Sign in

Rohan Padhye

@rohan.padhye.org
525 followers 108 following 35 posts

Computer Science professor at CMU. Doing research on automated software testing and bug finding. rohan.padhye.org

PostsRepliesMedia
Rohan Padhye @rohan.padhye.org · 09/03/2026
Wow, haven't come across this one before (and trust me, I've looked extensively -- rohan.padhye.org/files/dateti...). I'm trying to reverse engineer the implementation here, but it boggles the mind. Just storing opening hours as text?
120
Rohan Padhye @rohan.padhye.org · 17/02/2026
My students wrote a blog post explaining the problem with some neat examples. pastalab.org/spaghetti-be...
020
Rohan Padhye @rohan.padhye.org · 17/02/2026
Ever used AI to fix tricky race conditions and flaky tests? Not pretty, is it? Check out "Spaghetti Bench 🍝: A SWE-Agent Benchmark for Concurrency Bug Tasks" Turns out it's still a HARD problem, but it can be made tractable with deterministic replay. pastalab.org/spaghetti-be...
141
Rohan Padhye @rohan.padhye.org · 03/12/2025
SPLASH and ISSTA are going to be co-located in 2026 at Oakland, CA! 🥳 If you would like to run a workshop in PL/SE/Testing, submit a proposal by Jan 10th: conf.researchr.org/track/splash... Contact @sholtzen.bsky.social or me for questions.
conf.researchr.org
SPLASH/ISSTA 2026 - Workshops - SPLASH/ISSTA 2026
Welcome to the website of the SPLASH/ISSTA 2026 conference. We are working hard to fill the website with all related information. Please check back soon! In the meantime, please consider this overview...
051
Reposted by Rohan Padhye
Marcel Böhme @mboehme.bsky.social · 03/12/2025
⏱️ 9 days until submission deadline (Dec 11, 23:59 AoE). Organized by: @yannicnoller.bsky.social, @rohan.padhye.org, @ruijiemeng.bsky.social, and Laszlo (@lszekeres.bsky.social) Szekeres.
035
Reposted by Rohan Padhye
Antithesis @antithesis.com · 26/11/2025
Youtube: youtu.be/oF7krd0TQks Spotify: open.spotify.com/episode/2PH7... Apple Podcasts: podcasts.apple.com/us/podcast/f...
youtu.be
From the Lab to Production: Making Cutting-Edge Testing Practical
YouTube video by Antithesis
022
Rohan Padhye @rohan.padhye.org · 26/11/2025
Check out the latest episode of the #BugBash podcast! I had a great time chatting with David Wynn about automated testing in academia vs industry. Thanks @antithesis.com for having me on!
051
Rohan Padhye @rohan.padhye.org · 16/11/2025
(of course I don't know what all the Korean words mean but hoping it's useful to find place names and food items)
030
Rohan Padhye @rohan.padhye.org · 16/11/2025
Update: Mostly a success. On arrival I was able to read basic signs during my ride from 인천공항 to 서울. Super elegant and easy to learn script! Quite compositional much like Devanagari (Sanskrit/Hindi/Marathi) which I'm already familiar with. - 로힌
130
Rohan Padhye @rohan.padhye.org · 15/11/2025
Excited to be on my way to ASE in Seoul! Aiming to learn some Hangul on the flight. @aseconf.bsky.social
Screenshot of a Korean writing app with introductory lessons for Hangul
261
Reposted by Rohan Padhye
Marcel Böhme @mboehme.bsky.social · 03/11/2025
Gaetano's paper on Scaling Security Testing by Adressing the Reachability Gap has been accepted at #ICSE26! 📝 gpsapia.github.io/files/ICSE_2... 🧑‍💻 github.com/GPSapia/Reac... How to scale automatic security testing to arbitrary systems?
