unstructured":"Kim K Jeong DR Kim CH et al. HFL: Hybrid fuzzing on the Linux kernel. In: Proceedings of the 27th annual network and distributed system security symposium (NDSS) Feb. 23\u201326 2020 San Diego CA USA. Reston VA USA: Internet Society 2020 pp. 1\u201316.","DOI":"10.14722\/ndss.2020.24018"},{"key":"e_1_3_2_39_2","unstructured":"Pailoor S Aday A Jana S. {MoonShine}: Optimizing {OS} fuzzer seed selection with trace distillation. In: Proceedings of the 27th USENIX security symposium (USENIX Security 18) Aug. 15\u201317 2018 Baltimore MD USA pp.729\u2013743. Berkeley CA USA: USENIX Association."},{"key":"e_1_3_2_40_2","doi-asserted-by":"crossref","unstructured":"Xu M Kashyap S Zhao H et al. Krace: Data race fuzzing for kernel file systems. In: Proceedings of the 2020 IEEE symposium on security and privacy (SP) May 18\u201321 2020 San Francisco CA USA pp.1643\u20131660. Piscataway NJ USA: IEEE.","DOI":"10.1109\/SP40000.2020.00078"},{"key":"e_1_3_2_41_2","doi-asserted-by":"crossref","unstructured":"Xu W Moon H Kashyap S et al. Fuzzing file systems via two-dimensional input space exploration. In: Proceedings of the 2019 IEEE symposium on security and privacy (SP) May 19\u201322 2019 San Francisco CA USA pp.818\u2013834. Piscataway NJ USA: IEEE.","DOI":"10.1109\/SP.2019.00035"},{"key":"e_1_3_2_42_2","doi-asserted-by":"crossref","unstructured":"Chen Y Zhong R Hu H et al. One engine to fuzz\u2019em all: Generic language processor testing with semantic validation. In: Proceedings of the 2021 IEEE symposium on security and privacy (SP) May 24\u201328 2021 San Francisco CA USA pp. 642\u2013658. Piscataway NJ USA: IEEE.","DOI":"10.1109\/SP40001.2021.00071"},{"key":"e_1_3_2_43_2","doi-asserted-by":"crossref","unstructured":"Han H Oh D Cha SK. CodeAlchemist: Semantics-aware code generation to find vulnerabilities in JavaScript engines. In: Proceedings of the 26th network and distributed system security symposium (NDSS) Feb. 24\u201327 2019 San Diego CA USA pp. 1\u201316. Reston VA USA: The Internet Society.","DOI":"10.14722\/ndss.2019.23263"},{"key":"e_1_3_2_44_2","doi-asserted-by":"crossref","unstructured":"Park S Xu W Yun I et al. Fuzzing JavaScript engines with aspect-preserving mutation. In: Proceedings of the 2020 IEEE symposium on security and privacy (SP) May 18\u201321 2020 San Francisco CA USA. Piscataway NJ USA: IEEE pp.1629\u20131642.","DOI":"10.1109\/SP40000.2020.00067"},{"key":"e_1_3_2_45_2","unstructured":"Google. ClusterFuzz. https:\/\/google.github.io\/clusterfuzz (accessed 18 August 2023)."},{"key":"e_1_3_2_46_2","doi-asserted-by":"crossref","unstructured":"Xu W Park S Kim T. Freedom: Engineering a state-of-the-art dom fuzzer. In: Proceedings of the 2020 ACM SIGSAC conference on computer and communications security Nov. 9\u201313 2020 pp. 971\u2013986. New York NY USA: ACM.","DOI":"10.1145\/3372297.3423340"},{"key":"e_1_3_2_47_2","doi-asserted-by":"crossref","unstructured":"Dinh ST Cho H Martin K et al. Favocado: Fuzzing the binding code of JavaScript engines using semantically correct test cases. In: Proceedings of the 28th annual network and distributed system security symposium (NDSS) Feb. 21\u201325 2021 San Diego CA USA pp. 1\u201316. Reston VA USA: The Internet Society.","DOI":"10.14722\/ndss.2021.24224"},{"key":"e_1_3_2_48_2","doi-asserted-by":"crossref","unstructured":"Xu P Wang Y Hu H et al. COOPER: Testing the binding code of scripting languages with cooperative mutation. In: Proceedings of the 28th annual network and distributed system security symposium (NDSS) Feb. 27\u2013Mar. 3 2022 San Diego CA USA pp. 1\u201316. Reston VA USA: The Internet Society.","DOI":"10.14722\/ndss.2022.24353"},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","unstructured":"Jiang B Liu Y Chan WK. Contractfuzzer: Fuzzing smart contracts for vulnerability detection. In: Proceedings of the 33rd ACM\/IEEE international conference on automated software engineering Sep. 3\u20137 2018 Montpellier France pp. 259\u2013269. New York NY USA: ACM 2018.","DOI":"10.1145\/3238147.3238177"},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","unstructured":"Nguyen TD Pham LH Sun J et al. sfuzz: An efficient adaptive fuzzer for solidity smart contracts. In: Proceedings of the ACM\/IEEE 42nd international conference on software engineering Jun. 27\u2013Jul. 19 2020 Seoul South Korea 2020 pp. 778\u2013788. New York NY USA: IEEE.","DOI":"10.1145\/3377811.3380334"},{"key":"e_1_3_2_51_2","doi-asserted-by":"crossref","unstructured":"W\u00fcstholz V Christakis M. Harvey: A greybox fuzzer for smart contracts. In: Proceedings of the 28th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering Nov. 10 2020 Virtual 2020 pp. 1398\u20131409. New York NY USA: ACM.","DOI":"10.1145\/3368089.3417064"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.14778\/3357377.3357382"},{"key":"e_1_3_2_53_2","unstructured":"Liu X Zhou Q Arulraj J et al. Automated performance bug detection in database systems. arXiv preprint arXiv:2105.10016 2021."