Studying and Understanding the Tradeoffs Between Generality and Reduction in Software Debloating
Qi Xin,Qirun Zhang,Alessandro Orso +2 more
- 10 Oct 2022
17
TL;DR: In this paper , the authors perform an empirical evaluation of the reduction and generality of four debloating techniques, three state-of-the-art ones, and a baseline, on a set of 25 programs and different sets of inputs for these programs.
read more
Abstract: Existing approaches for program debloating often use a usage profile, typically provided as a set of inputs, for identifying the features of a program to be preserved. Specifically, given a program and a set of inputs, these techniques produce a reduced program that behaves correctly for these inputs. Focusing only on reduction, however, would typically result in programs that are overfitted to the inputs used for debloating. For this reason, another important factor to consider in the context of debloating is generality, which measures the extent to which a debloated program behaves correctly also for inputs that were not in the initial usage profile. Unfortunately, most evaluations of existing debloating approaches only consider reduction, thus providing partial information on the effectiveness of these approaches. To address this limitation, we perform an empirical evaluation of the reduction and generality of 4 debloating techniques, 3 state-of-the-art ones, and a baseline, on a set of 25 programs and different sets of inputs for these programs. Our results show that these approaches can indeed produce programs that are overfitted to the inputs used and have low generality. Based on these results, we also propose two new augmentation approaches and evaluate their effectiveness. The results of this additional evaluation show that these two approaches can help improve program generality without significantly affecting size reduction. Finally, because different approaches have different strengths and weaknesses, we also provide guidelines to help users choose the most suitable approach based on their specific needs and context.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
A Call for Removing Variability
Mathieu Acher,Luc Lesoil,Georges Aaron Randrianaina,Xhevahire Tërnava,Olivier Zendra +4 more
- 25 Jan 2023
TL;DR: In this article , a call to the community on software variability to devise methods and tools that will facilitate the removal of unneeded variability from software systems is made, and the advantages are expected to be numerous in terms of functional and non-functional properties.
IOSPReD: I/O Specialized Packaging of Reduced Datasets and Data-Intensive Applications for Efficient Reproducibility
01 Jan 2023
TL;DR: IOSPReD as discussed by the authors is a data-based debloating framework, designed to automatically track and package only necessary chunks of data (along with the application) in a container.
Machine Learning Systems are Bloated and Vulnerable
Huaifeng Zhang,Mohannad Alhanahnah,Fahmi Abdulqadir Ahmed,Dyako Fatih,Philipp Leitner,Ahmed Ali-Eldin +5 more
TL;DR: Machine learning containers are often bloated with unnecessary code and dependencies, significantly impacting container size, provisioning time, and vulnerabilities.
2
IOSPReD: I/O Specialized Packaging of Reduced Datasets and Data-Intensive Applications for Efficient Reproducibility
TL;DR: IOSPReD as discussed by the authors is a data-based debloating framework, designed to automatically track and package only necessary chunks of data (along with the application) in a container.
2
Scalable Demand-Driven Call Graph Generation for Python
TL;DR: Jarvis as discussed by the authors is a scalable demand-driven approach for generating call graphs for Python programs, and implement it as a prototype tool Jarvis maintains an assignment graph (i.e., points-to relations between program identifiers) for each function in a program to allow reuse and improve scalability.
1
References
The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86)
Hovav Shacham
- 28 Oct 2007
TL;DR: A return-into-libc attack to be mounted on x86 executables that calls no functions at all is presented, and how to discover such instruction sequences by means of static analysis is shown.
1.5K
Feature location in source code: a taxonomy and survey
TL;DR: A systematic literature survey of feature location techniques is presented and eighty‐nine articles from 25 venues have been reviewed and classified within the taxonomy in order to organize and structure existing work in the field of feature locations.
Automatic patch generation by learning correct code
Fan Long,Martin Rinard +1 more
- 11 Jan 2016
TL;DR: Experimental results show that, on a benchmark set of 69 real-world defects drawn from eight open-source projects, Prophet significantly outperforms the previous state-of-the-art patch generation system.
Staged program repair with condition synthesis
Fan Long,Martin Rinard +1 more
- 30 Aug 2015
TL;DR: SPR, a new program repair system that combines staged program repair and condition synthesis, is presented, to generate correct repairs for over five times as many defects as previous systems evaluated on the same benchmark set.
Automated program repair
TL;DR: This research presents a meta-modelling system that automates the very labor-intensive and therefore time-heavy and therefore expensive and expensive process of manually fixing programming mistakes.
424