Enhancing ROS System Fuzzing through Callback Tracing
Yuheng Shen, Jianzhong Liu, Yiru Xu, Hao Sun, Mingzhe Wang, Nan Guan, Heyuan Shi, Yu Jiang
Abstract
The Robot Operating System 2 (ROS) is the de-facto standard for robotic software development, with a wide application in diverse safety-critical domains. There are many efforts in testing that seek to deliver a more secure ROS codebase. However, existing testing methods are often inadequate to capture the complex and stateful behaviors inherent to ROS deployments, resulting in limited test- ing effectiveness. In this paper, we propose R2D2, a ROS system fuzzer that leverages ROS’s runtime states as guidance to increase fuzzing effectiveness and efficiency. Unlike traditional fuzzers, R2D2 employs a systematic instrumentation strategy that captures the system’s runtime behaviors and profiles the current system state in real-time. This approach provides a more in-depth understanding of system behaviors, thereby facilitating a more insightful explo- ration of ROS’s extensive state space. For evaluation, we applied it to four well-known ROS applications. Our evaluation shows that R2D2 achieves an improvement of 3.91× and 2.56× in code coverage compared to state-of-the-art ROS fuzzers, including Ros2Fuzz and RoboFuzz, while also uncovering 39 previously unknown vulnera- bilities, with 6 fixed in both ROS runtime and ROS applications. For its runtime overhead, R2D2 maintains an average execution and memory usage overhead with 10.4% and 1.0% in respect, making R2D2 effective in ROS testing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Finding Metadata Inconsistencies in Distributed File Systems via Cross-Node Operation ModelingFuchen Ma, Yuanliang Chen, Yuanhang Zhou, Zhen Yan et al.USENIX Security 2025
- Guarding the Lifeline: A First Look and Automated Defect Diagnosis for ROS Central IndexWeijie Sun, Huiyan Wang, Ying Wang, Chang XuISSTA 2026
Builds on15
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 180 citations
Related papers
- Multi-Dimensional and Message-Guided Fuzzing for Robotic Programs in Robot Operating SystemJia-Ju Bai, Haoxuan Song, Shimin HuASPLOS 2024 · 6 citations
- BTreeFuzz: Enhanced Feedback Mechanism for ROS Program Fuzzer Based on Behavior TreeHee Yeon Kim, Gyunghoon Kim, Dong Hoon Lee, Wonsuk ChoiICSE 2026
- RoboFuzz: fuzzing robotic systems over robot operating system (ROS) for finding correctness bugsSeulbae Kim, Taesoo KimFSE 2022 · 32 citations
- SFuzz: Slice-based Fuzzing for Real-Time Operating SystemsLibo Chen, Quanpu Cai, Zhenbang Ma, Yanhao Wang et al.CCS 2022 · 16 citations
- FuzzGen: Automatic Fuzzer GenerationKyriakos K. Ispoglou, Daniel Austin, Vishwath Mohan, Mathias PayerUSENIX Security 2020
