Boosting API Misuse Detection via Integrating API Constraints from Multiple Sources

Can Li, Jingxuan Zhang, Yixuan Tang, Zhuhang Li, Tianyue Sun · 2024

In modern software development, developers access reusable functionality provided by third-party libraries through Application Programming Interfaces (APIs). However, using APIs requires developers to conform specific constraints and guidelines, otherwise it may lead to API misuses. Existing approaches for API misuse detection often rely on analyzing API documentation or mining client code. However, these approaches are limited by the quality of API documentation and the naive assumption that deviations from common usage patterns in client code imply potential API misuses, making them less reliable. In this paper, we propose an approach that comprehensively integrates the API usage constraints from multiple sources, including client code, API documentation, and library code, to detect API misuses. First, we convert client code into API Usage Graphs (AUGs), extract the API usage patterns, and apply heuristic filtering rules to obtain API usage constraints. Meanwhile, we also analyze library code and API documentation to obtain various API usage constraints. Next, we combine the obtained API usage constraints from multiple sources together to generate a series of API preliminary constraint graphs. Based on these API preliminary constraint graphs, we design constraint alternative strategies to form API alternative constraint graphs. Finally, we parse the Abstract Syntax Tree (AST) of the test code and match it against API (alternative) constraint graphs to detect API misuses. The experimental evaluation demonstrates that our approach achieves the Precision of 72.22% and the Recall of 43.01% on the MUBench dataset, with an F1 score of 53.91%. These values significantly outperform existing state-of-the-art API misuse detection approaches, highlighting the effectiveness of integrating API usage constraints from various sources. Additionally, the designed heuristic filtering rules and constraint alternative strategies significantly reduce false positives, enhancing the Precision of our approach in API misuse detection.

Read the paper · More papers on PaperTik