1175
Reposted by Rohan Padhye
Yannic Noller @yannicnoller.bsky.social · 08/10/2025
#FUZZING'26 CALL FOR PAPERS ────── ✨ After 5 years, we will be again co-located with NDSS! 🔗 fuzzing-workshop.github.io 📅 11. Dec (Submission) //cc @mboehme.bsky.social (MPI-SP), @ruijiemeng.bsky.social (CISPA), @rohan.padhye.org (CMU), László Szekeres (Google)
0104
Rohan Padhye @rohan.padhye.org · 06/10/2025
Podcast! Had a fun conversation with @cachemisses.bsky.social on an episode of *Disseminate*. Check it out!
030
Rohan Padhye @rohan.padhye.org · 28/08/2025
Excited to announce that the Fray paper has been accepted to OOPSLA'25! Work led by @aoli.al with a full pastalab.org collaboration. 📄: rohan.padhye.org/files/fray-o... 💻: github.com/cmu-pasta/fray 🎥: www.youtube.com/watch?v=AX6P...
Front page of a paper titled "Fray: An Efficient General-Purpose Concurrency Testing Platform for the JVM" by Ao Li et al. from Carnegie Mellon University.
3154
Rohan Padhye @rohan.padhye.org · 22/08/2025
Debating whether we can add acks "We thank Reviewers A and C for their constructive feedback on our paper".
150
Rohan Padhye @rohan.padhye.org · 14/07/2025
My current conjecture is that the examples of broken JSON syntax in the paper somehow accidentally caused something like second-order prompt injection in Google Scholar's indexing pipeline. But there's only one way to find out ^^^
110
Rohan Padhye @rohan.padhye.org · 14/07/2025
Hilarious! It looks like Google Scholar is pulling citations for a different Kirschner et al. paper from 2006. I wonder if one could use the technique proposed in "Debugging inputs" to identify what causes this anomaly. Gonna need Lukas to publish a *lot* of papers.
110
Reposted by Rohan Padhye
Yannic Noller @yannicnoller.bsky.social · 29/06/2025
🚨 Our amazing #FUZZING'25 keynotes are online! "Constraining Fuzzing without Paying Too Much" by Miryung Kim youtu.be/L90MBb6NLBE "Are you sure you belong in academia?" by Will Wilson youtu.be/qQGuQ_4V6WI // @mboehme.bsky.social, László Szekeres, @rohan.padhye.org, @ruijiemeng.bsky.social
1116
Rohan Padhye @rohan.padhye.org · 17/06/2025
The limit applies to references too? Preposterous!
110
Rohan Padhye @rohan.padhye.org · 09/06/2025
Very cool: ‪@aoli.al‬ uncovered a deadlock in OpenJDK that can be triggered with a tiny test case and Fray's deterministic concurrency testing & debugging support. Read his blog post here: aoli.al/blogs/jdk-bug/ If you write Java/Scala/Kotlin, try Fray yourself: github.com/cmu-pasta/fray
aoli.al
Discovering a JDK Race Condition, and Debugging it in 30 Minutes with Fray
Discovering a JDK Race Condition, and Debugging it in 30 Minutes with Fray I’ve been adding more integration tests for Fray recently. To ensure Fray can handle different scenarios, I wrote many creati...
030
Rohan Padhye @rohan.padhye.org · 06/06/2025
Just Accepted to ACM TOSEM! The "Havoc Paradox" is about the relationship between byte-level fuzzer mutations and their effect on the inputs produced by generators for structured strings (e.g. XML/SQL). Can disruptive mutations be controlled? Should they be? Find out. 📄 dl.acm.org/doi/pdf/10.1...
2203
Reposted by Rohan Padhye
Marcel Böhme @mboehme.bsky.social · 28/05/2025
🖊️ Register here: ntnu.eventsair.com/fse2025-isst... (FUZZING is a co-located workshop)
ntnu.eventsair.com
Welcome to FSE 2025 + ISSTA 2025
053
Rohan Padhye @rohan.padhye.org · 27/05/2025
We also have an excellent program of research talks and *fuzzing nuggets*. Detailed schedule coming soon. conf.researchr.org/home/issta-2...
