Lune

USENIX Security2026顶会

TrioFuzz: A Three-Tier Architecture for Adaptive Strategy Selection in Fuzzing

Ruiqi Dong, Yiyi Wang, Kunpeng Zhang, Dongsong Yu, Xiaogang Zhu, Shaohua Wang, Shuai Wang, Chao Zhang, Sheng Wen, Yang Xiang

出版方
2026年份

摘要

Adaptive strategy selection is a promising direction for improving fuzzing effectiveness, yet existing learning-based approaches often fail to outperform random selection in practice. We identify the root cause as an architectural mismatch rather than an algorithmic limitation. Our empirical study reveals that strategy effectiveness shifts at minute-level timescales, while existing in-loop architectures require tens of minutes per learning cycle. This order-of-magnitude gap prevents timely adaptation regardless of which learning algorithm is used.

We propose TRIOFUZZ, a new fuzzing engine that decouples learning from execution through a three-tier thread architecture. A centralized learning thread aggregates feedback from parallel execution threads, compressing the adaptation cycle to under one minute. TRIOFUZZ integrates the same learning algorithms as prior work, isolating the architectural contribution from algorithmic factors. Our ablation study shows that learning algorithms perform significantly better under our proposed architecture than under their original inloop implementations. Notably, native MOpt underperforms baselines, but becomes a competitive performer under TRIO-FUZZ's architecture. Evaluation on FuzzBench and OSS-Fuzz shows that TRIOFUZZ achieves the highest coverage on 7 out of 9 FuzzBench targets and 8 out of 10 OSS-Fuzz projects, triggers 17% more vulnerabilities than AFL++ on Magma, and discovers 19 new CVEs in 6 real-world projects.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper18

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