{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T23:41:49Z","timestamp":1773186109526,"version":"3.50.1"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T00:00:00Z","timestamp":1773100800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T00:00:00Z","timestamp":1773100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Tianshui City Natural Science Foundation","award":["2025-FZGHK-4856"],"award-info":[{"award-number":["2025-FZGHK-4856"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"DOI":"10.1007\/s11416-026-00610-7","type":"journal-article","created":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T04:25:15Z","timestamp":1773116715000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Towards high-coverage web fuzzing: a framework integrating hybrid semantic modeling and online adaptive optimization"],"prefix":"10.1007","volume":"22","author":[{"given":"Zihao","family":"Zhou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaibin","family":"Wei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"LingJie","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiannian","family":"Xie","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,3,10]]},"reference":[{"issue":"8","key":"610_CR1","doi-asserted-by":"publisher","first-page":"877","DOI":"10.1007\/s11227-025-07371-y","volume":"81","author":"A Touqir","year":"2025","unstructured":"Touqir, A., Iradat, F., Iqbal, W., Rakib, A., Taskin, N., Jadidbonab, H., Haas, O.: Systematic exploration of fuzzing in iot: techniques, vulnerabilities, and open challenges: A. touqir et al. J. Supercomput. 81(8), 877 (2025)","journal-title":"J. Supercomput."},{"issue":"22","key":"610_CR2","doi-asserted-by":"publisher","first-page":"4449","DOI":"10.3390\/electronics14224449","volume":"14","author":"SMS Hossain","year":"2025","unstructured":"Hossain, S.M.S., Shapna, A.M.: Modern approaches to software vulnerability detection: A survey of machine learning, deep learning, and large language models. Electronics 14(22), 4449 (2025)","journal-title":"Electronics"},{"key":"610_CR3","unstructured":"Nascimento, N.: Safeguard analyzer: A fuzz testing tool. Master\u2019s thesis, Universidade do Porto (Portugal) (2024)"},{"key":"610_CR4","unstructured":"Baiget, A.: Explainfuzz: Explainable and wellformed test generation with probabilistic circuits. Master\u2019s thesis, University of California, Los Angeles (2025)"},{"key":"610_CR5","unstructured":"Yang, Y., Wang, L., Zhang, J., Liu, C.H., Hong, L., Xu, Q.: Multi-faceted attack: Exposing cross-model vulnerabilities in defense-equipped vision-language models. arXiv preprint arXiv:2511.16110 (2025)"},{"key":"610_CR6","doi-asserted-by":"publisher","first-page":"29175","DOI":"10.1109\/ACCESS.2024.3369613","volume":"12","author":"J Yang","year":"2024","unstructured":"Yang, J., Arya, S., Wang, Y.: Formal-guided fuzz testing: Targeting security assurance from specification to implementation for 5g and beyond. IEEE Access 12, 29175\u201329193 (2024)","journal-title":"IEEE Access"},{"key":"610_CR7","unstructured":"Sakpal, S.: Application of fuzz testing for testing highly configurable systems. PhD thesis, University of Stuttgart (2024)"},{"key":"610_CR8","doi-asserted-by":"crossref","unstructured":"Coppoletta, G.: Ocppstorm: A comprehensive fuzzing tool for ocpp implementations. Master\u2019s thesis, University of Illinois at Chicago (2024)","DOI":"10.14722\/vehiclesec.2024.23069"},{"key":"610_CR9","unstructured":"Ahmed, D.: An artificial intelligence model for the exploitation of sql injection vulnerabilities in web applications. PhD thesis, The George Washington University (2025)"},{"issue":"2","key":"610_CR10","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/s10207-025-00992-7","volume":"24","author":"SM Taghavi Far","year":"2025","unstructured":"Taghavi Far, S.M., Feyzi, F.: Large language models for software vulnerability detection: a guide for researchers on models, methods, techniques, datasets, and metrics. Int. J. Inf. Secur. 24(2), 78 (2025)","journal-title":"Int. J. Inf. Secur."