GUIFuzz++: Unleashing Grey-box Fuzzing on Desktop Graphical User Interfacing Applications
Dillon Otto, Tanner Rowlett, Stefan Nagy
摘要
Desktop applications represent one of today’s largest software ecosystems, accounting for over 96% of workplace computing and supporting essential operations across critical sectors such as healthcare, commerce, industry, and government. Though modern software is increasingly being vetted through fuzzing—an automated testing technique for large-scale bug discovery—a major component of desktop applications remains universally under-vetted: the Graphical User Interface (GUI). Existing desktop-based fuzzers like AFL++ and libFuzzer are limited to non-GUI interfaces (e.g., file- or buffer-based inputs), rendering them wholly incompatible with GUIs. Conversely, mobile app GUI fuzzers like Android’s Monkey and iOS’s XCMonkey rely on platform-specific SDKs and event-handling, rendering them fundamentally unportable to the broader, more complex landscape of desktop software. For these reasons, desktop GUI code remains largely under-tested, burdening users with numerous GUI-induced errors that should, in principle, be just as discoverable as any other well-fuzzed class of software bugs.This paper introduces GUIFuzz++: the first general-purpose fuzzer for desktop GUI software. Unlike desktop fuzzers that randomly mutate file- or buffer-based inputs, GUIFuzz++ exclusively targets GUI interactions—clicks, scrolls, key presses, window navigation, and more—to uncover complex event sequences triggering GUI-induced program errors. Central to our approach is a novel GUI Interaction Interpreter: a middle-layer translating fuzzer-generated random inputs into distinct GUI operations, enabling successful non-GUI fuzzers like AFL++ to be easily ported to testing GUIs. Beyond supporting today’s most popular GUI development frameworks like QT, GTK, and Xorg, we introduce a suite of enhancements capitalizing on ubiquitous Software Accessibility Technologies, significantly boosting GUI fuzzing precision as well as GUI bug-finding effectiveness.We integrate GUIFuzz++ as a prototype atop state-of-the-art GUI-agnostic fuzzer AFL++, and perform a large-scale ablation study of its fundamental components and enhancements. In an evaluation across 12 popular, real-world GUI applications, GUI-FUZZ++ uncovers 23 previously-unknown GUI-induced bugs— with 14 thus far confirmed or fixed by developers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- Nyx-net: network fuzzing with incremental snapshotsSergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi 等EuroSys 2022 · 被引用 76 次
- Profile-guided System Optimizations for Accelerated Greybox FuzzingYunhang Zhang, Chengbin Pang, Stefan Nagy, Xun Chen 等CCS 2023 · 被引用 7 次
- Program Environment FuzzingRuijie Meng, Gregory J. Duck, Abhik RoychoudhuryCCS 2024 · 被引用 6 次
- WINNIE : Fuzzing Windows Applications with Harness Synthesis and Fast CloningJinho Jung, Stephen Tong, Hong Hu, Jungwon Lim 等NDSS 2021
相关 Paper
- Deep GUI: Black-box GUI Input Generation with Deep LearningFaraz Yazdani Banafshe Daragh, Sam MalekASE 2021 · 被引用 29 次
- Sand: Decoupling Sanitization from Fuzzing for Low OverheadZiqiao Kong, Shaohua Li, Heqing Huang, Zhendong SuICSE 2025 · 被引用 1 次
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 被引用 139 次
- FISHFUZZ: Catch Deeper Bugs by Throwing Larger NetsHan Zheng, Jiayuan Zhang, Yuhang Huang, Zezhong Ren 等USENIX Security 2023
- Fully automated functional fuzzing of Android apps for detecting non-crashing logic bugsTing Su, Yichen Yan, Jue Wang, Jingling Sun 等OOPSLA 2021 · 被引用 58 次
