{"id":"W2401568214","doi":"","title":"Combining static analysis and targeted symbolic execution for scalable bug-finding in application binaries","year":2016,"lang":"en","type":"article","venue":"Computer Science and Software Engineering","topic":"Software Testing and Debugging Techniques","field":"Computer Science","cited_by":13,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Symbolic execution; Computer science; Concolic testing; Program analysis; Static analysis; Statement (logic); Programming language; Pruning; Process (computing); Program slicing; Scalability; Code (set theory); Debugging; Software; Operating system","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001250889,0.001460441,0.0008954309,0.002629257,0.0005078268,0.00109891,0.001450246,0.0006426616,0.002212662],"category_scores_gemma":[0.005514572,0.0007491583,0.0009681858,0.001601791,0.00142543,0.002145782,0.002595677,0.0009096682,0.0006735672],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008378673,"about_ca_system_score_gemma":0.001792642,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.004554341,"about_ca_topic_score_gemma":0.00508123,"domain_scores_codex":[0.9983626,0.0004180827,0.0001313507,0.0003034998,0.0005704755,0.0002139855],"domain_scores_gemma":[0.9962791,0.002032992,0.0003975521,0.0007943486,0.0003650948,0.0001309831],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0008481812,0.0003661502,0.01273029,0.0008725262,0.0001983914,0.0007346321,0.0007826631,0.2884261,0.08614955,0.0135128,0.003757607,0.5916211],"study_design_scores_gemma":[0.00004927138,0.0001605739,0.001209602,0.00005538229,0.00007762883,0.0001352525,0.00007466147,0.9534953,0.03169879,0.01064972,0.002348659,0.00004525597],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1198173,0.0005780359,0.8343806,0.0002807787,0.00004458274,0.0001992823,0.0002974366,0.04171865,0.002683388],"genre_scores_gemma":[0.6382964,0.0003400309,0.3570915,0.0001363411,0.00002745972,0.0001922784,0.0006971966,0.001828082,0.001390642],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.004554341,"threshold_uncertainty_score":0.009055674,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.009698424595459712,"score_gpt":0.2327454978405086,"score_spread":0.2230470732450489,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}