{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:09:25Z","timestamp":1782846565282,"version":"3.54.5"},"reference-count":81,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-2505223"],"award-info":[{"award-number":["CCF-2505223"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N000142512252"],"award-info":[{"award-number":["N000142512252"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Dynamic dependence analysis is essential for software performance optimization, debugging, regression testing, and security analysis. In long-running and distributed systems, continuously performing this analysis while balancing cost and precision under strict time budgets is a persistent challenge. Current state-of-the-art (SOTA) approaches tackled this problem but suffer from inefficient budget utilization and\/or imprecise dependence results, limiting their practicality in real-world software engineering workflows. We introduce GDist, a novel two-level adaptation framework that self-tunes analysis parameters to optimize cost-effectiveness for continuous dynamic dependence analysis. GDist integrates a decision-tree-based learning model, tailored to system executions, with domain knowledge about analysis precision levels, ensuring a more precise and budget-observing adaptation strategy. We evaluate GDist on 12 real-world distributed systems and in two key applications: regression test reduction and vulnerability detection. Results show that GDist improves budget utilization by 29% and precision by 18% over SOTA. Specifically, GDist reduces regression testing costs by 31% while maintaining test effectiveness and lowers the cost of identifying true-positive vulnerabilities by 36% in enterprise-scale systems. Its lightweight adaptation and the inherent interpretability of decision trees make it well-suited for scalable, cost-aware software maintenance and security analysis. These merits position GDist as a practical and adaptive solution for modern software engineering challenges.<\/jats:p>","DOI":"10.1145\/3808167","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"3627-3650","source":"Crossref","is-referenced-by-count":0,"title":["Two-Level Adaptation for Budget-Constrained Continuous Dynamic Dependence Analysis"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-8769-5404","authenticated-orcid":false,"given":"Xiaoqin","family":"Fu","sequence":"first","affiliation":[{"name":"Washington State University, Pullman, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-5224-9970","authenticated-orcid":false,"given":"Haipeng","family":"Cai","sequence":"additional","affiliation":[{"name":"University at Buffalo, SUNY, Buffalo, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2014. Vulnerability Details : CVE-2014-0085. https:\/\/2.zoppoz.workers.dev:443\/https\/www.cvedetails.com\/cve\/CVE-2014-0085\/."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330701"},{"key":"e_1_2_1_3_1","unstructured":"Apache. 2015. Voldemort. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/voldemort."},{"key":"e_1_2_1_4_1","unstructured":"Apache. 2015. ZooKeeper. https:\/\/2.zoppoz.workers.dev:443\/https\/zookeeper.apache.org\/."},{"key":"e_1_2_1_5_1","unstructured":"Apache. 2018. Thrift. https:\/\/2.zoppoz.workers.dev:443\/https\/thrift.apache.org\/."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1449764.1449776"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1088\/1749-"},{"key":"e_1_2_1_8_1","first-page":"2546","article-title":"Algorithms for hyper-parameter optimization","volume":"24","author":"Bergstra James S","year":"2011","unstructured":"James S Bergstra, R\u00e9mi Bardenet, Yoshua Bengio, and Bal\u00e1zs K\u00e9gl. 2011. Algorithms for hyper-parameter optimization. In Advances in Neural Information Processing Systems (NIPS), Vol. 24. 2546-2554.","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3375633"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-03421-4_11"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183399.3183401"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2017.2692783"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3742900"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2021.3124795"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2642937.2642950"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/saner.2015.7081833"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/tr.2015.2481000"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2894751"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2970276.2970352"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106297"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3204459"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.114.3.494"},{"key":"e_1_2_1_23_1","unstructured":"CVE. 2018. CVE-2018-8012. https:\/\/2.zoppoz.workers.dev:443\/https\/nvd.nist.gov\/vuln\/detail\/CVE-2018-8012."},{"key":"e_1_2_1_24_1","unstructured":"CVE. 2019. CVE-2018-8012. https:\/\/2.zoppoz.workers.dev:443\/https\/nvd.nist.gov\/vuln\/detail\/CVE-2019-0201."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3121257.3121262"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/tevc.2013.2281535"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/4235.996017"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10703-016-0264-5"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/icse-companion58688.2023.00092"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1882291.1882296"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3024188"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2015.2421318"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3341179"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/icpc.2019.00051"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377812.3390910"},{"key":"e_1_2_1_36_1","volume-title":"FlowDist: Multi-Staged Refinement-Based Dynamic Information Flow Analysis for Distributed Software Systems. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Fu Xiaoqin","year":"2021","unstructured":"Xiaoqin Fu and Haipeng Cai. 2021. FlowDist: Multi-Staged Refinement-Based Dynamic Information Flow Analysis for Distributed Software Systems. In 30th USENIX Security Symposium (USENIX Security 21). 