List of Accepted Papers at the FUZZING Workshop
033
Rohan Padhye @rohan.padhye.org · 27/05/2025
We're excited to announce two keynote speakers for the #FUZZING'25 workshop (part of @issta_conf at Trondheim, Norway): [*] Will Wilson, CEO and Co-Founder of Antithesis [*] Miryung Kim, Professor and Vice Chair of Graduate Studies at UCLA conf.researchr.org/home/issta-2...
183
Rohan Padhye @rohan.padhye.org · 27/05/2025
The JQF repo is now both popular enough (700+ stars) and contains enough buggy/vulnerable code as sample fuzz targets that we're getting occasionally spammed with crappy AI-generated patches. I can't imagine what bigger OSS projects are dealing with right now.
010
Rohan Padhye @rohan.padhye.org · 05/05/2025
Congratulations!
010
Rohan Padhye @rohan.padhye.org · 29/04/2025
Delighted to receive an ACM SIGSOFT Distinguished Award for this work... It's about time! Proud of the PASTA Lab students, including our visiting undergrads :-)
0110
Rohan Padhye @rohan.padhye.org · 31/03/2025
Love this argument: prior work does not use our novel idea.
Text highlighted from a research paper that says "To the best of our knowledge, there is no existing search-based testing approach for productiongrade AV software, including [20], [21], [41]–[55] that: (i) uses our novel gene representation"
060
Rohan Padhye @rohan.padhye.org · 20/03/2025
Submission deadline for the Fuzzing workshop is tonight (AoE)! Send us those nuggets and research ideas. Rohan
030
Rohan Padhye @rohan.padhye.org · 10/03/2025
Happy Daylight Savings Time to everyone in the US! A few more weeks for European Summer Time. If you notice some of your apps glitching, don't be alarmed. Even ChatGPT can't write correct date/time code!!! See more in our upcoming paper: rohan.padhye.org/files/dateti... (MSR'25 preprint)
Paper titled "It’s About Time: An Empirical Study of Date and
Time Bugs in Open-Source Python Software".  Authors List:

Shrey Tiwari
Carnegie Mellon University
Pittsburgh, PA, USA
shrey@cmu.edu
Peter Vandervelde∗
University of California, Santa Barbara
Santa Barbara, CA, USA
pvandervelde@ucsb.edu
Serena Chen∗
University of California, San Diego
San Diego, CA, USA
sec022@ucsd.edu
Ao Li
Carnegie Mellon University
Pittsburgh, PA, USA
aoli@cmu.edu
Alexander Joukov∗
Stony Brook University
Stony Brook, NY, USA
ajoukov@cs.stonybrook.edu
Rohan Padhye
Carnegie Mellon University
Pittsburgh, PA, USA
rohanpadhye@cmu.edu
050
Rohan Padhye @rohan.padhye.org · 23/02/2025
It's always been a "response" for me. The only time it was a "rebuttal" was when I explicitly thanked Reviewers A, C, and D for their valuable feedback.
