arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SeedSmith:用于定向模糊测试的基于大语言模型的种子合成

SeedSmith: LLM-Driven Seed Synthesis for Directed Fuzzing

Junmin Zhu, Siyu Liu, Jie Hu, Fabio Gritti, Ati Priya Bajaj, Hulin Wang, Wenbo Guo, Tiffany Bao, Christopher Kruegel, Giovanni Vigna

arXiv 2607.08949首次发表:更新:

AI 中文总结

研究针对定向模糊测试常无法触发崩溃的问题,提出SeedSmith这一基于大语言模型的管道,通过复制分析师工作流程合成种子,提升模糊器性能,在Magma和ARVO上取得显著加速和发现新漏洞的成果。

AI 中文摘要

定向模糊测试旨在引导模糊器针对用户定义的下沉函数来识别漏洞,但即使经过长时间测试也常无法触发崩溃。我们识别出两个阻碍因素:间接调用的静态分析不完整,使基于距离的引导无法看到可达路径;缺乏对崩溃前置条件的语义引导,盲目变异在实际时间预算内无法满足。现有种子生成方法无法解决这些问题。我们提出SeedSmith,它能复制安全分析师的工作流程,从下沉函数开始迭代探索代码库、解析间接调用、识别崩溃前置条件并合成满足条件的具体输入。其种子与模糊器无关,能提升任何基于变异的下游模糊器。在Magma上,使用SeedSmith种子的模糊器相比默认种子,崩溃时间几何平均加速11.51倍(AFL++)至14.66倍(AFLGo)。在ARVO上,SeedSmith使模糊器触发了16个之前无法到达的漏洞,涉及10个具有不同输入格式的项目。

英文摘要

Directed fuzzing steers fuzzers toward user-defined sink functions to identify vulnerabilities, but it frequently fails to trigger crashes even after long campaigns. We identify two challenges that prevent directed fuzzers from exposing crashes: incomplete static analysis of indirect calls, which leaves reachable paths invisible to distance-based guidance, and lack of semantic guidance for crash preconditions, which blind mutation cannot satisfy within practical time budgets. A natural intervention point is the initial seed corpus: seeds that encode the right control-flow path and satisfy key crash preconditions shift fuzzing from blind exploration to local refinement. Existing seed generation approaches address neither: grammar-based and format-driven methods produce structurally valid inputs with no sink awareness, while LLM-based methods either lack sink targeting or inherit static analysis limitations through one-shot prompting. We present SeedSmith, an agentic LLM pipeline that replicates a security analyst's workflow: starting from a sink, it iteratively explores the codebase, resolves indirect calls, identifies crash preconditions, and synthesizes concrete inputs that satisfy them. Because SeedSmith operates as a seed generation front-end, its seeds are fuzzer-agnostic and improve any downstream mutation-based fuzzer without modification. On Magma, fuzzers using SeedSmith seeds achieve geometric mean crash-time speedups of 11.51 times (AFL++) to 14.66 times (AFLGo) over default seeds. On ARVO, SeedSmith enables fuzzers to trigger 16 previously unreachable bugs spanning 10 projects with diverse input formats.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