Fuzzing for CPS Mutation Testing
Jaekwon Lee, Enrico Viganò, Oscar Cornejo, Fabrizio Pastore, Lionel C. Briand
Abstract
Mutation testing can help reduce the risks of releasing faulty software. For such reason, it is a desired practice for the development of embedded software running in safety-critical cyber-physical systems (CPS). Unfortunately, state-of-the-art test data generation techniques for mutation testing of C and C++ software, two typical languages for CPS software, rely on symbolic execution, whose limitations often prevent its application (e.g., it cannot test black-box components). We propose a mutation testing approach that leverages fuzz testing, which has proved effective with C and C++ software. Fuzz testing automatically generates diverse test inputs that exercise program branches in a varied number of ways and, therefore, exercise statements in different program states, thus maximizing the likelihood of killing mutants, our objective. We performed an empirical assessment of our approach with software components used in satellite systems currently in orbit. Our empirical evaluation shows that mutation testing based on fuzz testing kills a significantly higher proportion of live mutants than symbolic execution (i.e., up to an additional 47 percentage points). Further, when symbolic execution cannot be applied, fuzz testing provides significant benefits (i.e., up to 41% mutants killed). Our study is the first one comparing fuzz testing and symbolic execution for mutation testing; our results provide guidance towards the development of fuzz testing tools dedicated to mutation testing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- VLATest: Testing and Evaluating Vision-Language-Action Models for Robotic ManipulationZhijie Wang, Zhehua Zhou, Jiayang Song, Yuheng Huang et al.FSE 2025 · 6 citations
- ROCAS: Root Cause Analysis of Autonomous Driving Accidents via Cyber-Physical Co-mutationShiwei Feng, Yapeng Ye, Qingkai Shi, Zhiyuan Cheng et al.ASE 2024 · 4 citations
- IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesSudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon et al.ASE 2025
Builds on11
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
- Automated test generation for REST APIs: no time to rest yetMyeongsoo Kim, Qi Xin, Saurabh Sinha, Alessandro OrsoISSTA 2022 · 67 citations
Related papers
- SLEMI: equivalence modulo input (EMI) based mutation of CPS models for finding compiler bugs in SimulinkShafiul Azam Chowdhury, Sohil Lal Shrestha, Taylor T. Johnson, Christoph CsallnerICSE 2020 · 35 citations
- Detecting Simulink compiler bugs via controllable zombie blocks mutationShikai Guo, He Jiang, Zhihao Xu, Xiaochen Li et al.FSE 2022 · 15 citations
- Semantic Image Fuzzing of AI Perception SystemsTrey Woodlief, Sebastian G. Elbaum, Kevin SullivanICSE 2022 · 17 citations
- Signal Breaker: Fuzzing Digital Signal ProcessorsCameron Santiago Garcia, Matthew HicksASPLOS 2026
- SQUIRREL: Testing Database Management Systems with Language Validity and Coverage FeedbackRui Zhong, Yongheng Chen, Hong Hu, Hangfan Zhang et al.CCS 2020 · 5 citations