180
Rohan Padhye @rohan.padhye.org · 17/02/2025
I'm super excited about this new track at the #FUZZING'25 workshop. It's the academic version of thoughtful blog posts, but with a paper and talk for wider reach! Submission deadline is in a month (March 20th)! fuzzingworkshop.github.io
183
Reposted by Rohan Padhye
Marcel Böhme @mboehme.bsky.social · 17/02/2025
#FUZZING'25 CALL FOR PAPERS ────── ✨ New OC members: * Ruijie Meng (@ruijiemeng.bsky.social; NUS) * Rohan Padhye (@rohan.padhye.org; CMU). ✨ New paper type: Fuzzing Nuggets (short papers). 🔗 fuzzingworkshop.github.io 📅 20.March (Submission) 📅 17.April (Notification) 📅 28.June (Workshop)
11711
Rohan Padhye @rohan.padhye.org · 07/02/2025
Back to basics: Concurrency testing in Java! Our new tool *Fray* correctly solves a 25+ year old problem for real-world software. See this feature from Elastic Labs about Fray's contributions to Lucene. 📰: www.elastic.co/search-labs/... 🔧: github.com/cmu-pasta/fray 📝: arxiv.org/pdf/2501.12618
Blog post titled "Concurrency bugs in Lucene: How to fix optimistic concurrency failures" By Benjamin Trent and Ao Li (February 7, 2025)

Text reads: "Thanks to Fray, a deterministic concurrency testing framework from CMU’s PASTA Lab, we tracked down a tricky Lucene bug and squashed it"
2204
Rohan Padhye @rohan.padhye.org · 19/12/2024
Cite only the paper title for now, and submit a PDF without embedded fonts. They'll probably tell you to fix it and re-submit in 48 hours. Plenty of time to get an arxiv identifier :-)
1100
Rohan Padhye @rohan.padhye.org · 13/12/2024
Takeaway: Don't just fuzz and wait for bugs to show up. Measure what your inputs look like based on user-defined predicates, and things start making a lot more sense.
121
Rohan Padhye @rohan.padhye.org · 13/12/2024
[3/3] Another similarly cool idea is "events" in Tyche (by @harrisongoldste.in et al.), which is a PBT visualization extension for VSCode. We've actually integrated Tyche into JQF now so it works with Java fuzzing! Check it out. (Ref: github.com/tyche-pbt/ty..., github.com/rohanpadhye/...)
A screenshot with two columns. On the left, a Python property-based test annotated with `event(<predicate>)` statements. On the right, a visualization of how frequently event predicates have been excercised by random tests, plotted as histograms and tree-maps.
120
Rohan Padhye @rohan.padhye.org · 13/12/2024
[2/3] I like the "Sometimes Assertions" abstraction recommended by Antithesis, which generalizes code coverage to user-defined predicates, possibly interleaved with application logic. Maybe we should support these in JQF too. (Ref: antithesis.com/docs/best_pr...)
You may be less familiar with the second type of assertion, which at Antithesis we call Sometimes Assertions. Just as an always assertion asserts that something is always true, a Sometimes Assertion asserts that something is sometimes true! Here are some examples:
```
assertSometimes x < 1;
assertSometimes y == 1;
assertSometimes(condition);
```
120
Rohan Padhye @rohan.padhye.org · 13/12/2024
How do you know whether random testing is working as expected? [1/3] Long ago in JQF, we used `assumeTrue` to bias fuzzing towards *valid* inputs. This is powerful, but the abstraction is quite coarse if you have many properties. (Refs: github.com/rohanpadhye/..., rohan.padhye.org/files/zest-i...)
```
@Fuzz
    public void testMap2Trie(Map<String, Integer> map, String key) {
        assumeTrue(map.containsKey(key));
        // Create new trie with input `map`
        Trie trie = new PatriciaTrie(map);
        // The key should exist in the trie as well
        assertTrue(trie.containsKey(key));
    }
```
160
Reposted by Rohan Padhye
Dr. Claire Le Goues @clegoues.bsky.social · 26/11/2024
And now that we’re all here, some work!🚨 Are Large Language Models Memorizing Bug Benchmarks? 🚨 There’s growing concern that LLMs for SE are prone to data leakage, but no one has quantified it... until now. 🕵️‍♂️ 1/
arxiv.org
26411
Rohan Padhye @rohan.padhye.org · 25/11/2024
It was expected to happen once this year, because there are 366 days.
140
Rohan Padhye @rohan.padhye.org · 20/11/2024
Now to find everyone else again.
100
Rohan Padhye @rohan.padhye.org · 20/11/2024
Alright, I'm here!
241