},{"key":"e_1_3_2_54_2","doi-asserted-by":"crossref","unstructured":"Wang M Wu Z Xu X et al. Industry practice of coverage-guided enterprise-level DBMS fuzzing. In: Proceedings of the 2021 IEEE\/ACM 43rd International conference on software engineering: Software engineering in practice (ICSE-SEIP) May 23\u201329 2021 Madrid Spain pp. 328\u2013337. Piscataway NJ USA: IEEE.","DOI":"10.1109\/ICSE-SEIP52600.2021.00042"},{"key":"e_1_3_2_55_2","doi-asserted-by":"crossref","unstructured":"Zhong R Chen Y Hu H et al. Squirrel: Testing database management systems with language validity and coverage feedback. In: Proceedings of the 2020 ACM SIGSAC conference on computer and communications security Nov. 9\u201313 2020 Virtual Event USA pp. 955\u2013970. New York NY USA: ACM 2020.","DOI":"10.1145\/3372297.3417260"},{"key":"e_1_3_2_56_2","unstructured":"SQLite bug 1b1dd4d4. SQLite Version Control System.\u00a0https:\/\/www.sqlite.org\/src\/info\/1b1dd4d4 (accessed 18 August 2023)."},{"key":"e_1_3_2_57_2","unstructured":"SQLite bug f65c929. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/f65c929. (accessed 18 August 2023)."},{"key":"e_1_3_2_58_2","unstructured":"SQLite bug f9c6426. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/f9c6426. (accessed 18 August 2023)."},{"key":"e_1_3_2_59_2","unstructured":"SQLite bug faaaae49. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/faaaae49. (accessed 18 August 2023)."},{"key":"e_1_3_2_60_2","unstructured":"SQLite bug c0c90961. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/c0c90961. (accessed 18 August 2023)."},{"key":"e_1_3_2_61_2","unstructured":"SQLite bug db9acef1. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/db9acef1. (accessed 18 August 2023)."},{"key":"e_1_3_2_62_2","unstructured":"SQLite bug 16252d7. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/16252d7. (accessed 18 August 2023)."},{"key":"e_1_3_2_63_2","unstructured":"SQLite bug 659c551d. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/659c551d. (accessed 18 August 2023)."},{"key":"e_1_3_2_64_2","unstructured":"SQLite bug 86fa0087. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/86fa0087. (accessed 18 August 2023)."},{"key":"e_1_3_2_65_2","unstructured":"SQLite bug 6ac0f822. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/6ac0f822. (accessed 18 August 2023)."},{"key":"e_1_3_2_66_2","unstructured":"SQLite bug ebe4845c. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/ebe4845c. (accessed 18 August 2023)."},{"key":"e_1_3_2_67_2","unstructured":"SQLite bug 1685610e. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/1685610e. (accessed 18 August 2023)."},{"key":"e_1_3_2_68_2","unstructured":"SQLite bug f898d04c. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/f898d04c. (accessed 18 August 2023)."},{"key":"e_1_3_2_69_2","unstructured":"SQLite bug 9c8c1092. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/9c8c1092. (accessed 18 August 2023)."},{"key":"e_1_3_2_70_2","unstructured":"SQLite bug eb40248. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/eb40248. (accessed 18 August 2023)."},{"key":"e_1_3_2_71_2","unstructured":"SQLite bug 54110870. SQLite Version Control System. https:\/\/www.sqlite.org\/src\/info\/54110870. (accessed 18 August 2023)."},{"key":"e_1_3_2_72_2","unstructured":"MySQL bug 99122. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=99122. (accessed 18 August 2023)."},{"key":"e_1_3_2_73_2","unstructured":"MySQL bug 95927. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=95927. (accessed 18 August 2023)."},{"key":"e_1_3_2_74_2","unstructured":"MySQL bug 95954. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=95954. (accessed 18 August 2023)."},{"key":"e_1_3_2_75_2","unstructured":"MySQL bug 95908. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=95908. (accessed 18 August 2023)."},{"key":"e_1_3_2_76_2","unstructured":"MySQL bug 95926. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=95926. (accessed 18 August 2023)."},{"key":"e_1_3_2_77_2","unstructured":"MySQL bug 95975. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=95975. (accessed 18 August 2023)."},{"key":"e_1_3_2_78_2","unstructured":"MySQL bug 95983. