Property-Based Fuzzing for Finding Data Manipulation Errors in Android Apps
Jingling Sun, Ting Su, Jiayi Jiang, Jue Wang, Geguang Pu, Zhendong Su
Abstract
Like many software applications, data manipulation functionalities( DMFs ) are prevalent in Android apps, which perform the common CRUD operations (create, read, update, delete) to handle app-specific data. Thus, ensuring the correctness of these DMFs is fundamentally important for many core app functionalities. However, the bugs related to DMFs (named as data manipulation errors, DMEs ), especially those non-crashing logic ones, are prevalent but difficult to find. To this end, inspired by property-based testing, we introduce a property-based fuzzing approach to effectively finding DMEs in Android apps. Our key idea is that, given some type of app data of interest, we randomly interleave its relevant DMFs and other possible events to explore diverse app states for thorough validation. Specifically, our approach characterizes DMFs in (data) model-based properties and leverage the consistency between the data model and the UI layouts as the handler to do property checking. The properties of DMFs are specified by human according to specific app features. To support the application of our approach, we implemented an automated GUI testing tool, PBFDroid. We evaluated PBFDroid on 20 real-world Android apps, and successfully found 30 unique and previously unknown bugs in 18 apps. Out of the 30 bugs, 29 of which are DMEs (22 are non-crashing logic bugs, and 7 are crash ones). To date, 19 have been confirmed and 9 have already been fixed. Many of these bugs are non-trivial and lead to different types of app failures. Our further evaluation confirms that none of the 22 non-crashing DMEs can be found by the state-of-the-art techniques. In addition, a user study shows that the manual cost of specifying the DMF properties with the assistance of our tool is acceptable. Overall, given accurate DMF properties, our approach can automatically find DMEs without any false positives. We have made all the artifacts publicly available at:https:// github.com/ property-based-fuzzing/ home.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- General and Practical Property-based Testing for Android AppsYiheng Xiong, Ting Su, Jue Wang, Jingling Sun et al.ASE 2024 · 5 citations
- GUIPilot: A Consistency-Based Mobile GUI Testing Approach for Detecting Application-Specific BugsRuofan Liu, Xiwen Teoh, Yun Lin, Guanjie Chen et al.ISSTA 2025 · 5 citations
- RandSet: Randomized Corpus Reduction for Fuzzing Seed SchedulingYuchong Xie, Kaikai Zhang, Yu Liu, Rundong Yang et al.OOPSLA 2026 · 1 citation
- From Natural Language to Executable Properties for Property-Based Testing of Mobile Apps (Experience Paper)Yiheng Xiong, Ting Su, Jingling Sun, Jue Wang et al.ISSTA 2026
Builds on14
- Reinforcement learning based curiosity-driven testing of Android applicationsMinxue Pan, An Huang, Guoxin Wang, Tian Zhang et al.ISSTA 2020 · 166 citations
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 116 citations
- Time-travel testing of Android appsZhen Dong, Marcel Böhme, Lucia Cojocaru, Abhik RoychoudhuryICSE 2020 · 104 citations
- Benchmarking automated GUI testing for Android against real-world bugsTing Su, Jue Wang, Zhendong SuFSE 2021 · 77 citations
Related papers
- Fully automated functional fuzzing of Android apps for detecting non-crashing logic bugsTing Su, Yichen Yan, Jue Wang, Jingling Sun et al.OOPSLA 2021 · 58 citations
- An Empirical Study of Functional Bugs in Android AppsYiheng Xiong, Mengqian Xu, Ting Su, Jingling Sun et al.ISSTA 2023 · 40 citations
- Understanding and finding system setting-related defects in Android appsJingling Sun, Ting Su, Junxin Li, Zhen Dong et al.ISSTA 2021 · 35 citations
- Automata-Based Trace Analysis for Aiding Diagnosing GUI Testing Tools for AndroidEnze Ma, Shan Huang, Weigang He, Ting Su et al.FSE 2023 · 3 citations
- FuncDroid: Towards Inter-functional Flows for Comprehensive Mobile App GUI TestingJinlong He, Changwei Xia, Binru Huang, Jiwei Yan et al.ISSTA 2026
