Page 55 - 《软件学报》2026年第7期
P. 55
2740 软件学报 2026 年第 37 卷第 7 期
(3) 提升可扩展性, 与编译工具链集成. 现有工具在分析大型 Python-C/C++软件包时存在显著的可扩展性问
题, 部分工具依赖动态输入、特定项目结构或繁杂的源汇点配置, 难以适应真实工程环境. 基于 GCC、LLVM/Clang
等编译工具链的技术表现出较好的可扩展性, 是比较可取的设计方向.
References
[1] Alfadel M, Costa DE, Shihab E. Empirical analysis of security vulnerabilities in Python packages. Empirical Software Engineering, 2023,
28(3): 59. [doi: 10.1007/s10664-022-10278-4]
[2] Guo WB, Xu ZZ, Liu CW, Huang C, Fang Y, Liu Y. An empirical study of malicious code in PyPI ecosystem. In: Proc. of the 38th Int’l
Conf. on Automated Software Engineering. Luxembourg: IEEE, 2023. 166–177. [doi: 10.1109/ASE56229.2023.00135]
[3] Samaana H, Costa DE, Shihab E, Abdellatif A. A machine learning-based approach for detecting malicious PyPI packages. In: Proc. of
the 40th ACM/SIGAPP Symp. on Applied Computing. Catania: ACM, 2025. 1617–1626. [doi: 10.1145/3672608.3707756]
[4] Sun XB, Gao XG, Cao SC, Bo LL, Wu XX, Huang KF. 1+1>2: Integrating deep code behaviors with metadata features for malicious
PyPI package detection. In: Proc. of the 39th IEEE/ACM Int’l Conf. on Automated Software Engineering. Sacramento: ACM, 2024.
1159–1170. [doi: 10.1145/3691620.3695493]
[5] Vu DL, Pashchenko I, Massacci F, Plate H, Sabetta A. Typosquatting and combosquatting attacks on the Python ecosystem. In: Proc. of
the 2020 European Symp. on Security and Privacy Workshops. Genoa: IEEE, 2020. 509–514. [doi: 10.1109/EuroSPW51379.2020.00074]
[6] Grichi M, Abidi M, Jaafar F, Eghan EE, Adams B. On the impact of interlanguage dependencies in multilanguage systems empirical case
study on Java Native Interface applications (JNI). IEEE Trans. on Reliability, 2021, 70(1): 428–440. [doi: 10.1109/TR.2020.3024873]
[7] Li W, Li L, Cai HP. On the vulnerability proneness of multilingual code. In: Proc. of the 30th ACM Joint European Software Engineering
Conf. and Symp. on the Foundations of Software Engineering. Singapore: ACM, 2022. 847–859. [doi: 10.1145/3540250.3549173]
[8] Tan G, Croft J. An empirical security study of the native code in the JDK. In: Proc. of the 17th USENIX Security Symp. San Jose:
USENIX Association, 2008. 365–378.
[9] Hu MZ, Zhang Y. An empirical study of the Python/C API on evolution and bug patterns. Journal of Software: Evolution and Process,
2023, 35(2): e2507. [doi: 10.1002/smr.2507]
[10] Hu MZ, Zhang Y. The Python/C API: Evolution, usage statistics, and bug patterns. In: Proc. of the 27th Int’l Conf. on Software Analysis,
Evolution and Reengineering. London: IEEE, 2020. 532–536. [doi: 10.1109/SANER48275.2020.9054835]
[11] Li SL, Tan G. Finding reference-counting errors in Python/C programs with affine analysis. In: Proc. of the 28th European Conf. on
Object-oriented Programming. Uppsala: Springer, 2014. 80–104. [doi: 10.1007/978-3-662-44202-9_4]
[12] Mao JJ, Chen Y, Xiao QX, Shi YC. RID: Finding reference count bugs with inconsistent path pair checking. In: Proc. of the 21st Int’l
Conf. on Architectural Support for Programming Languages and Operating Systems. Atlanta: ACM, 2016. 531–544. [doi: 10.1145/
2872362.2872389]
[13] Ma XT, Yan JW, Zhang H, Yan J, Zhang J. Detecting memory errors in Python native code by tracking object lifecycle with reference
count. In: Proc. of the 38th Int’l Conf. on Automated Software Engineering. Luxembourg: IEEE, 2023. 1429–1440. [doi: 10.1109/
ASE56229.2023.00198]
[14] Li W, Ming J, Luo XP, Cai HP. PolyCruise: A cross-language dynamic information flow analysis. In: Proc. of the 31st USENIX Security
Symp. Boston: USENIX Association, 2022. 2513–2530.
[15] Li W, Ruan JY, Yi GB, Cheng L, Luo XP, Cai HP. PolyFuzz: Holistic greybox fuzzing of multi-language systems. In: Proc. of the 32nd
USENIX Security Symp. Anaheim: USENIX Association, 2023. 1379–1396.
[16] Monat R, Ouadjaout A, Miné A. A multilanguage static analysis of Python programs with native C extensions. In: Proc. of the 28th Int’l
Symp. on Static Analysis. Chicago: Springer, 2021. 323–345. [doi: 10.1007/978-3-030-88806-0_16]
[17] Hu MZ, Zhang Y, Huang WC, Xiong Y. Static type inference for foreign functions of Python. In: Proc. of the 32nd Int’l Symp. on
Software Reliability Engineering. Wuhan: IEEE, 2021. 423–433. [doi: 10.1109/ISSRE52982.2021.00051]
[18] Hu MZ, Yu L, Zhang Y, Han LP. A survey of multilanguage interoperability and its program analysis. IEEE Trans. on Reliability, 2025,
74(4): 4944–4958. [doi: 10.1109/TR.2025.3576267]
[19] Simons AJH. Borrow, copy or steal? Loans and larceny in the orthodox canonical form. In: Proc. of the 13th ACM SIGPLAN Int’l Conf.
on Object-oriented Programming Systems, Languages, and Applications. Vancouver: ACM, 1998. 65–83. [doi: 10.1145/286936.286948]
[20] Kirchner F, Kosmatov N, Prevosto V, Signoles J, Yakobowski B. Frama-C: A software analysis perspective. Formal Aspects of
Computing, 2015, 27(3): 573–609. [doi: 10.1007/s00165-014-0326-7]
[21] Zhang J, Zhang C, Xuan JF, Xiong YF, Wang QX, Liang B, Li L, Dou WS, Chen ZB, Chen LQ, Cai Y. Recent progress in program

