Function Clustering-Based Fuzzing Termination: Toward Smarter Early Stopping
Liang Ding, Wenzhang Yang, Yinxing Xue
Abstract
Fuzzing is a testing technique that generates a large number of inputs to cause program crashes. As software development accelerates and projects scale, the demand for fuzz testing in software assurance has increased. Performing comprehensive fuzz testing on all functions has become increasingly challenging and resource-intensive. Current methods for determining when to stop fuzz testing activities rely on metrics such as function coverage, potential vulnerability function coverage or crash count. However, these metrics fail to account for the scale of the functions under test. For example, function coverage may lead to excessive testing on non-critical functions, while vulnerability function coverage can result in premature termination if the estimated number of vulnerability functions is too low. This paper introduces a novel fuzzing testing termination criterion based on function clustering. We compare our criterion with three existing methods. First, by leveraging language model for function encoding and a multi-metric fusion algorithm for determining the number of clusters, we establish a relationship between function clustering and vulnerability distribution. Second, our experiments on eight function libraries demonstrate that the proposed termination criterion significantly improves testing efficiency, reducing fuzzing time by 1.4-7.2 hours (5-30%) across different configurations while maintaining minimal bug loss (averaging 0.25 bugs), outperforming existing criteria like potential vulnerability function coverage-based approaches.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fba2b118-fd38-42e1-8f64-cd79f251268dBuilds on9
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- On the Reliability of Coverage-Based Fuzzer BenchmarkingMarcel Böhme, László Szekeres, Jonathan MetzmanICSE 2022 · 91 citations
- Fuzzing: on the exponential cost of vulnerability discoveryMarcel Böhme, Brandon FalkFSE 2020 · 66 citations
Related papers
- Green Fuzzing: A Saturation-Based Stopping Criterion using Vulnerability PredictionStephan Lipp, Daniel Elsner, Severin Kacianka, Alexander Pretschner et al.ISSTA 2023 · 6 citations
- Not All Coverage Measurements Are Equal: Fuzzing by Coverage Accounting for Input PrioritizationYanhao Wang, Xiangkun Jia, Yuwei Liu, Kyle Zeng et al.NDSS 2020
- CrFuzz: fuzzing multi-purpose programs through input validationSuhwan Song, Chengyu Song, Yeongjin Jang, Byoungyoung LeeFSE 2020 · 14 citations
- Igor: Crash Deduplication Through Root-Cause ClusteringZhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang et al.CCS 2021 · 20 citations
- Terminator: Enabling Efficient Fuzzing of Closed-Source GUI Programs by Automatic Coverage-Guided TerminationJonas Zabel, Philip Kolvenbach, Steven ArztASE 2025
