GPTrace: Effective Crash Deduplication Using LLM Embeddings
Patrick Herter, Vincent Ahlrichs, Ridvan Açilan, Julian Horsch
Abstract
Fuzzing is a highly effective method for uncovering software vulnerabilities, but analyzing the resulting data typically requires substantial manual effort. This is amplified by the fact that fuzzing campaigns often find a large number of crashing inputs, many of which share the same underlying bug. Crash deduplication is the task of finding such duplicate crashing inputs and thereby reducing the data that needs to be examined. Many existing deduplication approaches rely on comparing stack traces or other information that is collected when a program crashes. Although various metrics for measuring the similarity of such pieces of information have been proposed, many do not yield satisfactory deduplication results. In this work, we present GPTrace, a deduplication workflow that leverages a large language model to evaluate the similarity of various data sources associated with crashes by computing embedding vectors and supplying those as input to a clustering algorithm. We evaluate our approach on over 300 000 crashing inputs belonging to 50 ground truth labels from 14 different targets. The deduplication results produced by GPTrace show a noticeable improvement over hand-crafted stack trace comparison methods and even more complex state-of-the-art approaches that are less flexible.
• Software and its engineering → Software testing and debugging; • Security and privacy → Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 671f1f3a-9977-473a-92d4-b571920d6c5bBuilds on6
- Matryoshka Representation LearningAditya Kusupati, Gantavya Bhatt, Aniket Rege, Matthew Wallingford et al.NeurIPS 2022 · 364 citations
- Seed selection for successful fuzzingAdrian Herrera, Hendra Gunadi, Shane Magrath, Michael Norrish et al.ISSTA 2021 · 95 citations
- Igor: Crash Deduplication Through Root-Cause ClusteringZhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang et al.CCS 2021 · 20 citations
- FuzzerAid: Grouping Fuzzed Crashes Based On Fault SignaturesAshwin Kallingal Joshy, Wei LeASE 2022 · 6 citations
- Default: Mutual Information-based Crash Triage for Massive CrashesXing Zhang, Jiongyi Chen, Chao Feng, Ruilin Li et al.ICSE 2022 · 5 citations
Related papers
- Function Clustering-Based Fuzzing Termination: Toward Smarter Early StoppingLiang Ding, Wenzhang Yang, Yinxing XueASE 2025
- TRIGFUZZ: Triggering Conditions Guided Directed FuzzingYiyang Chen, Nuoqi Gui, Long Wang, Longfei Chen et al.S&P 2026 · 1 citation
- Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug UnearthingAsmita, Yaroslav Oliinyk, Michael Scott, Ryan Tsang et al.USENIX Security 2024 · 56 citations
- An In-depth Analysis of Duplicated Linux Kernel Bug ReportsDongliang Mu, Yuhang Wu, Yueqi Chen, Zhenpeng Lin et al.NDSS 2022
- CrashTranslator: Automatically Reproducing Mobile Application Crashes Directly from Stack TraceYuchao Huang, Junjie Wang, Zhe Liu, Yawen Wang et al.ICSE 2024 · 22 citations
