Parse this! Summoning Context-Sensitive Inputs with Goblin
Robert Lorch, Muhammad Daniyal Pirwani Dar, Cesare Tinelli, Omar Chowdhury
Abstract
Grammar-based fuzzers have been effective at identifying bugs in software systems with highly structured input formats (e.g., XML). Many existing grammar-based fuzzers rely on context-free grammars (CFGs) to represent input structure; however, CFGs are often insufficient to capture the context-sensitive constraints common in real-world inputs. While application-specific fuzzers can often handle such constraints, they lack the generality needed to adapt to new applications. We present Goblin, a new input generation tool that addresses this gap. Given a context-free grammar annotated with semantic constraints, Goblin generates inputs that both conform to the grammar and satisfy the constraints. A distinguishing feature of Goblin is its support—via an external SMT solver—for constraints expressed in arbitrary SMT theories. Inspired by DPLL-style SAT solvers, Goblin enjoys formal guarantees of solution soundness, solution completeness, and refutation soundness. We evaluate Goblin by comparing it with prior work and by integrating it into a grammar-based network protocol fuzzer.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Input invariantsDominic Steinhöfel, Andreas ZellerFSE 2022 · 47 citations
- Detecting critical bugs in SMT solvers using blackbox mutational fuzzingMuhammad Numair Mansur, Maria Christakis, Valentin Wüstholz, Fuyuan ZhangFSE 2020 · 51 citations
- Once4All: Skeleton-Guided SMT Solver Fuzzing with LLM-Synthesized GeneratorsMaolin Sun, Yibiao Yang, Yuming ZhouASPLOS 2026 · 1 citation
- Validating SMT Solvers via Skeleton Enumeration Empowered by Historical Bug-Triggering InputsMaolin Sun, Yibiao Yang, Ming Wen, Yongcong Wang et al.ICSE 2023 · 9 citations
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
