“Wait, My Tool Can’t Do That?” A Fine-Grained Capability Study of Modern Static Taint Analyzers
Static taint analyzers are widely used in software security, yet aggregate vulnerability-detection metrics provide limited insight into the specific language constructs and analysis capabilities that cause tools to succeed or fail. This paper presents xAST , a fine-grained benchmark containing 844 paired capability cases, implemented as 1,825 individual source files across Python, Go, Java, and JavaScript. The benchmark covers 16 capability dimensions and 76 sub-categories, including context, flow, path, field, and element precision, as well as functions, modules, concurrency, expressions, and dynamic features. Each pair contains a positive instance in which an expected source-to-sink flow should be detected and a structurally related negative instance in which the corresponding alarm should be suppressed. We evaluate eight mainstream static taint analyzers under 14 tool-language configurations. The highest pair pass rate is 61.7%, achieved by CodeQL on JavaScript. Across all 2,881 tool-language pair evaluations, 47.5% pass both instances, 36.1% are false-negative-only failures, 14.3% are false-positive-only failures, and 2.1% fail both instances. The aggregate T-instance detection rate is 61.9%, while the aggregate F-instance suppression rate is 83.6%, showing that missed expected flows are the dominant global failure mode, although individual tools exhibit substantially different detection and suppression profiles. Fine-grained analysis further identifies recurring weaknesses in field and element precision, path-feasibility reasoning, transfer-rule coverage, concurrency and asynchronous modeling, advanced language idioms, alias analysis, and module resolution. These results provide a capability-oriented diagnostic complement to application-level and vulnerability-level benchmarks and offer actionable guidance for tool developers, researchers, and practitioners.
Authors
- Yanjie Zhao (ORCID: https://orcid.org/0000-0001-8793-5367)
- Shenao Wang (ORCID: https://orcid.org/0000-0003-3818-3343)
- Jian Zhao (ORCID: https://orcid.org/0009-0003-5716-1462)
- Kan Yu (ORCID: https://orcid.org/0009-0001-2554-7681)
- Haoyu Wang (ORCID: https://orcid.org/0000-0003-1100-8633)
- Lizhong Bian (ORCID: https://orcid.org/0009-0006-0563-0409)
- Yayi Wang (ORCID: https://orcid.org/0009-0000-8880-1061)
- Yan Cheng (ORCID: https://orcid.org/0009-0006-1025-5965)
- Junjie He (ORCID: https://orcid.org/0009-0008-2160-7270)
Institutions
- Ant Group (China) (CN)
- Huazhong University of Science and Technology (CN)
Publication Details
- Journal
- ACM Transactions on Software Engineering and Methodology
- Published
- 2026-10-03
- DOI
- https://doi.org/10.1145/3849705
- Primary Topic
- Security and Verification in Computing
- Type
- article
- Field-Weighted Citation Impact
- 0.00