StepStone: LLM-Based GPU Kernel Driver Fuzzing via User-Space Libraries
Xiaochen Zou, Juefei Pu, Arrdya Srivastav, Jonathan Cox, Zhengchuan Liang, Yuan Tan, Xingyu Li, Yilin Zhu, Zhiyun Qian
摘要
GPU device driver fuzzing is an underexplored area. GPUs are directly accessible by untrusted users and represent a huge attack surface (e.g., NVIDIA driver has over a million lines of code). While continuous fuzzing has mitigated many kernel bugs within core subsystems, GPU device drivers have not received sufficient attention. SyzDescribe, a state-of-theart tool for generating fuzzing interfaces for device drivers, significantly improves device driver fuzzing, but falls short given the complexity of GPU device drivers.
In this paper, we observed that syscalls are not the only interface one can use to fuzz a device driver. In fact, user-space libraries provide an alternative interface, which can also be utilized for device driver fuzzing. Fuzzing user-space libraries has a number of advantages, such as more functionality-specific and user-friendly APIs, and comprehensive documentation providing valuable information about the API interfaces. To capitalize on this fact, we leverage Large Language Models (LLMs), which are highly effective in understanding and extracting information from both code and natural language (both exist in API documents). Therefore, we introduce Step-Stone, a novel approach that leverages LLMs to generate syzkaller descriptions for GPU libraries (e.g., CUDA, Vulkan), and fuzz these libraries to indirectly fuzz GPU kernel drivers. Our experiments show that StepStone achieves two to four times the level of coverage when compared with SyzDescribe, KernelGPT, and Moneta, when fuzzing NVIDIA, AMD, and Mali GPUs, respectively. Additionally, StepStone uncovered 11 new bugs in NVIDIA kernel drivers, demonstrating its effectiveness and efficiency in GPU driver fuzzing.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper22
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo 等NDSS 2018 · 被引用 311 次
- Large Language Models Are Zero-Shot Fuzzers: Fuzzing Deep-Learning Libraries via Large Language ModelsYinlin Deng, Chunqiu Steven Xia, Haoran Peng, Chenyuan Yang 等ISSTA 2023 · 被引用 253 次
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili 等CCS 2017 · 被引用 195 次
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 被引用 180 次
- Fuzz4All: Universal Fuzzing with Large Language ModelsChunqiu Steven Xia, Matteo Paltenghi, Jia Le Tian, Michael Pradel 等ICSE 2024 · 被引用 155 次
相关 Paper
- Moneta: Ex-Vivo GPU Driver Fuzzing by Recalling In-Vivo Execution StatesJoonkyo Jung, Jisoo Jang, Yongwan Jo, Jonas Vinck 等NDSS 2025
- CuFuzz: An API-Knowledge-Graph Coverage-Driven Fuzzing Framework for CUDA LibrariesXiming Fan, Yong Fang, Peng Jia, Yang Liu 等FSE 2026
- Your Fix Is My Exploit: Enabling Comprehensive DL Library API Fuzzing with Large Language ModelsKunpeng Zhang, Shuai Wang, Jitao Han, Xiaogang Zhu 等ICSE 2025 · 被引用 6 次
- Hunting CUDA Bugs at Scale with cuFuzzMohamed Tarek Ibn Ziad, Christos KozyrakisOOPSLA 2026
- Unlocking Low Frequency Syscalls in Kernel Fuzzing with Dependency-Based RAGZhiyu Zhang, Longxing Li, Ruigang Liang, Kai ChenISSTA 2025 · 被引用 3 次
