LEGION: Best-First Concolic Testing
Dongge Liu, Gidon Ernst, Toby Murray, Benjamin I. P. Rubinstein
Abstract
Concolic execution and fuzzing are two complementary coveragebased testing techniques. How to achieve the best of both remains an open challenge. To address this research problem, we propose and evaluate Legion. Legion re-engineers the Monte Carlo tree search (MCTS) framework from the AI literature to treat automated test generation as a problem of sequential decision-making under uncertainty. Its best-first search strategy provides a principled way to learn the most promising program states to investigate at each search iteration, based on observed rewards from previous iterations. Legion incorporates a form of directed fuzzing that we call approximate path-preserving fuzzing (APPFuzzing) to investigate program states selected by MCTS. APPFuzzing serves as the Monte Carlo simulation technique and is implemented by extending prior work on constrained sampling. We evaluate Legion against competitors on 2531 benchmarks from the coverage category of Test-Comp 2020, as well as measuring its sensitivity to hyperparameters, demonstrating its effectiveness on a wide variety of input programs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a8f0d741-abe3-4c8c-8482-6e443da7f19aCited by top-tier papers4
- Fuzzle: Making a Puzzle for FuzzersHaeun Lee, Soomin Kim, Sang Kil ChaASE 2022 · 13 citations
- SymFusion: Hybrid Instrumentation for Concolic ExecutionEmilio Coppa, Heng Yin, Camil DemetrescuASE 2022 · 7 citations
- Marco: A Stochastic Asynchronous Concolic ExplorerJie Hu, Yue Duan, Heng YinICSE 2024 · 6 citations
- Empc: Effective Path Prioritization for Symbolic Execution with Path CoverShuangjie Yao, Dongdong SheS&P 2025
Builds on9
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
Related papers
- Enhancing Coverage-Guided Fuzzing via Phantom ProgramMingyuan Wu, Kunqiu Chen, Qi Luo, Jiahong Xiang et al.FSE 2023 · 7 citations
- Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid FuzzingLei Zhao, Yue Duan, Heng Yin, Jifeng XuanNDSS 2019 · 157 citations
- Towards Understanding the Effectiveness of Large Language Models on Directed Test Input GenerationZongze Jiang, Ming Wen, Jialun Cao, Xuanhua Shi et al.ASE 2024 · 8 citations
- PILOT: Command-Line Interface Fuzzing Via Path-Guided, Iterative Large Language Model PromptingMomoko Shiraishi, Yinzhi Cao, Takahiro ShinagawaS&P 2026 · 1 citation
- Pangolin: Incremental Hybrid Fuzzing with Polyhedral Path AbstractionHeqing Huang, Peisen Yao, Rongxin Wu, Qingkai Shi et al.S&P 2020 · 94 citations
