AI 中文总结
本文提出PROGRESS,将意图驱动属性整合到搜索式进化测试生成中,在25个Java系统上验证其能高效检测漏洞、满足属性前置条件,可暴露回归测试遗漏的故障。
AI 中文摘要
基于搜索的回归测试生成能有效探索复杂程序结构,获得高结构覆盖率,但其预言源自被测系统:已存在的故障被记录为预期行为而非暴露。基于属性的测试提供独立的语义预言,但依赖高质量属性,且对到达深层状态或满足选择性前置条件的指导不足。本文提出PROGRESS(PROperty-Guided REgression Search for Semantic Falsification),将意图驱动的属性整合到基于覆盖率的搜索式进化测试生成中,以到达深层程序状态并检测意图行为的违反。PROGRESS包含三方面工作:(1)提取带意图的代码上下文,使用语言模型流水线生成可执行的jqwik属性,同时限制实现泄漏;(2)为每个属性扩展EvoSuite的DynaMOSA,加入搜索目标和属性感知适应度函数,奖励通过前置条件的进展并优先选择证伪执行;(3)绑定属性参数,使用jqwik提供的生成器将量化输入与演化测试序列关联,引导生成朝向覆盖率和漏洞检测目标。我们在25个大规模Java系统上对PROGRESS进行评估,与回归测试生成、独立基于属性的测试及上下文消融实验对比:PROGRESS检测到当前版本562个漏洞中的328个(占比58%),而回归测试生成未检测到任何漏洞;PROGRESS满足150个难访问属性中70个的所有前置条件,独立jqwik仅满足18个;消融实验表明文档和调用者/被调用者上下文是生成有效可执行属性的关键。PROGRESS在保留结构探索能力的同时,能暴露回归导出断言遗漏的漏洞;我们发布了完整的工件包。
英文摘要
Search-based regression-test generation effectively explores complex program structures, yielding high structural coverage, but its oracles are derived from the system under test: faults already present are recorded as expected behavior rather than exposed. Property-based testing offers independent semantic oracles, but depends on high-quality properties and gives little guidance for reaching deep states or satisfying selective preconditions. We present PROGRESS (PROperty-Guided REgression Search for Semantic Falsification), integrating intent-driven properties into coverage-guided, search-based evolutionary test generation to reach deep program states and detect violations of intended behavior. PROGRESS (1) extracts intent-bearing code context and uses a language-model pipeline to generate executable jqwik properties while limiting implementation leakage; (2) extends EvoSuite's DynaMOSA with a search objective and property-aware fitness function per property, rewarding progress through preconditions and prioritizing falsifying executions; and (3) binds property parameters and uses jqwik-provided generators to connect quantified inputs to evolving test sequences, steering generation toward coverage and bug-detection goals. We evaluate PROGRESS on 25 large-scale Java systems against regression-test generation, standalone property-based testing, and context ablations. PROGRESS detects 328/562 current-version bugs (58%) versus none for regression-test generation, and satisfies all preconditions for 70/150 hard-to-reach properties versus 18 for standalone jqwik. Ablations show documentation and caller/callee context are key to generating valid executable properties. PROGRESS preserves structural exploration while exposing faults missed by regression-derived assertions; we release a comprehensive artifact package.
Comments12 pages, 2 figures