Pith. sign in

REVIEW 3 cited by

The Art, Science, and Engineering of Fuzzing: A Survey

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1812.00140 v4 pith:7L35YZ47 submitted 2018-12-01 cs.CR cs.SE

classification cs.CRcs.SE
keywords fuzzingliteratureengineeringmodelsciencesoftwarevastalike
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Among the many software vulnerability discovery techniques available today, fuzzing has remained highly popular due to its conceptual simplicity, its low barrier to deployment, and its vast amount of empirical evidence in discovering real-world software vulnerabilities. At a high level, fuzzing refers to a process of repeatedly running a program with generated inputs that may be syntactically or semantically malformed. While researchers and practitioners alike have invested a large and diverse effort towards improving fuzzing in recent years, this surge of work has also made it difficult to gain a comprehensive and coherent view of fuzzing. To help preserve and bring coherence to the vast literature of fuzzing, this paper presents a unified, general-purpose model of fuzzing together with a taxonomy of the current fuzzing literature. We methodically explore the design decisions at every stage of our model fuzzer by surveying the related literature and innovations in the art, science, and engineering that make modern-day fuzzers effective.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Directed Grammar-Based Test Generation

    cs.SE 2025-08 unverdicted novelty 6.0 of 10

    An iterative, feedback-driven grammar fuzzer, FdLoop, produces inputs aimed at specific goals and outperforms five baselines in most tested settings.

  2. Following Devils' Footprint: Towards Real-time Detection of Price Manipulation Attacks

    cs.CR 2025-02 conditional novelty 6.0 of 10

    SMARTCAT detects price-manipulation attack contracts from bytecode alone, before they execute, by building a token flow graph and matching it against formalized attack patterns.

  3. IoTFuzzSentry: A Protocol Guided Mutation Based Fuzzer for Automatic Vulnerability Testing in Commercial IoT Devices

    cs.CR 2025-09 conditional novelty 4.0 of 10

    A protocol-guided mutation fuzzer reports seven non-crash IoT vulnerabilities in three commercial devices, backed by two CVEs, though live-stream access is inferred from 200 OK responses rather than demonstrated.

Pith tools