1
Return

Directed fuzzing with variable state diversity

delete2026-06-18
delete0
PRE
AI
Z
Ziyuan Wang *
Y
Yuhang Chen
S
Shule Ma
K
Ke Ding
W
Weifeng Zhang *
DOI:10.1016/j.jss.2026.113008delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Directed greybox fuzzing has become a prominent technique for targeted vulnerability detection by focusing computational resources on specific code locations. However, existing approaches primarily rely on control-flow information while neglecting the critical role of program data states in triggering vulnerabilities. Many security bugs require specific variable value combinations to manifest, which purely coverage-driven approaches may fail to expose efficiently. This paper presents VSDFuzz, a novel directed fuzzing method guided by variable state diversity that integrates fine-grained data-state awareness into the fuzzing process. VSDFuzz employs multi-strategy variable identification to locate key variables related to target locations, instruments programs to monitor runtime states with type-specific handling, and uses variable state diversity as additional feedback for seed selection and energy allocation. An adaptive weight adjustment mechanism dynamically balances coverage-based and state-based guidance throughout the campaign. We implemented VSDFuzz as an extension of AFLGo and evaluated it against state-of-the-art fuzzers on ten real-world programs containing known vulnerabilities. In 10 experiments each lasting 12 h across 10 real-world programs, VSDFuzz demonstrated a 21.5% increase in unique path discovery compared to AFLGo, outperforming DiPri’s 9.1% and SDFuzz’s 13.5%. In terms of code coverage, VSDFuzz achieved an 18.8% improvement over AFLGo, outperforming DiPri’s 6.8% and SDFuzz’s 12.4%. In vulnerability detection, VSDFuzz triggered 19 out of 20 CVE vulnerabilities, outperforming AFLGo (9), DiPri (13), and SDFuzz (16), fully demonstrating the value of variable state diversity guidance in detecting deep-level vulnerabilities.

Journal

Journal of Systems and Software cover
Journal of Systems and Software
IF:
4.1
Papers:
5.4K
Citations:
8.4K

Organization

No organization information available
Cited Papers

Cited Papers

Citing Papers

Citing Papers