2093-2110."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3417920"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379345"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/icse-companion55297.2022.9793800"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3708476"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2491411.2491462"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/seams51251.2021.00023"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/3540261.3542529"},{"key":"e_1_2_1_44_1","unstructured":"GoogleCode. 2015. MultiChat. https:\/\/2.zoppoz.workers.dev:443\/https\/code.google.com\/p\/multithread-chat-server\/."},{"key":"e_1_2_1_45_1","volume-title":"International Conference on Machine Learning. PMLR, 1792-1801","author":"Greydanus Samuel","year":"2018","unstructured":"Samuel Greydanus, Anurag Koul, Jonathan Dodge, and Alan Fern. 2018. Visualizing and understanding atari agents. In International Conference on Machine Learning. PMLR, 1792-1801."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22038-9_16"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/icse.2019.00027"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-25566-3_40"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519575"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/tevc.2013.2281534"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133924"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3440119"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/ase51524.2021.9678761"},{"key":"e_1_2_1_54_1","first-page":"2513","volume-title":"PolyCruise: A Cross-Language Dynamic Information Flow Analysis. In 31st USENIX Security Symposium (USENIX Security 22)","author":"Li Wen","year":"2022","unstructured":"Wen Li, Ming Jiang, Xiapu Luo, and Haipeng Cai. 2022. PolyCruise: A Cross-Language Dynamic Information Flow Analysis. In 31st USENIX Security Symposium (USENIX Security 22). 2513-2530."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/icst46399.2020.00014"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3276511"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236041"},{"key":"e_1_2_1_58_1","unstructured":"LinkedIn \/ Microsoft. 2022. voldemort\/voldemort. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/voldemort\/voldemort."},{"key":"e_1_2_1_59_1","unstructured":"MITRE\/NVD. 2022. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor . https:\/\/2.zoppoz.workers.dev:443\/https\/cwe.mitre.org\/ data\/definitions\/200.html."},{"key":"e_1_2_1_60_1","first-page":"12360","article-title":"Towards interpretable reinforcement learning using attention augmented agents","volume":"32","author":"Mott Alexander","year":"2019","unstructured":"Alexander Mott, Daniel Zoran, Mike Chrzanowski, Daan Wierstra, and Danilo Jimenez Rezende. 2019. Towards interpretable reinforcement learning using attention augmented agents. Advances in Neural Information Processing Systems 32 (2019), 12360-12369.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2009.18"},{"key":"e_1_2_1_62_1","volume-title":"Network and Distributed System Security Symposium (NDSS). 1-17","author":"Newsome James","year":"2005","unstructured":"James Newsome and Dawn Xiaodong Song. 2005. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In Network and Distributed System Security Symposium (NDSS). 1-17."},{"key":"e_1_2_1_63_1","volume-title":"SAT competition 2004","author":"Nudelman Eugene","year":"2004","unstructured":"Eugene Nudelman, Kevin Leyton-Brown, Alex Devkar, Yoav Shoham, and Holger Hoos. 2004. SATzilla: An algorithm portfolio for SAT. Solver description, SAT competition 2004 (2004), 1-2."},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/2858965.2814309"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/2335484.2335511"},{"key":"e_1_2_1_67_1","volume-title":"Netty: Home. https:\/\/2.zoppoz.workers.dev:443\/https\/netty.io\/index.html.","author":"Netty","year":"2020","unstructured":"Netty project. 2020. Netty: Home. https:\/\/2.zoppoz.workers.dev:443\/https\/netty.io\/index.html."},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17502-3_19"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/icse.2009.5070508"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2017.2704579"},{"key":"e_1_2_1_71_1","unstructured":"SourceForge. 2015. NioEcho. https:\/\/2.zoppoz.workers.dev:443\/http\/rox-xmlrpc.sourceforge.net\/niotut\/index.html#Thecode."},{"key":"e_1_2_1_72_1","unstructured":"SourceForge. 2018. xSocket. https:\/\/2.zoppoz.workers.dev:443\/https\/sourceforge.net\/projects\/xsocket\/."},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/2554850.2554955"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2597073.2597080"},{"key":"e_1_2_1_75_1","unstructured":"Bamberg University. 2015. Open Chord. https:\/\/2.zoppoz.workers.dev:443\/http\/sourceforge.net\/projects\/open-chord\/."},{"key":"e_1_2_1_76_1","volume-title":"Ye","author":"Walpole Ronald E.","year":"2011","unstructured":"Ronald E. Walpole, Raymond H. Myers, Sharon L. Myers, and Keying E. Ye. 2011. Probability and Statistics for Engineers and Scientists. Prentice Hall."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/1831708.1831740"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2015.712"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof"},{"key":"e_1_2_1_80_1","first-page":"57","volume-title":"Proceedings of SAT Challenge","author":"Xu Lin","year":"2012","unstructured":"Lin Xu, Frank Hutter, Jonathan Shen, Holger H Hoos, and Kevin Leyton-Brown. 2012. SATzilla2012: Improved algorithm selection based on cost-sensitive classification models. Proceedings of SAT Challenge (2012), 57-58."},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134285.1134324"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3808167","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3808167","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:26:11Z","timestamp":1782843971000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3808167"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":81,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808167"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3808167","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}