USENIX Security2024Top-tier venue
Racing on the Negative Force: Efficient Vulnerability Root-Cause Analysis through Reinforcement Learning on Counterexamples
Dandan Xu, Di Tang, Yi Chen, XiaoFeng Wang, Kai Chen, Haixu Tang, Longxing Li
Abstract
Root-Cause Analysis (RCA) is crucial for discovering security vulnerabilities from fuzzing outcomes. Automating this process through triaging the crashes observed during the fuzzing process, however, is considered to be challenging. Particularly, today's statistical RCA approaches are known to be exceedingly slow, often taking tens of hours or even a week to analyze a crash. This problem comes from the biased sampling such approaches perform. More specifically, given an input inducing a crash in a program, these approaches sample around the input by mutating it to generate new test cases; these cases are used to fuzz the program, in a hope that a set of program elements (blocks, instructions or predicates) on the execution path of the original input can be adequately sampled so their correlations with the crash can be determined. This process, however, tends to generate the input samples more likely causing the crash, with their execution paths involving a similar set of elements, which become less distinguishable until a large number of samples have been made. We found that this problem can be effectively addressed by sampling around "counterexamples", the inputs causing a significant change to the current estimates of correlations. These inputs though still involving the elements often do not lead to the crash. They are found to be effective in differentiating program elements, thereby accelerating the RCA process. Based upon the understanding, we designed and implemented a reinforcement learning (RL) technique that rewards the operations involving counterexamples. By balancing random sampling with the exploitation on the counterexamples, our new approach, called RACING, is shown to substantially elevate the scalability and the accuracy of today's statistical RCA, outperforming the state-of-the-art by more than an order of magnitude.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d36d7b6f-a412-4377-92fb-8392c86ab595Cited by top-tier papers8
- PortGPT: Towards Automated Backporting Using Large Language ModelsZhaoyang Li, Zheng Yu, Jingyi Song, Meng Xu et al.S&P 2026 · 2 citations
- Firmrca: Towards Post-Fuzzing Analysis on ARM Embedded Firmware with Efficient Event-Based Fault LocalizationBoyu Chang, Binbin Zhao, Qiao Zhang, Peiyu Liu et al.S&P 2025
- TypeForge: Synthesizing and Selecting Best-Fit Composite Data Types for Stripped BinariesYanzhong Wang, Ruigang Liang, Yilin Li, Peiwei Hu et al.S&P 2025
- PATCHAGENT: A Practical Program Repair Agent Mimicking Human ExpertiseZheng Yu, Ziyi Guo, Yuhang Wu, Jiahao Yu et al.USENIX Security 2025
- Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy InjectionYihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang et al.USENIX Security 2026
Builds on9
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Postmortem Program Analysis with Hardware-Enhanced Post-Crash ArtifactsJun Xu, Dongliang Mu, Xinyu Xing, Peng Liu et al.USENIX Security 2017 · 55 citations
- ARCUS: Symbolic Root Cause Analysis of Exploits in Production SystemsCarter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick et al.USENIX Security 2021 · 42 citations
- Automated Bug Hunting With Data-Driven Symbolic Root Cause AnalysisCarter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke LeeCCS 2021 · 17 citations
- Default: Mutual Information-based Crash Triage for Massive CrashesXing Zhang, Jiongyi Chen, Chao Feng, Ruilin Li et al.ICSE 2022 · 5 citations
Related papers
- Benzene: A Practical Root Cause Analysis System with an Under-Constrained State MutationYounggi Park, Hwiwon Lee, Jinho Jung, Hyungjoon Koo et al.S&P 2024 · 11 citations
- AURORA: Statistical Crash Analysis for Automated Root Cause ExplanationTim Blazytko, Moritz Schlögel, Cornelius Aschermann, Ali Abbasi et al.USENIX Security 2020
- KernelRCA: Facilitating Root Cause Analysis of Memory Corruptions in Linux Kernel with Contextual Causality ChainKangzheng Gu, Yifan Zhang, Yuan Zhang, Min YangUSENIX Security 2026
- Igor: Crash Deduplication Through Root-Cause ClusteringZhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang et al.CCS 2021 · 20 citations
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao et al.S&P 2022 · 139 citations
