StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries
Xiaochen Zou, Juefei Pu, Arrdya Srivastav, Jonathan Cox, Zhengchuan Liang, Yuan Tan, Xingyu Li, Yilin Zhu, Zhiyun Qian
Abstract
GPU device driver fuzzing is an underexplored area. GPUs are directly accessible by untrusted users and represent a huge attack surface (e.g., NVIDIA driver has over a million lines of code). While continuous fuzzing has mitigated many kernel bugs within core subsystems, GPU device drivers have not received sufficient attention. SyzDescribe, a state-of-theart tool for generating fuzzing interfaces for device drivers, significantly improves device driver fuzzing, but falls short given the complexity of GPU device drivers.
In this paper, we observed that syscalls are not the only interface one can use to fuzz a device driver. In fact, user-space libraries provide an alternative interface, which can also be utilized for device driver fuzzing. Fuzzing user-space libraries has a number of advantages, such as more functionality-specific and user-friendly APIs, and comprehensive documentation providing valuable information about the API interfaces. To capitalize on this fact, we leverage Large Language Models (LLMs), which are highly effective in understanding and extracting information from both code and natural language (both exist in API documents). Therefore, we introduce Step-Stone, a novel approach that leverages LLMs to generate syzkaller descriptions for GPU libraries (e.g., CUDA, Vulkan), and fuzz these libraries to indirectly fuzz GPU kernel drivers. Our experiments show that StepStone achieves two to four times the level of coverage when compared with SyzDescribe, KernelGPT, and Moneta, when fuzzing NVIDIA, AMD, and Mali GPUs, respectively. Additionally, StepStone uncovered 11 new bugs in NVIDIA kernel drivers, demonstrating its effectiveness and efficiency in GPU driver fuzzing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d7740b7b-c7fa-4d48-b3c3-bb270a086445Builds on22
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- Large Language Models Are Zero-Shot Fuzzers: Fuzzing Deep-Learning Libraries via Large Language ModelsYinlin Deng, Chunqiu Steven Xia, Haoran Peng, Chenyuan Yang et al.ISSTA 2023 · 253 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 180 citations
- Fuzz4All: Universal Fuzzing with Large Language ModelsChunqiu Steven Xia, Matteo Paltenghi, Jia Le Tian, Michael Pradel et al.ICSE 2024 · 155 citations
Related papers
- Moneta: Ex-Vivo GPU Driver Fuzzing by Recalling In-Vivo Execution StatesJoonkyo Jung, Jisoo Jang, Yongwan Jo, Jonas Vinck et al.NDSS 2025
- CuFuzz: An API-Knowledge-Graph Coverage-Driven Fuzzing Framework for CUDA LibrariesXiming Fan, Yong Fang, Peng Jia, Yang Liu et al.FSE 2026
- Your Fix Is My Exploit: Enabling Comprehensive DL Library API Fuzzing with Large Language ModelsKunpeng Zhang, Shuai Wang, Jitao Han, Xiaogang Zhu et al.ICSE 2025 · 6 citations
- Hunting CUDA Bugs at Scale with cuFuzzMohamed Tarek Ibn Ziad, Christos KozyrakisOOPSLA 2026
- Unlocking Low Frequency Syscalls in Kernel Fuzzing with Dependency-Based RAGZhiyu Zhang, Longxing Li, Ruigang Liang, Kai ChenISSTA 2025 · 3 citations
