Eidolon: Perform Noise-Aware Fuzzing on FHE Libraries via Equivalence Expression Transformation
Zhensheng Xian, Zhen Yan, Yuanliang Chen, Xuelian Cao, Fuchen Ma, Dalong Shi, Yu Jiang
Abstract
Ensuring data privacy during computation is a critical challenge in many security systems. Fully Homomorphic Encryption (FHE) addresses this gap by enabling multiple operations on encrypted data without decryption, thus ensuring privacy is preserved throughout computation. However, existing cryptographic testing tools are unable to test the core functionality of FHE, which is the execution of computations on encrypted data. They are expertly designed to generate structured data for testing cryptographic algorithms. This structural mismatch, combined with a lack of awareness of FHE-specific noise management, leads them to generate invalid test inputs that fail to probe FHE libraries' core logic.
To address this gap, we propose Eidolon, a noise-aware fuzzer. It directs mutations toward arithmetic expressions that explore the computational space defined by the noise budget. As its test oracle, Eidolon leverages Equivalence Expression Transformation, which transforms a standard arithmetic expression into two mathematically identical but structurally different forms (e.g., Factored, Horner) to detect inconsistencies in their outputs. We evaluated Eidolon on SEAL, OpenFHE, HElib, and TFHE. Compared with existing cryptographic and grammar-based fuzzers, Eidolon achieves 28.7%, 45.5%, 75.6%, and 37.6% higher final code coverage than CLFuzz, Cryptofuzz, CDF, and Peach, respectively. In total, Eidolon uncovered 20 previously unknown bugs, 10 of which have been fixed and 12 assigned CVEs.
CCS Concepts: • Software and its engineering → Software testing and debugging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 69a86359-7977-4632-855b-00ddcb458abaBuilds on4
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- QFuzz: quantitative fuzzing for side channelsYannic Noller, Saeid Tizpaz-NiariISSTA 2021 · 15 citations
- PolyJuice: Detecting Mis-compilation Bugs in Tensor Compilers with Equality Saturation Based RewritingChijin Zhou, Bingzhou Qian, Gwihwan Go, Quan Zhang et al.OOPSLA 2024 · 7 citations
- Testing and Understanding Deviation Behaviors in FHE-Hardened Machine Learning ModelsYiteng Peng, Daoyuan Wu, Zhibo Liu, Dongwei Xiao et al.ICSE 2025 · 1 citation
Related papers
- T-Fuzz: Fuzzing by Program TransformationHui Peng, Yan Shoshitaishvili, Mathias PayerS&P 2018 · 326 citations
- FREEDOM: Engineering a State-of-the-Art DOM FuzzerWen Xu, Soyeon Park, Taesoo KimCCS 2020 · 25 citations
- EchoFuzz: Empowering Smart Contract Fuzzing with Large Language ModelsJuanen Li, Peng Qian, Guanyan Li, Rui Wang et al.ICSE 2026
- MundoFuzz: Hypervisor Fuzzing with Statistical Coverage Testing and Grammar InferenceCheolwoo Myung, Gwangmu Lee, Byoungyoung LeeUSENIX Security 2022
- TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable VulnerabilitiesRahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig et al.USENIX Security 2022
