---
格式版本: 2
标题: "Validating HTTP Semantics in REST APIs With Constructed Call Sequence Scenarios"
原文链接: "https://arxiv.org/abs/2608.16239"
发布日期: "2026-08-17"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Mon, 17 Aug 2026 08:16:31 UTC (32 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T14:46:16+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T14:38:42+08:00"
入库时间: "2026-08-20T06:46:16.517Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=Oracle&searchtype=all"
匹配关键词:
  []
相关厂家:
  - "Oracle"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 5
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为REST API HTTP语义测试，与超节点/AI Rack/机柜级AI基础设施完全无关，未涉及任何相关技术、厂商或落地信息。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T14:49:25+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "该研究扩展了EvoMaster模糊测试器，新增9个测试预言以自动检测REST API中的HTTP语义级故障。实验在9个人工注入故障的API上全部检出，并在36个真实世界API中发现166个现有故障。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:24:56.198Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.16239"
---

## Computer Science > Software Engineering

## Title:Validating HTTP Semantics in REST APIs With Constructed Call Sequence Scenarios

Authors:[Omur Sahin](https://arxiv.org/search/cs?searchtype=author&query=Sahin,+O), [Andrea Arcuri](https://arxiv.org/search/cs?searchtype=author&query=Arcuri,+A)

[View PDF](https://arxiv.org/pdf/2608.16239) [HTML (experimental)](https://arxiv.org/html/2608.16239v1)

> Abstract:Context: REST APIs are widely used in industry. These APIs use HTTP for their communications. Failures in following the specifications of HTTP can lead to confusing and hard to use APIs, with possibly serious software faults with dire consequences. Objectives: Define novel automated techniques to automatically find HTTP semantics-level faults in existing REST APIs. Methods: We extended the state-of-the-art fuzzer EvoMaster with 9 new oracles to detect HTTP semanticslevel faults. Once the standard fuzzing process is finished generating N test cases, a new phase is executed in which these N tests are used as a starting point to create new scenarios (i.e., new sequences of HTTP calls) aimed at validating specific HTTP properties defined in these 9 oracles. Results: Experiments on 9 artificial APIs with inject faults show that our novel techniques can successfully detect all of them. Further experiments on 36 APIs from the WFD corpus show that our novel techniques can automatically find 166 existing faults in these real-world APIs. Conclusion: REST APIs use HTTP, and, as such, they need to follow its semantics to avoid misleading their clients and introducing subtle software faults. The novel techniques presented in this paper are shown to be effective at automatically finding several of this type of faults.

| Subjects: | Software Engineering (cs.SE) |
| --- | --- |
| Cite as: | [arXiv:2608.16239](https://arxiv.org/abs/2608.16239) \[cs.SE\] |
|  | (or [arXiv:2608.16239v1](https://arxiv.org/abs/2608.16239v1) \[cs.SE\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.16239](https://doi.org/10.48550/arXiv.2608.16239) |

## Submission history

From: Andrea Arcuri \[[view email](https://arxiv.org/show-email/5d24bb63/2608.16239)\]  
**\[v1\]** Mon, 17 Aug 2026 08:16:31 UTC (32 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.16239) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
