SPFuzz: Stateful Path based Parallel Fuzzing for Protocols in Autonomous Vehicles
Junze Yu, Zhengxiong Luo, Fangshangyuan Xia, Yanyang Zhao, Heyuan Shi, Yu Jiang
Abstract
Protocols in autonomous vehicles are essential for efficient invehicle network communication. To ensure their security, many research efforts have been paid to the fuzz testing of their implementations. However, those fuzzing optimizations often struggle to manage the protocols' complex state, resulting in low efficiency in branch covering and vulnerability detection.
This paper introduces SPFuzz, a stateful path based parallel fuzzing framework to improve the testing performance of protocols in autonomous vehicles. The basic idea is to accelerate fuzzing speed by dividing tasks to reduce conflicts and dispatching them on different fuzzing instances. SPFuzz first leverages protocol state and data models to generate stateful paths, then divides them into discrete tasks and dispatches them based on their complexity and diversity, ensuring a balanced workload distribution across all fuzzing instances. For evaluation, we implement SPFuzz on top of the stateof-the-art protocol fuzzer Peach and conduct experiments on four prominent vehicle protocols, including ZMTP, MQTT, DDS, and DoIP. The results show that, compared to the original parallel mode of Peach, SPFuzz achieves the same code coverage at a speed of 2.8X-473.2X, with 5.52% more branch coverage within 24 hours. SPFuzz uncovered six previously unknown vulnerabilities in those protocol implementations, with five CVEs assigned in the national vulnerability database. Additionally, SPFuzz has been adapted to ECUs from several vendors, such as NISSAN, and triggered a total of four vulnerabilities that may cause system crashes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f3282189-0a7a-4c46-89cc-5159341a3145Cited by top-tier papers3
- Logos: Log Guided Fuzzing for Protocol ImplementationsFeifan Wu, Zhengxiong Luo, Yanyang Zhao, Qingpeng Du et al.ISSTA 2024 · 13 citations
- CMFuzz: Parallel Fuzzing of IoT Protocols by Configuration Model Identification and SchedulingQi Xu, Fuchen Ma, Yuanliang Chen, Wanli Chen et al.DAC 2025 · 1 citation
- Protocol Reverse Engineering via Deep Transfer LearningYanyang Zhao, Zhengxiong Luo, Wenlong Zhang, Feifan Wu et al.FSE 2026
Builds on5
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue et al.CCS 2021 · 146 citations
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 139 citations
- ICS Protocol Fuzzing: Coverage Guided Packet Crack and GenerationZhengxiong Luo, Feilong Zuo, Yuheng Shen, Xun Jiao et al.DAC 2020 · 72 citations
- PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous VehiclesFeilong Zuo, Zhengxiong Luo, Junze Yu, Zhe Liu et al.DAC 2021 · 30 citations
- Bleem: Packet Sequence Oriented Fuzzing for Protocol ImplementationsZhengxiong Luo, Junze Yu, Feilong Zuo, Jianzhong Liu et al.USENIX Security 2023
Related papers
- Stateful Greybox FuzzingJinsheng Ba, Marcel Böhme, Zahra Mirzamomen, Abhik RoychoudhuryUSENIX Security 2022
- µFUZZ: Redesign of Parallel Fuzzing using Microservice ArchitectureYongheng Chen, Rui Zhong, Yupeng Yang, Hong Hu et al.USENIX Security 2023
- Camveil: Unveiling Security Camera Vulnerabilities Through Multi-Protocol Coordinated FuzzingFuchen Ma, Yuqiao Yang, Yuanliang Chen, Yanyang Zhao et al.S&P 2026
- 5GC-Fuzz: Finding Deep Stateful Vulnerabilities in 5G Core Network with Black-Box FuzzingYu Sun, Xinyu Liu, Qian Sun, Jiaming Wang et al.INFOCOM 2025 · 5 citations
- SnapFuzz: high-throughput fuzzing of network applicationsAnastasios Andronidis, Cristian CadarISSTA 2022 · 56 citations
