LLM-Based Alarm Resolution Guided by Bayesian Program Analysis
This program is tentative and subject to change.
Abstract-interpretation-based static analyzers often report large numbers of alarms due to over-approximation. Although large language models (LLMs) can help filter alarms, per-alarm prompting is often inaccurate and expensive. Alarm validity may require long, fragile whole-program reasoning, and the repeated context wastes many tokens. We shift LLM judgment from end alarms to small, local intermediate facts (e.g., alias or flow edges), which are easier to validate. If a fact is judged false, all dependent facts and alarms can be pruned. We capture these dependencies in a derivation graph, enabling analyzer-agnostic pruning for any tool that exposes derivations. Under a token budget, we define the fact impact prioritization problem, which asks which facts to query first to maximize expected downstream pruning. We solve it with Bayesian program analysis by estimating each fact’s pruning impact from rule probabilities and fact posteriors. Building on these ideas, we present an LLM-based alarm resolution framework guided by Bayesian program analysis. It iteratively queries high-impact facts that LLMs can judge accurately, prunes downstream nodes when a fact is false, and feeds the judgments back to the Bayesian model as high-confidence evidence. We evaluate our approach on a Java datarace analysis and a C taint analysis, showing that it improves alarm-resolution quality while substantially reducing token consumption compared with both unfiltered static analysis and per-alarm LLM judging.
This program is tentative and subject to change.
Mon 5 OctDisplayed time zone: Pacific Time (US & Canada) change
10:30 - 12:00 | LLM Agents for Program AnalysisOOPSLA at East Hall 2 Chair(s): Yun Lin Shanghai Jiao Tong University | ||
10:30 18mTalk | Process-Centric Analysis of Agentic Software Systems OOPSLA Shuyang Liu University of Illinois at Urbana-Champaign, Yang Chen University of Illinois at Urbana-Champaign, Rahul Krishna IBM Research, Saurabh Sinha IBM Research, Jatin Ganhotra IBM Research, Reyhaneh Jabbarvand University of Illinois at Urbana-Champaign | ||
10:48 18mTalk | MetaSpace: Metamorphic Testing for Spatial Cognition in Embodied Agents OOPSLA Gengyang Xu Department of Computer Science and Engineering, The Hong Kong University of Science and Technology, Dongwei Xiao Hong Kong University of Science and Technology, Yiteng Peng Hong Kong University of Science and Technology, Shuai Wang Hong Kong University of Science and Technology | ||
11:06 18mTalk | Reframing Paths as Logic: Semantic Segmentation for Vulnerability Detection OOPSLA Zong Cao Imperial Global Singapore, Yuqiang Sun Nanyang Technological University, Zhengzi Xu Imperial Global Singapore, Kaixuan Li Nanyang Technological University, Yeqi Fu National University of Singapore, Yiran Zhang Nanyang Technological University, Ziqiao Kong Nanyang Technological University, Yang Liu Nanyang Technological University | ||
11:24 18mTalk | Agent-Based Automated Remediation for Vulnerabilities in Maven Projects OOPSLA Lyuye Zhang Nanyang Technological University, He Ye University College London (UCL), Federica Sarro University College London, Yuqiang Sun Nanyang Technological University, Yang Liu Nanyang Technological University | ||
11:42 18mTalk | LLM-Based Alarm Resolution Guided by Bayesian Program Analysis OOPSLA Yifan Zhang Peking University, Yuanfeng Shi Peking University, Haoran Lin Peking University, Yingfei Xiong Peking University, Xin Zhang Peking University | ||