• Home
  • Search
  • FENSE: Feedback-Driven Incremental Symbolic Execution for Redundant Path Elimination
  • https://doi.org/10.1109/tse.2026.3667998Copy DOI Icon

FENSE: Feedback-Driven Incremental Symbolic Execution for Redundant Path Elimination

Show More
  • Abstract
  • Literature Map
  • Similar Papers
Abstract

Incremental symbolic execution aims to address the scalability challenges of traditional symbolic execution by concentrating on behavioural differences between program versions introduced during program evolution. Despite progress in the field, existing techniques often struggle to explore these behaviors both efficiently and accurately. In this paper, we introduce <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FENSE</monospace>, a novel approach for incremental symbolic execution that improves efficiency by identifying and eliminating redundant paths. <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FENSE</monospace> achieves this by summarizing previously explored paths and monitoring variables that may induce divergent incremental behaviors at each branching point. This summarization process enables <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FENSE</monospace> to detect whether a newly explored path subsumes distinct incremental behaviors compared to prior explorations. By effectively pruning redundant paths that exhibit identical incremental behaviors as those previously explored, <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FENSE</monospace> achieves a potentially exponential reduction in the number of explored paths. We implemented a prototype of <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FENSE</monospace> and evaluated it on a diverse set of real-world applications. Experimental results demonstrate that <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FENSE</monospace> outperforms state-of-the-art techniques by significantly reducing both path exploration and execution time. When applied to real-world commits from the GNU Coreutils project, <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">FENSE</monospace> achieved an average of 76% reduction in explored paths and a 139× speedup over <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">KLEE</monospace>.

Similar Papers
  • Research Article
  • Citations38

Eliminating Path Redundancy via Postconditioned Symbolic Execution

  • Jan 01, 2018
  • IEEE Transactions on Software Engineering
  • Qiuping Yi +5
  • Conference Article
  • Citations31

Compositional Symbolic Execution with Memoized Replay

  • May 01, 2015
  • Rui Qiu +3
  • Book Chapter
  • Citations2

Symbolic Execution and Deductive Verification Approaches to VerifyThis 2017 Challenges

  • Jan 01, 2018
  • Ziqing Luo +1
  • Research Article
  • Citations7

Lazy symbolic execution for test data generation

  • Apr 01, 2011
  • IET Software
  • M.X Lin +3
  • Research Article
  • Citations3

Genetic algorithm based estimation of non–functional properties for GPGPU programs

  • Dec 07, 2019
  • Journal of Systems Architecture
  • Adrian Horga +3
  • Research Article

Side-Channel Analysis via Symbolic Execution and Model Counting

  • Dec 28, 2018
  • ACM SIGSOFT Software Engineering Notes
  • Tevfik Bultan
  • Research Article
  • Citations8

Scaling symbolic execution using ranged analysis

  • Oct 19, 2012
  • ACM SIGPLAN Notices
  • Junaid Haroon Siddiqui +1
  • Research Article
  • Citations2

The Optimization of a Symbolic Execution Engine for Detecting Runtime Errors

  • Jan 01, 2017
  • Acta Cybernetica
  • István Kádár
  • Conference Article
  • Citations15

QFuzz: quantitative fuzzing for side channels

  • Jul 11, 2021
  • Yannic Noller +1
  • Research Article
  • Citations24

Scalable and precise refinement of cache timing analysis via path-sensitive verification

  • Feb 02, 2013
  • Real-Time Systems
  • Sudipta Chattopadhyay +1
  • Conference Article
  • Citations41

JBSE: a symbolic executor for Java programs with complex heap inputs

  • Nov 01, 2016
  • Pietro Braione +2
  • Research Article

Fast PokeEMU

  • Mar 25, 2018
  • ACM SIGPLAN Notices
  • Qiuchen Yan +1
  • Research Article

Optimizing Symbolic Execution Path Exploration with a Transfer Learning-Based Strategy

  • Sep 11, 2025
  • International Journal of Computers Communications & Control
  • Te Sun +3
  • Research Article
  • Citations67

Observation of nonspherical particle behaviors for continuous shape-based separation using hydrodynamic filtration

  • Apr 20, 2011
  • Biomicrofluidics
  • Sari Sugaya +2
  • Conference Article
  • Citations1

Address-Aware Query Caching for Symbolic Execution

  • Apr 01, 2021
  • David Trabish +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.