Racing on the Negative Force: Efficient Vulnerability Root-Cause Analysis through Reinforcement Learning on Counterexamples
Dandan Xu, Di Tang, Yi Chen, XiaoFeng Wang, Kai Chen, Haixu Tang, Longxing Li
摘要
Root-Cause Analysis (RCA) is crucial for discovering security vulnerabilities from fuzzing outcomes. Automating this process through triaging the crashes observed during the fuzzing process, however, is considered to be challenging. Particularly, today's statistical RCA approaches are known to be exceedingly slow, often taking tens of hours or even a week to analyze a crash. This problem comes from the biased sampling such approaches perform. More specifically, given an input inducing a crash in a program, these approaches sample around the input by mutating it to generate new test cases; these cases are used to fuzz the program, in a hope that a set of program elements (blocks, instructions or predicates) on the execution path of the original input can be adequately sampled so their correlations with the crash can be determined. This process, however, tends to generate the input samples more likely causing the crash, with their execution paths involving a similar set of elements, which become less distinguishable until a large number of samples have been made. We found that this problem can be effectively addressed by sampling around "counterexamples", the inputs causing a significant change to the current estimates of correlations. These inputs though still involving the elements often do not lead to the crash. They are found to be effective in differentiating program elements, thereby accelerating the RCA process. Based upon the understanding, we designed and implemented a reinforcement learning (RL) technique that rewards the operations involving counterexamples. By balancing random sampling with the exploitation on the counterexamples, our new approach, called RACING, is shown to substantially elevate the scalability and the accuracy of today's statistical RCA, outperforming the state-of-the-art by more than an order of magnitude.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- PortGPT: Towards Automated Backporting Using Large Language ModelsZhaoyang Li, Zheng Yu, Jingyi Song, Meng Xu 等S&P 2026 · 被引用 2 次
- Firmrca: Towards Post-Fuzzing Analysis on ARM Embedded Firmware with Efficient Event-Based Fault LocalizationBoyu Chang, Binbin Zhao, Qiao Zhang, Peiyu Liu 等S&P 2025
- TypeForge: Synthesizing and Selecting Best-Fit Composite Data Types for Stripped BinariesYanzhong Wang, Ruigang Liang, Yilin Li, Peiwei Hu 等S&P 2025
- PATCHAGENT: A Practical Program Repair Agent Mimicking Human ExpertiseZheng Yu, Ziyi Guo, Yuhang Wu, Jiahao Yu 等USENIX Security 2025
- Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy InjectionYihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang 等USENIX Security 2026
它引用的顶会 Paper9
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- Postmortem Program Analysis with Hardware-Enhanced Post-Crash ArtifactsJun Xu, Dongliang Mu, Xinyu Xing, Peng Liu 等USENIX Security 2017 · 被引用 55 次
- ARCUS: Symbolic Root Cause Analysis of Exploits in Production SystemsCarter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick 等USENIX Security 2021 · 被引用 42 次
- Automated Bug Hunting With Data-Driven Symbolic Root Cause AnalysisCarter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke LeeCCS 2021 · 被引用 17 次
- Default: Mutual Information-based Crash Triage for Massive CrashesXing Zhang, Jiongyi Chen, Chao Feng, Ruilin Li 等ICSE 2022 · 被引用 5 次
相关 Paper
- Benzene: A Practical Root Cause Analysis System with an Under-Constrained State MutationYounggi Park, Hwiwon Lee, Jinho Jung, Hyungjoon Koo 等S&P 2024 · 被引用 11 次
- AURORA: Statistical Crash Analysis for Automated Root Cause ExplanationTim Blazytko, Moritz Schlögel, Cornelius Aschermann, Ali Abbasi 等USENIX Security 2020
- KernelRCA: Facilitating Root Cause Analysis of Memory Corruptions in Linux Kernel with Contextual Causality ChainKangzheng Gu, Yifan Zhang, Yuan Zhang, Min YangUSENIX Security 2026
- Igor: Crash Deduplication Through Root-Cause ClusteringZhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang 等CCS 2021 · 被引用 20 次
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao 等S&P 2022 · 被引用 139 次
