BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw Detection
Ting Yang, Yue Qin, Lan Zhang, Zhiyuan Fu, Junfan Chen, Jice Wang, Shangru Zhao, Qi Li, Ruidong Li, He Wang, Yuqing Zhang
Abstract
Bluetooth Low Energy (BLE) has become a foundational communication standard for modern connected devices. However, its complex design introduces subtle logic flaws, such as misinterpreted fields or invalid state transitions, that can enable authentication bypass, unauthorized control, or Denial-of-Service (DoS) attacks. These issues often evade conventional fuzzing and formal analysis. To address this gap, we propose BSFuzzer, a black-box, context-aware semantic fuzzing framework guided by the Bluetooth Core Specification. BSFuzzer uses a Large Language Model (LLM) agent to semantically parse the Bluetooth specification, extracting state machines and packet semantics from text, diagrams, and context. It then generates two types of mutations: field-level violations of protocol rules and state-level disruptions of key transitions. These are composed into structured test sequences and executed on target devices. The LLM agent is further used to verify responses against expected behaviors, enabling detection of subtle logic flaws beyond the reach of traditional fuzzers. We evaluated BSFuzzer on 19 real-world BLE devices, including 9 System-on-Chip (SoC) modules and 10 smartphones. It uncovered 36 security issues, including 34 previously unknown bugs, 9 of which have received CVE identifiers. Two critical flaws were recognized by a major vendor through bug bounty programs. The experimental results indicate that BSFuzzer attains high accuracy in both LLM-based specification analysis (up to 97%) and response validation (up to 85.8%), demonstrating its effectiveness in semantic extraction and enhancing fuzzing performance. Compared to four state-of-the-art BLE vulnerability detection tools, BSFuzzer achieved 9.34% higher code coverage and exposed a broader class of vulnerabilities, demonstrating its effectiveness in uncovering deep interpretation inconsistencies in BLE protocol implementations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bf70b8ba-0ee4-441d-8faa-db2d0d5c2370Builds on11
- SweynTooth: Unleashing Mayhem over Bluetooth Low EnergyMatheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun et al.USENIX ATC 2020 · 83 citations
- LLMIF: Augmented Large Language Model for Fuzzing IoT DevicesJincheng Wang, Le Yu, Xiapu LuoS&P 2024 · 61 citations
- BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth PeripheralsFenghao Xu, Wenrui Diao, Zhou Li, Jiongyi Chen et al.NDSS 2019 · 51 citations
- From One Thousand Pages of Specification to Unveiling Hidden Bugs: Large Language Model Assisted Fuzzing of Matter IoT DevicesXiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2024 · 49 citations
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks and DefensesDaniele AntonioliCCS 2023 · 7 citations
Related papers
- BrakTooth: Causing Havoc on Bluetooth Link Manager via Directed FuzzingMatheus E. Garbelini, Vaibhav Bedi, Sudipta Chattopadhyay, Sumei Sun et al.USENIX Security 2022
- BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol StacksWei-Che Kao, Yen-Chia Chen, Yu-Sheng Lin, Yu-Cheng Yang et al.USENIX Security 2025
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen et al.WWW 2026
- Bluetooth Low Energy Security Testing with Combinatorial MethodsDominik-Philip Schreiber, Manuel Leithner, Jovan Zivanovic, Dimitris E. SimosUSENIX ATC 2025 · 1 citation
- An LLM-Guided Fuzzing of Proprietary Industrial Communication Protocols with Context KnowledgeTianci Pan, Huan Qian, Yaowen Zheng, Haining Wang et al.INFOCOM 2026
