Variability-Aware Fuzzing
Meah Tahmeed Ahmed, Arnab Dev, Shiyi Wei
Abstract
Modern software systems often provide a vast configuration space to enhance reusability and adaptability, but this configurability also significantly complicates bug finding. While existing static and dynamic variability-aware analysis approaches systematically explore the configuration space, they often suffer from scalability limitations. Conversely, grey-box fuzzing has demonstrated remarkable success in vulnerability detection through lightweight, iterative input space exploration, yet the state-of-the-art configuration fuzzers overlook the potential of integrating variability-aware analysis within the fuzzing process. In this paper, we present VA-Fuzz, a novel variability-aware fuzzer that integrates principled dynamic variability-aware analysis within the fuzzing process to enhance configuration space exploration. VAFuzz introduces new variability-aware seed selection and mutations to drive the fuzzing process. These are enabled by a new presence condition seed queue that tracks coverage and crash contributions across the configuration space, and a map that captures the relationship between data seeds and presence conditions. Our evaluation on a diverse set of programs show that VAFuzz outperforms the state-of-the-art configuration fuzzers on 21 out of 25 programs in terms of code coverage. It also detects more vulnerabilities than these baselines, including previous unknown bugs.
• Software and its engineering → Software testing and debugging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d4115332-9053-4903-8204-fa8f8af17d04Builds on11
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- One Fuzzing Strategy to Rule Them AllMingyuan Wu, Ling Jiang, Jiahong Xiang, Yanwei Huang et al.ICSE 2022 · 64 citations
- Efficient Greybox Fuzzing to Detect Memory ErrorsJinsheng Ba, Gregory J. Duck, Abhik RoychoudhuryASE 2022 · 13 citations
Related papers
- MUZZ: Thread-aware Grey-box Fuzzing for Effective Bug Hunting in Multithreaded ProgramsHongxu Chen, Shengjian Guo, Yinxing Xue, Yulei Sui et al.USENIX Security 2020
- Program Feature-Based Benchmarking for Fuzz TestingMiao Miao, Sriteja Kummita, Eric Bodden, Shiyi WeiISSTA 2025
- An Empirical Examination of Fuzzer Mutator PerformanceJames Kukucka, Luís Pina, Paul Ammann, Jonathan BellISSTA 2024 · 4 citations
- On Understanding and Forecasting Fuzzers Performance with Static AnalysisDongjia Zhang, Andrea Fioraldi, Davide BalzarottiCCS 2024 · 1 citation
- Program Environment FuzzingRuijie Meng, Gregory J. Duck, Abhik RoychoudhuryCCS 2024 · 6 citations
