USENIX Security2026Top-tier venue
PANGOLIN: Fuzzing Multilingual IoT Firmware with LLM-Driven Code Analysis
Zhipeng Jia, Xiaokang Yin, Shuitao Gan, Chao Zhang, Hangtian Liu, Jiangan Ji, Enzhou Song, Ruijie Cai, Jinglei Tan, Shengli Liu
Abstract
Multilingual IoT typically refers to the use of multiple languages to implement its web services, such as C, Python, Lua, etc. While some user-accessible interfaces are visualized through the frontend for interaction, a large number of interfaces remain hidden and are not exposed to the frontend in multilingual IoT. Additionally, their parameters often exhibit complex hierarchical structures. Effectively extracting interface specifications from multilingual devices for vulnerability discovery is an urgent problem that remains unresolved. In this paper, we present PANGOLIN, a novel fuzzing solution designed for multilingual IoT devices. First, we utilize LLMs to analyze API dispatching mechanisms and identify interfaces. Then, we introduce an LLM agent to perform cross-language analysis and generate input parameter specifications. Lastly, we utilize response-driven feedback to correct parameter specifications. This knowledge enables semantics-aware fuzzing that can explore deeper code paths and discover more vulnerabilities. PANGOLIN successfully discovered 68 previously unknown vulnerabilities, i.e., 2.96X more than SOTA tool LABRADOR. Notably, 45 of these vulnerabilities were found in hidden interfaces, whereas EAGLEYE was only able to identify 4 such cases. As of the time of writing, all vulnerabilities have been reported to vendors and acknowledged, with 31 vulnerability IDs assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3cc26f29-b62d-46cb-a371-7d925341d5daBuilds on17
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue et al.CCS 2021 · 146 citations
- Karonte: Detecting Insecure Multi-binary Interactions in Embedded FirmwareNilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky et al.S&P 2020 · 128 citations
- Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded SystemsLibo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan et al.USENIX Security 2021 · 71 citations
Related papers
- EAGLEYE: Exposing Hidden Web Interfaces in IoT Devices via Routing AnalysisHangtian Liu, Lei Zheng, Shuitao Gan, Chao Zhang et al.NDSS 2025
- PolyFuzz: Holistic Greybox Fuzzing of Multi-Language SystemsWen Li, Jinyang Ruan, Guangbei Yi, Long Cheng et al.USENIX Security 2023
- LLMIF: Augmented Large Language Model for Fuzzing IoT DevicesJincheng Wang, Le Yu, Xiapu LuoS&P 2024 · 61 citations
- Labrador: Response Guided Directed Fuzzing for Black-box IoT DevicesHangtian Liu, Shuitao Gan, Chao Zhang, Zicong Gao et al.S&P 2024 · 25 citations
- Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT DevicesWei Xie, Jiongyi Chen, Zhenhua Wang, Chao Feng et al.WWW 2022 · 26 citations
