Return
From coverage to causes: Data-centric fuzzing for Javascript engines
K
T
DOI:10.1016/j.infsof.2026.108211.png)
Abstract
En 中文
Exhaustive fuzzing of modern JavaScript engines is infeasible due to the vast number of program states and execution paths. Coverage-guided fuzzers rely on coverage as a proxy for progress, but many vulnerability-triggering inputs that do not increase coverage are discarded. Since fuzzing is expensive and crashes are rare in mature engines, relying on brute-force exploration wastes substantial effort. Existing heuristics proposed to mitigate this require expert effort, are brittle, and hard to adapt.
Journal
IF:
4.3
Papers:
3.7K
Citations:
7.7K
Organization
No organization information available
