AI 中文总结
该研究针对Rust库模糊测试中现有工具约束处理不足导致覆盖率低的问题,提出GRAFT方法,通过结构化API分析生成可编译模糊目标,在13个Rust crate上的API覆盖率和编译成功率均优于现有工具。
AI 中文摘要
对Rust库API进行模糊测试需要构建符合类型规则、可编译的调用序列,满足所有权规则、泛型参数和特质约束;现有工具要么忽略这些约束,要么采用浅层启发式方法,导致覆盖率较低。本文提出GRAFT,它从Rust文档中提取结构化API信息,通过递归泛型感知类型匹配构建API依赖图,采用拓扑引导遍历结合带编译器错误反馈的大语言模型(LLM)合成来生成可编译的模糊测试目标。在来自指定来源的13个 crate 上,GRAFT达到80.75%的宏平均API覆盖率,编译成功率为96.19%,分别比RULF和RPG高出4.76倍和2.43倍,在涉及不安全可达API的 crate 上达到deepSURF平均API覆盖率的1.41倍。
英文摘要
Fuzzing Rust library APIs requires constructing well-typed, compilable call sequences that satisfy ownership rules, generic parameters, and trait bounds; existing tools ignore these constraints or use shallow heuristics, yielding low coverage. We present GRAFT, which extracts structured API information from Rust documentation, builds an API dependency graph via recursive generics-aware type matching, and uses topology-guided traversal plus LLM synthesis with compiler-error feedback to produce compilable fuzz targets. On 13 crates from crates.io, GRAFT achieves 80.75% macro-average API coverage at 96.19% compilation success, outperforming RULF and RPG by 4.76x and 2.43x, and reaching 1.41x the average API coverage of deepSURF on crates with unsafe-reaching APIs.