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=95983. (accessed 18 August 2023)."},{"key":"e_1_3_2_79_2","unstructured":"MySQL bug 95937. SQLite Version Control System. https:\/\/bugs.mysql.com\/bug.php?id=95937. (accessed 18 August 2023)."},{"key":"e_1_3_2_80_2","unstructured":"TiDB bug 15725. SQLite Version Control System. https:\/\/github.com\/pingcap\/tidb\/issues\/15725. (accessed 18 August 2023)."},{"key":"e_1_3_2_81_2","unstructured":"TiDB bug 15733. SQLite Version Control System. https:\/\/github.com\/pingcap\/tidb\/issues\/15733. (accessed 18 August 2023)."},{"key":"e_1_3_2_82_2","unstructured":"TiDB bug 15986. SQLite Version Control System. https:\/\/github.com\/pingcap\/tidb\/issues\/15986. (accessed 18 August 2023)."},{"key":"e_1_3_2_83_2","unstructured":"TiDB bug 15789. SQLite Version Control System. https:\/\/github.com\/pingcap\/tidb\/issues\/15789. (accessed 18 August 2023)."},{"key":"e_1_3_2_84_2","unstructured":"TiDB bug 15846. SQLite Version Control System. https:\/\/github.com\/pingcap\/tidb\/issues\/15846. (accessed 18 August 2023)."},{"key":"e_1_3_2_85_2","unstructured":"TiDB bug 15994. SQLite Version Control System. https:\/\/github.com\/pingcap\/tidb\/issues\/15994. (accessed 18 August 2023)."},{"key":"e_1_3_2_86_2","unstructured":"TiDB bug 17814. SQLite Version Control System. https:\/\/github.com\/pingcap\/tidb\/issues\/17814. (accessed 18 August 2023)."},{"key":"e_1_3_2_87_2","unstructured":"LLVM pass. SQLite Version Control System. https:\/\/llvm.org\/docs\/WritingAnLLVMPass.html. (accessed 18 August 2023)."},{"key":"e_1_3_2_88_2","unstructured":"Xu D Tang D Chen Y et al. Racing on the negative force: Efficient vulnerability {Root-Cause} analysis through reinforcement learning on counterexamples. In: 33rd USENIX security symposium (USENIX Security 24) Aug. 14\u201316 2024 Philadelphia PA USA 2024 pp. 4229\u20134246. Berkeley CA USA: USENIX Association."},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1145\/3654991"},{"key":"e_1_3_2_90_2","unstructured":"Hao Z Huang Q Wang C et al. Pinolo: Detecting logical bugs in database management systems with approximate query synthesis. In: 2023 USENIX annual technical conference (USENIX ATC 23) Jul. 10\u201312 2023 Boston MA USA 2023 pp. 345\u2013358. Berkeley CA USA: USENIX Association."},{"key":"e_1_3_2_91_2","unstructured":"Jiang Z-M Su Z. Detecting logic bugs in database engines via equivalent expression transformation. In: 18th USENIX Symposium on operating systems design and implementation (OSDI 24) Jul. 10\u201312 2024 Santa Clara CA USA 2024 pp. 821\u2013835. Berkeley CA USA: USENIX Association."},{"key":"e_1_3_2_92_2","doi-asserted-by":"crossref","unstructured":"Song J Dou W Cui Z et al. Testing database systems via differential query execution. In: 2023 IEEE\/ACM 45th International conference on software engineering (ICSE) May 14-20 2023 Melbourne Australiam pp.2072\u20132084. Piscataway New Jersey USA: IEEE.","DOI":"10.1109\/ICSE48619.2023.00175"},{"key":"e_1_3_2_93_2","doi-asserted-by":"crossref","unstructured":"Sang Q Wang Y Liu Y et al. Airtaint: Making dynamic taint analysis faster and easier. In: 2024 IEEE symposium on security and privacy (SP) 19-23 May 2024 San Francisco CA USA. pp.3998\u20134014. Piscataway New Jersey USA: IEEE.","DOI":"10.1109\/SP54263.2024.00045"},{"key":"e_1_3_2_94_2","doi-asserted-by":"crossref","unstructured":"He J Sivanrupan G Tsankov P et al. Learning to explore paths for symbolic execution. In: Proceedings of the 2021 ACM SIGSAC conference on computer and communications security November 15\u201319 2021 pp.2526\u20132540. Virtual Event. New York NY: Association for Computing Machinery.","DOI":"10.1145\/3460120.3484813"},{"key":"e_1_3_2_95_2","unstructured":"Qin L Chen Q Feng X et al. Large language models meet NLP: A survey. arXiv preprint arXiv:2405.12819 2024."},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2024.100211"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251370258","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0926227X251370258","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251370258","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:56Z","timestamp":1777495556000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0926227X251370258"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,5]]},"references-count":95,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,1]]}},"alternative-id":["10.1177\/0926227X251370258"],"URL":"https:\/\/doi.org\/10.1177\/0926227x251370258","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,5]]}}}