Cottontail: Large Language Model-Driven Concolic Execution for Highly Structured Test Input Generation
Haoxin Tu, Seongmin Lee, Yuxian Li, Peng Chen, Lingxiao Jiang, Marcel Böhme
摘要
How can we perform concolic execution to generate highly structured test inputs for systematically testing parsing programs? Existing concolic execution engines are significantly restricted by (1) input structure-agnostic path constraint selection, leading to the waste of testing effort or missing coverage;
(2) limited constraint-solving capability, yielding many syntactically invalid test inputs; (3) reliance on manual acquisition of highly-structured seeds, resulting in non-continuous testing.
This paper proposes COTTONTAIL, a new Large Language Model (LLM)-driven concolic execution engine, to mitigate the above limitations. A more complete program path representation, named Expressive Coverage Tree (ECT), is first constructed to help select structure-aware path constraints. Later, an LLM-driven constraint solver based on a Solve-Complete paradigm is designed to solve the path constraints smartly to get test inputs that are not only satisfiable to the constraints but also valid to the input syntax. Finally, a historyguided seed acquisition is employed to obtain new highly structured test inputs either before testing starts or after testing is saturated. We implemented COTTONTAIL on top of SYMCC and evaluated eight extensively tested open-source libraries across four different formats (XML, SQL, JavaScript, and JSON). The experimental results are promising: COTTONTAIL significantly outperforms baseline approaches by 30.73% and 41.32% on average in terms of line and branch coverage. Besides, COTTONTAIL found six previously unknown vulnerabilities (six CVEs assigned). We have reported these issues to developers, and four out of them have been fixed so far.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Agentic Concolic ExecutionZhengxiong Luo, Huan Zhao, Dylan Wolff, Cristian Cadar 等S&P 2026 · 被引用 17 次
- Agentic Verification of Software SystemsHaoxin Tu, Huan Zhao, Yahui Song, Mehtab Zafar 等FSE 2026 · 被引用 1 次
- Evaluating LLM-Based Regression Test GenerationJing Liu, Seongmin Lee, Eleonora Losiouk, Marcel BöhmeFSE 2026 · 被引用 1 次
- Defusing Logic Bombs in Symbolic Execution with LLM-Generated Ghost CodeDimitrios Stamatios Bouras, Sergey MechtaevISSTA 2026
- State-Aware Fuzzing of JavaScript Engines with LLM-Guided InstrumentationWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Ping Fan Ke 等SOSP 2026
它引用的顶会 Paper39
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma 等NeurIPS 2022 · 被引用 22,562 次
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu 等S&P 2018 · 被引用 426 次
相关 Paper
- Towards Understanding the Effectiveness of Large Language Models on Directed Test Input GenerationZongze Jiang, Ming Wen, Jialun Cao, Xuanhua Shi 等ASE 2024 · 被引用 8 次
- Efficient Directed Hybrid Fuzzing via Target-Centric Seed Selection and GenerationZhen Li, Shenghan Liu, Qiuping Yi, Pengbo Du 等OOPSLA 2026
- Symbolic execution with SymCC: Don't interpret, compile!Sebastian Poeplau, Aurélien FrancillonUSENIX Security 2020
- Quantum Concolic TestingShangzhou Xia, Jianjun Zhao, Fuyuan Zhang, Xiaoyu GuoISSTA 2025 · 被引用 4 次
- ELFuzz: Efficient Input Generation via LLM-driven Synthesis Over Fuzzer SpaceChuyang Chen, Brendan Dolan-Gavitt, Zhiqiang LinUSENIX Security 2025
