ConTest: Taming the Cyber-physical Input Space in Fuzz Testing with Control Theory
Jinwen Wang, Hongchao Zhang, Chuanrui Jiang, Andrew Clark, Ning Zhang
Abstract
With the proliferation of Cyber-Physical Systems (CPSs) in daily life, the security of these systems is becoming an pressing problem. Fuzz testing has recently gained attention as a promising approach for automatically detecting vulnerabilities, however, the prohibitively large search space of physical and cyber inputs remains an open research challenge. To address this gap, the paper draws on control theory, leveraging physics-informed control models to guide exploration of the input space. We design and develop ConTest, a fuzzing tool that leverages Lyapunov functions of the control model for both detection and mutation to efficiently search through the parameter space with a provable guarantee on the effectiveness of bug-finding effectiveness under bounded dynamic model errors. We implemented a prototype of ConTest and deployed it to detect spatial and temporal input validation bugs in two representative robotic vehicle (RV) platforms, ArduPilot and PX4. A total of 253 input validation bugs were found, 58 of them being zero-day bugs, and 54 of them were acknowledged by the vendors.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get eca198a7-993d-4808-87fd-19ab623e4e3bRelated papers
- RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided TestingTaegyu Kim, Chung Hwan Kim, Junghwan Rhee, Fan Fei et al.USENIX Security 2019 · 92 citations
- PGFUZZ: Policy-Guided Fuzzing for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Antonio Bianchi, Z. Berkay Celik et al.NDSS 2021
- PatchVerif: Discovering Faulty Patches in Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Z. Berkay Celik, Antonio Bianchi et al.USENIX Security 2023
- Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control SystemsBurak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang et al.S&P 2026 · 3 citations
- IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesSudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon et al.ASE 2025
