利用大语言模型(LLM)实现Python库的文档引导模糊测试
Harnessing LLMs for Document-Guided Fuzzing of Python Libraries
浏览论文内容
中文总结 AI 辅助
本文提出VistaFuzz,一种基于本地开源LLM的文档引导模糊测试技术,用于测试Python库API,在12个库的7718个API上发现74个问题,其中43个已确认、29个已修复。
中文摘要 AI 辅助
Python库是深度学习、科学计算、数据分析和计算机视觉的基础,其可靠性对下游应用至关重要。测试这些库的应用程序编程接口(API)需要满足每个参数的约束以及参数间的依赖关系。现有方法要么将此类约束隐含在生成的程序中,要么依赖于特定库的解析规则。本文提出VistaFuzz,一种文档引导的模糊测试技术,它使用本地部署的开源大语言模型(LLM)从API文档中提取参数规范,并生成同时满足参数约束和参数间依赖关系的输入。我们在12个Python库的7718个API上评估VistaFuzz,参数间关系存在于40.1%的被测API中,若不解析这些关系,这些API的有效生成率会从95%以上降至31.6%至52.8%。VistaFuzz共发现74个问题,其中43个已被开发者确认,29个已修复。
英文摘要
Python libraries underpin deep learning, scientific computing, data analysis, and computer vision, making their reliability critical to downstream applications. Testing their APIs requires inputs that satisfy both per-parameter constraints and dependencies among parameters. Existing approaches either leave such constraints implicit in generated programs or rely on library-specific parsing rules. This paper introduces VistaFuzz, a document-guided fuzzing technique that uses a locally served open-sourced LLM to extract parameter specifications from API documents and generate inputs that satisfy both parameter constraints and inter-parameter dependencies. We evaluate VistaFuzz on 7,718 APIs across twelve Python libraries. Inter-parameter relationships occur in 40.1\% of tested APIs, and disabling their resolution reduces the valid generation rate on those APIs from above 95\% to 31.6\%--52.8\%. VistaFuzz reports 74 issues, of which 43 have been confirmed by developers and 29 have been fixed.