[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82527-en":3,"doc-seo-82527-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},82527,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","Rise From The Ashes LLM-based Static Analysis for Deep Learning Framework Bugs","Deep learning (DL) frameworks are core AI infrastructure yet often conceal bugs that carry serious security risks. Dynamic testing such as fuzzing can expose faults but requires executing real programs and incurs heavy computational cost. Static analysis offers faster, scalable bug detection without runtime execution, but remains limited due to multilingual architectures and tensor-centric program state. PHOENIX introduces the first LLM-based static analysis for DL frameworks, modeling cross-language tensor flows via SBIR.","Rise From The Ashes: LLM-based Static Analysis for Deep Learning Framework Bugs  \narXiv :2607 .00555v 1 [ cs . SE] 1 Jul 2026  \nShaoyu Yang∗ , Haifeng Lin∗ , Chunrong Fang∗\\#, Xiang Chen†, Wei Cheng‡, Jiawei Liu∗ , Yiyu Zhang∗ , Hongyu Liu§ , Zhenyu Chen∗  \n∗ State Key Laboratory for Novel Software Technology, Nanjing University, China †School of Artificial Intelligence and Computer Science, Nantong University, China ‡College of Computer Science and Technology/College of Software, Nanjing University of Aeronautics and Astronautics, China  \n§ Beijing Academy of Artificial Intelligence, China  \n[shaoyuyang@gmail.com](shaoyuyang@gmail.com), [linhaifeng0716@163.com](linhaifeng0716@163.com), [fangchunrong@nju.edu.cn](fangchunrong@nju.edu.cn),  \n[xchencs@ntu.edu.cn](xchencs@ntu.edu.cn), [chengweii@nuaa.edu.cn](chengweii@nuaa.edu.cn), [jwliu@nju.edu.cn](jwliu@nju.edu.cn),  \n[zhangyy0721@smail.nju.edu.cn](zhangyy0721@smail.nju.edu.cn), [hyliu@baai.ac.cn](hyliu@baai.ac.cn), [zychen@nju.edu.cn](zychen@nju.edu.cn)  \n\\# Corresponding author  \nAbstract—Deep learning (DL) frameworks are critical AI infrastructures that often hide bugs with serious security implications. While dynamic approaches such as fuzzing are effective in uncovering these bugs, they require real test execution and incur high computational costs. Static analysis is a natural complement because it can detect bugs without runtime execution, offering fast and scalable testing. Unfortunately, there is still limited work targeting static analysis for DL frameworks due to their multilingual architectures and tensor-related program state.  \nWe present PHOENIX, the first LLM-based static analysis technique for DL frameworks. Our key insight is that crosslanguage tensor flows in DL frameworks can be modeled, together with concrete code context, as a structured semantic bridge intermediate representation (SBIR) that LLMs can analyze for potential bugs in tensor semantic propagation. We implement this insight through a multi-agent workflow. A summarization agent first distills bug summaries from historical bug-fix patches and CWE rules. Guided by each summary, an extraction agent identifies bug-relevant repository symbols for code retrieval, and a generation agent synthesizes grounded SBIRs from the retrieved context. Finally, an analysis agent is leveraged to check SBIRs and report potential bugs. Our evaluation shows that PHOENIX is a practical complement to dynamic DL framework testing for bug finding. To date, PHOENIX has found 31 real new bugs in PyTorch for different heterogeneous hardware backends (Intel CPU, NVIDIA CUDA, and Apple MPS). Among them, 20 submitted bug-fixing patches have been merged into upstream.  \nIndex Terms—Deep learning frameworks, static analysis, large language models  \nI. INTRODUCTION  \nDeep learning (DL) frameworks, such as PyTorch [33], JAX [4], and TVM [6], are now critical infrastructure for building, optimizing, and deploying DL and large language model (LLM) applications [19],[51] . Their correctness affects downstream systems in safety-sensitive domains, including autonomous driving [40], biometric recognition [38], and financial services [29] . A framework bug can therefore propagate beyond an ordinary library failure because an inconsistent tensor contract, an unsafe backend assumption, or a missing  \nruntime check may silently corrupt numerical results, crash production systems, or expose memory-safety risks [12], [5] .  \nDynamic testing is a standard software testing paradigm for finding faults through program execution [1], [18] . In DL frameworks, fuzz testing (fuzzing) techniques [31], [45],[15], [27], [24], [25] generate or mutate DL programs, execute them against a framework or compiler, and report bugs through crash, differential, numerical, or metamorphic oracles [24],[47] . Recent fuzzers using LLMs further improve test generation by using LLM knowledge about API syntax and tensor constraints [10], [47] . Despite these advances, dyn","cbCaikGO7cbzxin8","https://ap.wps.com/l/cbCaikGO7cbzxin8","pdf",4733580,1,12,"English","en",105,"# Abstract\n# Introduction\n## Motivation and Challenges\n## Static Analysis as a Complement\n## Key Technical Challenge","[{\"question\":\"Why is static analysis useful for finding bugs in deep learning frameworks?\",\"answer\":\"Static analysis inspects implementation logic without requiring concrete failure-triggering inputs, enabling fast and scalable testing compared with runtime-dependent approaches like fuzzing.\"},{\"question\":\"What is the core idea behind PHOENIX for static bug detection?\",\"answer\":\"PHOENIX models cross-language tensor flows together with concrete code context as a structured semantic bridge intermediate representation (SBIR), which LLMs analyze to predict tensor semantic propagation bugs.\"},{\"question\":\"How does PHOENIX’s multi-agent workflow operate?\",\"answer\":\"A summarization agent distills bug summaries from historical patches and CWE rules, an extraction agent retrieves bug-relevant repository symbols, and a generation agent builds grounded SBIRs; an analysis agent then checks SBIRs and reports potential bugs.\"}]",1784181258,30,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"rise-from-the-ashes-llm-based-static-analysis-for-deep-learning-framework-bugs","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/rise-from-the-ashes-llm-based-static-analysis-for-deep-learning-framework-bugs/82527/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is static analysis useful for finding bugs in deep learning frameworks?","Question",{"text":75,"@type":76},"Static analysis inspects implementation logic without requiring concrete failure-triggering inputs, enabling fast and scalable testing compared with runtime-dependent approaches like fuzzing.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the core idea behind PHOENIX for static bug detection?",{"text":80,"@type":76},"PHOENIX models cross-language tensor flows together with concrete code context as a structured semantic bridge intermediate representation (SBIR), which LLMs analyze to predict tensor semantic propagation bugs.",{"name":82,"@type":73,"acceptedAnswer":83},"How does PHOENIX’s multi-agent workflow operate?",{"text":84,"@type":76},"A summarization agent distills bug summaries from historical patches and CWE rules, an extraction agent retrieves bug-relevant repository symbols, and a generation agent builds grounded SBIRs; an analysis agent then checks SBIRs and reports potential bugs.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":28,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]