Fuzz4All: Universal Fuzzing with Large Language Models
arXiv:2308.04748 · doi:10.1145/3597503.3639121
Abstract
Fuzzing has achieved tremendous success in discovering bugs and vulnerabilities in various software systems. Systems under test (SUTs) that take in programming or formal language as inputs, e.g., compilers, runtime engines, constraint solvers, and software libraries with accessible APIs, are especially important as they are fundamental building blocks of software development. However, existing fuzzers for such systems often target a specific language, and thus cannot be easily applied to other languages or even other versions of the same language. Moreover, the inputs generated by existing fuzzers are often limited to specific features of the input language, and thus can hardly reveal bugs related to other or new features. This paper presents Fuzz4All, the first fuzzer that is universal in the sense that it can target many different input languages and many different features of these languages. The key idea behind Fuzz4All is to leverage large language models (LLMs) as an input generation and mutation engine, which enables the approach to produce diverse and realistic inputs for any practically relevant language. To realize this potential, we present a novel autoprompting technique, which creates LLM prompts that are wellsuited for fuzzing, and a novel LLM-powered fuzzing loop, which iteratively updates the prompt to create new fuzzing inputs. We evaluate Fuzz4All on nine systems under test that take in six different languages (C, C++, Go, SMT2, Java and Python) as inputs. The evaluation shows, across all six languages, that universal fuzzing achieves higher coverage than existing, language-specific fuzzers. Furthermore, Fuzz4All has identified 98 bugs in widely used systems, such as GCC, Clang, Z3, CVC5, OpenJDK, and the Qiskit quantum computing platform, with 64 bugs already confirmed by developers as previously unknown.
Accepted at ICSE 2024
References in corpus (9)
- Training language models to follow instructions with human feedback
- Learning How to Ask: Querying LMs with Mixtures of Soft Prompts
- Open source software in quantum computing
- No More Fine-Tuning? An Experimental Evaluation of Prompt Tuning in Code Intelligence
- NNSmith: Generating Diverse and Valid Test Cases for Deep Learning Compilers
- Bugs in Quantum Computing Platforms: An Empirical Study
- On the Unusual Effectiveness of Type-Aware Operator Mutations for Testing SMT Solvers
- MorphQ: Metamorphic Testing of the Qiskit Quantum Computing Platform
- Code Generation Tools (Almost) for Free? A Study of Few-Shot, Pre-Trained Language Models on Code
Cited by in corpus (13)
- Generative AI for Self-Adaptive Systems: State of the Art and Research Roadmap
- CoverUp: Effective High Coverage Test Generation for Python
- Analyzing Quantum Programs with LintQ: A Static Analysis Framework for Qiskit
- Enhancing Genetic Improvement Mutations Using Large Language Models
- Moderating New Waves of Online Hate with Chain-of-Thought Reasoning in Large Language Models
- ProphetFuzz: Fully Automated Prediction and Fuzzing of High-Risk Option Combinations with Only Documentation via Large Language Model
- Validating Network Protocol Parsers with Traceable RFC Document Interpretation
- ClozeMaster: Fuzzing Rust Compiler by Harnessing LLMs for Infilling Masked Real Programs
- MR-Adopt: Automatic Deduction of Input Transformation Function for Metamorphic Testing
- Mokav: Execution-driven Differential Testing with LLMs
- OOPS: Automated generation of REST API specification via LLMs
- LibLMFuzz: LLM-Augmented Fuzz Target Generation for Black-box Libraries
- On the Mistaken Assumption of Interchangeable Deep Reinforcement Learning Implementations