Revisiting Neural Program Smoothing for Fuzzing
Maria-Irina Nicolae, Max Eisele, Andreas Zeller
Abstract
Testing with randomly generated inputs (fuzzing) has gained significant traction due to its capacity to expose program vulnerabilities automatically. Fuzz testing campaigns generate large amounts of data, making them ideal for the application of machine learning (ML). Neural program smoothing, a specific family of ML-guided fuzzers, aims to use a neural network as a smooth approximation of the program target for new test case generation.
In this paper, we conduct the most extensive evaluation of neural program smoothing (NPS) fuzzers against standard gray-box fuzzers (>11 CPU years and >5.5 GPU years), and make the following contributions: (1) We find that the original performance claims for NPS fuzzers do not hold; a gap we relate to fundamental, implementation, and experimental limitations of prior works.
(2) We contribute the first in-depth analysis of the contribution of machine learning and gradient-based mutations in NPS. (3) We implement Neuzz++, which shows that addressing the practical limitations of NPS fuzzers improves performance, but that standard gray-box fuzzers almost always surpass NPS-based fuzzers. (4) As a consequence, we propose new guidelines targeted at benchmarking fuzzing based on machine learning, and present MLFuzz, a platform with GPU access for easy and reproducible evaluation of ML-based fuzzers. Neuzz++, MLFuzz, and all our data are public.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6f0fbebb-430d-42c5-9bb4-b732db88eec5Cited by top-tier papers4
- FOX: Coverage-guided Fuzzing as Online Stochastic ControlDongdong She, Adam Storek, Yuchong Xie, Seoyoung Kweon et al.CCS 2024 · 5 citations
- An Empirical Examination of Fuzzer Mutator PerformanceJames Kukucka, Luís Pina, Paul Ammann, Jonathan BellISSTA 2024 · 4 citations
- IDFuzz: Intelligent Directed Grey-box FuzzingYiyang Chen, Chao Zhang, Long Wang, Wenyu Zhu et al.USENIX Security 2025
- On Interaction Effects in Greybox FuzzingKonstantinos Kitsios, Marcel Böhme, Alberto BacchelliICSE 2026
Builds on12
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
Related papers
- NEUZZ: Efficient Fuzzing with Neural Program SmoothingDongdong She, Kexin Pei, Dave Epstein, Junfeng Yang et al.S&P 2019 · 220 citations
- Evaluating and Improving Neural Program-Smoothing-based FuzzingMingyuan Wu, Ling Jiang, Jiahong Xiang, Yuqun Zhang et al.ICSE 2022 · 22 citations
- MTFuzz: fuzzing with a multi-task neural networkDongdong She, Rahul Krishna, Lu Yan, Suman Jana et al.FSE 2020 · 46 citations
- A Generative and Mutational Approach for Synthesizing Bug-Exposing Test Cases to Guide Compiler FuzzingGuixin Ye, Tianmin Hu, Zhanyong Tang, Zhenye Fan et al.FSE 2023 · 14 citations
- Interleaved Learning and Exploration: A Self-Adaptive Fuzz Testing Framework for MLIRZeyu Sun, Jingjing Liang, Weiyi Wang, Chenyao Suo et al.ASE 2025 · 1 citation
