Logo image
I Can SE Clearly Now: Investigating the Effectiveness of GUI-based Symbolic Execution for Software Vulnerability Discovery
Conference proceeding   Open access

I Can SE Clearly Now: Investigating the Effectiveness of GUI-based Symbolic Execution for Software Vulnerability Discovery

Yi Jou Li, Zeming Yu, James A Mattei, Ananta Soneji, Zhibo Sun, Ruoyu Wang, Jaron Mink, Daniel Votipka and Tiffany Bao
Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, pp 1-17
13 Apr 2026
Featured in Collection :   Drexel's Newest Publications
url
https://doi.org/10.1145/3772318.3790906View
Published, Version of Record (VoR) Open

Abstract

Human-centered computing -- User studies Security and privacy -- Software and application security
While symbolic execution (SE) can discover software vulnerabilities, it has received limited practical adoption. A key barrier is that SE requires human expertise to understand the program’s state and prioritize paths to analyze. Traditionally, users controlled SE through programmatic API calls, but recent tooling now implements graphical user interfaces (GUI). However, it is unclear how these new features affect human-SE performance. To understand this impact, we conducted a controlled experiment where 24 vulnerability discovery experts were tasked with analyzing a binary using an SE tool with either API or GUI-based features. From this study, we identify (1) experts’ SE process, and (2) the impact of GUI-based features on human-SE performance. Then we propose recommendations to improve SE tool design.

Metrics

1 Record Views

Details

Logo image