Titan : Efficient Multi-target Directed Greybox Fuzzing
Heqing Huang, Peisen Yao, Hung-Chun Chiu, Yiyuan Guo, Charles Zhang
Abstract
Modern directed fuzzing often faces scalability issues when analyzing multiple targets in a program simultaneously. We observe that the root cause is that directed fuzzers are unaware of the correlations among the targets, thereby could degenerate into a target-undirected method. As a result, directed fuzzing suffers severely from efficiency when reproducing multiple targets.
This paper presents Titan, which enables fuzzers to distinguish correlations among various targets in the program and, thus, optimizes the input generation to reproduce multiple targets effectively. Leveraging these correlations, Titan differentiates seeds' potential of reaching each target for the scheduling and identifies bytes that can be changed simultaneously for the mutation. We compare our approach to eight state-of-theart (directed) fuzzers. The evaluation demonstrates that Titan outperforms existing approaches by efficiently detecting multiple targets, achieving a 21.4x speedup and requiring 95.0% fewer number of executions. In addition, Titan detects nine incomplete fixes, which cannot be detected by other directed fuzzers, in the latest versions of the benchmark programs with two CVE IDs assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bb415dc0-bfde-452c-a3ee-e456818b2bdeCited by top-tier papers11
- DDGF: Dynamic Directed Greybox Fuzzing with Path ProfilingHaoran Fang, Kaikai Zhang, Donghui Yu, Yuanyuan ZhangISSTA 2024 · 10 citations
- Accurate and Efficient Recurring Vulnerability Detection for IoT FirmwareHaoyu Xiao, Yuan Zhang, Minghang Shen, Chaoyang Lin et al.CCS 2024 · 5 citations
- ZTaint-Havoc: From Havoc Mode to Zero-Execution Fuzzing-Driven Taint InferenceYuchong Xie, Wenhui Zhang, Dongdong SheISSTA 2025 · 2 citations
- Fuzzing Guided by Bayesian Program AnalysisYifan Zhang, Xin ZhangPOPL 2026 · 2 citations
- KRAKEN: Program-Adaptive Parallel FuzzingAnshunkang Zhou, Heqing Huang, Charles ZhangISSTA 2025
Builds on23
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
Related papers
- Critical Variable State-Aware Directed Greybox FuzzingXu Chen, Ningning Cui, Zhe Pan, Liwei Chen et al.ICSE 2025 · 3 citations
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao et al.S&P 2022 · 139 citations
- FISHFUZZ: Catch Deeper Bugs by Throwing Larger NetsHan Zheng, Jiayuan Zhang, Yuhang Huang, Zezhong Ren et al.USENIX Security 2023
- Everything is Good for Something: Counterexample-Guided Directed Fuzzing via Likely Invariant InferenceHeqing Huang, Anshunkang Zhou, Mathias Payer, Charles ZhangS&P 2024 · 15 citations
- Efficient Directed Hybrid Fuzzing via Target-Centric Seed Selection and GenerationZhen Li, Shenghan Liu, Qiuping Yi, Pengbo Du et al.OOPSLA 2026
