WeSearch

What the hell are we doing?

·8 min read · 0 reactions · 0 comments · 18 views
#fuzzing#research#evaluation#SBFT'25#AFL++#LibAFL#HFuzz#FOX#ZTaint-Havoc#CCS'24#ISSTA'25
⚡ TL;DR · AI summary

The article discusses the stagnation in fuzzing research, suggesting that contributions are often incremental and lack clarity in their utility. It highlights a recent fuzzing competition where two contestants demonstrated different approaches, yet the winner's methods were deemed less technically interesting. The author calls for a reevaluation of how fuzzers are assessed and emphasizes the need for more meaningful metrics in the field.

Key facts
Original article
Addisoncrump
Read full at Addisoncrump →
Opening excerpt (first ~120 words) tap to expand

I have come to realise---or rather, I have become more and more convinced that---fuzzing research has stalled not because we have no further contributions to make, but because the contributions that we are making are either incremental and merely sound impressive or presented in ways that obscure their utility. To be more concrete: we are spending time trying to "improve" fuzzing generally rather than identifying what can be improved; everyone is trying to be "the best" rather than trying to identify what is actually happening. This is not the first time that I have felt this, but perhaps my understanding of this problem has improved in the last two years. It's time for a revisit! Last year, I was involved in a paper which tried to standardise fuzzer evaluation.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Addisoncrump.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Addisoncrump