AFGen: Whole-Function Fuzzing for Applications and Libraries
Yuwei Liu, Yanhao Wang, Xiangkun Jia, Zheng Zhang, Purui Su
Abstract
Fuzzing technology has been widely used to discover vulnerabilities, but existing fuzzing techniques still cannot cover and explore all functions in an application or a library. The works that automatically generate fuzzing harnesses for API functions of libraries provide a way to test the target function directly. However, applying these approaches to arbitrary internal functions of a project (e.g., library) is challenging. Specifically, the context of an API function is usually simple and clear for users, but the complex dependence of the internal functions leads to a more complicated running context and constraints on their parameters, making it hard to generate fuzzing harnesses efficiently.In this paper, we propose whole-function fuzzing, a "bottom-up" approach that fuzzes applications and libraries by covering all functions. We argue that it is beneficial to vulnerability discovery if one achieves full function coverage with precision sacrifice that can be mitigated through a delicate design. To this end, we design and implement AFGen, a framework of automatic whole-function fuzzing. Given a target function, AFGen will generate a fuzzing harness that reaches the target function with proper initial program context, and it will refine the fuzzing harness based on the constraints of the discovered crashes. Specifically, it slices the calling statements of a target function based on the control flow and data flow dependency, assigns values for the necessary variables used in the sliced code according to their types, and searches the constraint statements of the variables related to crash. In this way, AFGen generates fuzzing harnesses with a low false positive rate. To verify the effectiveness of AFGen, we collected 102 known vulnerabilities from 11 open-source projects. AFGen successfully creates fuzzing harnesses for all vulnerable functions, and it identifies 66 vulnerabilities of the collected 102 known vulnerabilities, which outperforms all comparing tools and achieves 2x vulnerabilities discovered by the second best fuzzer (i.e., AFL++). The crashes triggered by AFGen achieve 77.1% precision, which is 10 times the precision of FUDGE. AFGen also discovers 24 unknown vulnerabilities confirmed with CVE IDs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 3492a057-ff2b-47e2-8209-b75988c66ae4Cited by top-tier papers11
- Prompt Fuzzing for Fuzz Driver GenerationYunlong Lyu, Yuxuan Xie, Peng Chen, Hao ChenCCS 2024 · 21 citations
- No Harness, No Problem: Oracle-guided Harnessing for Auto-generating C API Fuzzing HarnessesGabriel Sherman, Stefan NagyICSE 2025 · 1 citation
- RandSet: Randomized Corpus Reduction for Fuzzing Seed SchedulingYuchong Xie, Kaikai Zhang, Yu Liu, Rundong Yang et al.OOPSLA 2026 · 1 citation
- RTCON: Context-Adaptive Function-Level Fuzzing for RTOS KernelsEunkyu Lee, Junyoung Park, Insu YunNDSS 2026 · 1 citation
- Thinking More, Harnessing Better: Automatic Harness Generation with Dataflow Aggregation and Workflow DecompositionXing Zhang, Zikang Huang, Gang Yang, CongChong Wang et al.CCS 2026
Related papers
- FuzzGen: Automatic Fuzzer GenerationKyriakos K. Ispoglou, Daniel Austin, Vishwath Mohan, Mathias PayerUSENIX Security 2020
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 44 citations
- WildSync: Automated Fuzzing Harness Synthesis via Wild API Usage RecoveryWei-Cheng Wu, Stefan Nagy, Christophe HauserISSTA 2025 · 1 citation
- APICraft: Fuzz Driver Generation for Closed-source SDK LibrariesCen Zhang, Xingwei Lin, Yuekang Li, Yinxing Xue et al.USENIX Security 2021 · 64 citations
- Atlas: Automating Cross-Language Fuzzing on Android Closed-Source LibrariesHao Xiong, Qinming Dai, Rui Chang, Mingran Qiu et al.ISSTA 2024 · 6 citations
