Skip to content
Book

Understanding the Performance-Effectiveness Trade-Offs of AddressSanitizer in Real-World Programs: An Empirical Study

Oct 2026 · Proceedings of the 41st IEEE/ACM International Conference on Automated Software Engineering · 0 citations · 50 references

Abstract

AddressSanitizer (ASan) is widely deployed in industrial C/C++ development, but its runtime and memory costs can limit routine use in continuous integration and production-like testing. Although many optimized ASan-like sanitizers have been proposed, heterogeneous workloads, configurations, and baselines make their practical trade-offs difficult to compare. We present a unified, deployment-oriented empirical study of ASan and seven representative optimized sanitizers: ASan--, SanRazor, GiantSan, RSan, MEDs, ASAP, and LFP. Using 17 SPEC CPU2006 benchmarks, Juliet, MSET, 21 real-world CVEs, and a multi-threaded MySQL case study, we examine component costs, parameter sensitivity, build configurations, detection outcomes, and deployability. In our ordered cumulative ablation, the largest first-step runtime reduction follows removal of memory-access checks, while the largest late-stage RSS reduction occurs at the heap-management step. Parameter tuning identifies lower-memory configurations without additional false negatives relative to default ASan on Juliet, although this result does not establish preservation of delayed-UAF detection. The reported evidence shows distinct efficiency, detection, and deployment outcomes, but unequal completion sets prevent a formal cross-tool ranking. Our results support treating tuned ASan as a necessary, configuration-dependent comparison baseline for sanitizer evaluation and provide bounded evidence for deployment decisions under different resource and risk constraints.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.