SimiFuzz: Seed–Worker Scheduling for Parallel Fuzzing via Contextual Bandits
Yijia Guo, Zhiguo Ding, Hong Liang, Ming Zhong, Dandan Zhao, Xuhong Zhang, Bo Zhang, Shouling Ji, Hao Peng
Abstract
Parallel fuzzing is now a standard way to scale vulnerability discovery, yet its efficiency is still limited by ineffective task allocation among workers. Existing approaches mainly aim to reduce conflicts; however, none considers the interaction between seeds and workers: the same seed can yield very different gains on different workers due to their divergent exploration states. As a result, parallel fuzzing can drift toward over-isolation that wastes shared states, or excessive overlap that duplicates effort. To solve this problem, we present SimiFuzz, a context-aware scheduling framework that learns to assign seed–worker pairs online. SimiFuzz encodes each assignment with a compact context vector that jointly models seed characteristics, worker state, and seed–worker interaction. On top of this representation, SimiFuzz employs a LinUCB-based contextual bandit to score candidate pairs, balancing individual worker efficiency against group-level redundancy to maximize collective progress. To handle non-stationary fuzzing dynamics, SimiFuzz adopts a time-slice feedback mechanism that aggregates coverage gains within fixed intervals, combining globally new edges with cross-learning progress to form stable reward signals. We implement SimiFuzz on top of AFL++ and evaluate it on eight real-world targets. In 24-hour campaigns with 10 parallel instances, SimiFuzz improves average edge coverage by 11.76 % over FlexFuzz, the strongest baseline in coverage and unique vulnerability (VUL) count, achieves the highest final coverage on all evaluated targets, and uncovers 16 more unique vulnerabilities and 11 more CVEs than FlexFuzz.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Critical Variable State-Aware Directed Greybox FuzzingXu Chen, Ningning Cui, Zhe Pan, Liwei Chen et al.ICSE 2025 · 3 citations
- Tumbling Down the Rabbit Hole: How do Assisting Exploration Strategies Facilitate Grey-Box Fuzzing?Mingyuan Wu, Jiahong Xiang, Kunqiu Chen, Peng Di et al.ICSE 2025 · 1 citation
- xFUZZ: A Flexible Framework for Fine-Grained, Runtime-Adaptive Fuzzing Strategy CompositionDongsong Yu, Yiyi Wang, Chao Zhang, Yang Lan et al.ISSTA 2025
- FISHFUZZ: Catch Deeper Bugs by Throwing Larger NetsHan Zheng, Jiayuan Zhang, Yuhang Huang, Zezhong Ren et al.USENIX Security 2023
- MUZZ: Thread-aware Grey-box Fuzzing for Effective Bug Hunting in Multithreaded ProgramsHongxu Chen, Shengjian Guo, Yinxing Xue, Yulei Sui et al.USENIX Security 2020