},{"key":"610_CR11","doi-asserted-by":"crossref","unstructured":"Ding, Y., Fu, Y., Ibrahim, O., Sitawarin, C., Chen, X., Alomair, B., Wagner, D., Ray, B., Chen, Y.: Vulnerability detection with code language models: How far are we? arXiv preprint arXiv:2403.18624 (2024)","DOI":"10.1109\/ICSE55347.2025.00038"},{"issue":"5","key":"610_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3708522","volume":"34","author":"X Zhou","year":"2025","unstructured":"Zhou, X., Cao, S., Sun, X., Lo, D.: Large language model for vulnerability detection and repair: Literature review and the road ahead. ACM Transactions on Software Engineering and Methodology 34(5), 1\u201331 (2025)","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"610_CR13","doi-asserted-by":"crossref","unstructured":"Dived, N., Bernard, N., Rhodes, C., McKinney, J.: An automated recursive token-level security fuzzing test for large language models (2024)","DOI":"10.22541\/au.172556921.12877160\/v1"},{"key":"610_CR14","doi-asserted-by":"crossref","unstructured":"Farras, N.S.M., Loderick, J., Saputri, H.A., Sari, A.C.: Exploring penetration testing: A comparative analysis of brute force directory tools in vulnerability analysis phase. In: 2024 2nd International Conference on Technology Innovation and Its Applications (ICTIIA), pp. 1\u20136 (2024). IEEE","DOI":"10.1109\/ICTIIA61827.2024.10761451"},{"key":"610_CR15","unstructured":"Nandi, S.: Evaluating the effectiveness of security testing tools in automated testing (2024)"},{"issue":"3","key":"610_CR16","doi-asserted-by":"publisher","first-page":"536","DOI":"10.35377\/saucis.8.94717.1711704","volume":"8","author":"\u015e Kara","year":"2025","unstructured":"Kara, \u015e, \u0130lkbahar, F., G\u00fcnd\u00fcz, M.Z.: Ai-powered vulnerability detection and adaptive defense strategies in cybersecurity. Sakarya University Journal of Computer and Information Sciences 8(3), 536\u2013552 (2025)","journal-title":"Sakarya University Journal of Computer and Information Sciences"},{"key":"610_CR17","doi-asserted-by":"crossref","unstructured":"Chen, X., Liu, J., Zhang, Y., Hu, Q., Han, Y., Zhang, R., Ran, J., Yan, L., Huang, B., Ma, S., et al.: Webfuzzauto: An automated fuzz testing tool integrating reinforcement learning and large language models for web security. In: 2024 12th International Conference on Information Systems and Computing Technology (ISCTech), pp. 1\u201310 (2024). IEEE","DOI":"10.1109\/ISCTech63666.2024.10845318"},{"key":"610_CR18","doi-asserted-by":"crossref","unstructured":"Zhang, C., Zheng, Y., Bai, M., Li, Y., Ma, W., Xie, X., Li, Y., Sun, L., Liu, Y.: How effective are they? exploring large language model based fuzz driver generation. In: Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 1223\u20131235 (2024)","DOI":"10.1145\/3650212.3680355"},{"key":"610_CR19","doi-asserted-by":"crossref","unstructured":"Sun, Y.: Automated generation and compilation of fuzz driver based on large language models. In: Proceedings of the 2024 9th International Conference on Cyber Security and Information Engineering, pp. 461\u2013468 (2024)","DOI":"10.1145\/3689236.3689272"},{"issue":"1","key":"610_CR20","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1007\/s10515-024-00483-4","volume":"32","author":"J Sun","year":"2025","unstructured":"Sun, J., Yin, Z., Zhang, H., Chen, X., Zheng, W.: Adversarial generation method for smart contract fuzz testing seeds guided by chain-based llm. Autom. Softw. Eng. 32(1), 12 (2025)","journal-title":"Autom. Softw. Eng."},{"key":"610_CR21","unstructured":"Yu, J., Shao, Y., Miao, H., Shi, J.: Promptfuzz: Harnessing fuzzing techniques for robust testing of prompt injection in llms. arXiv preprint arXiv:2409.14729 (2024)"},{"key":"610_CR22","unstructured":"Kim, T., Han, H., Park, S., Jeong, D.R., Kim, D., Kim, D., Kim, E., Kim, J., Wang, J., Kim, K., et al.: Atlantis: Ai-driven threat localization, analysis, and triage intelligence system. arXiv preprint arXiv:2509.14589 (2025)"},{"key":"610_CR23","doi-asserted-by":"publisher","first-page":"129064","DOI":"10.1109\/ACCESS.2024.3421989","volume":"12","author":"V-H Pham","year":"2024","unstructured":"Pham, V.-H., Chuong, N.P., Thai, P.T., Duy, P.T., et al.: A coverage-guided fuzzing method for automatic software vulnerability detection using reinforcement learning-enabled multi-level input mutation. IEEE Access 12, 129064\u2013129080 (2024)","journal-title":"IEEE Access"},{"key":"610_CR24","doi-asserted-by":"crossref","unstructured":"Kathiresan, G.: Next-gen mutation testing: Using ai and fuzzing to evolve fault injection for modern software. Available at SSRN 5241045 (2025)","DOI":"10.2139\/ssrn.5241045"},{"key":"610_CR25","unstructured":"Mao, E., Li, D., Yan, X.: Wafuzz: A fuzz-based waf protection function testing technology. In: International Conference on Machine Learning and Intelligent Computing, pp. 560\u2013572 (2025). PMLR"},{"key":"610_CR26","doi-asserted-by":"crossref","unstructured":"Wang, Q., Chen, J., Jiang, Z., Guo, R., Liu, X., Zhang, C., Duan, H.: Break the wall from bottom: Automated discovery of protocol-level evasion vulnerabilities in web application firewalls. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 185\u2013202 (2024). IEEE","DOI":"10.1109\/SP54263.2024.00129"},{"key":"610_CR27","unstructured":"Toledo, H.V.d., Oliveira, D.A.d.: Wafamole++: um fuzzer mutacional para inje\u00e7\u00f5es sql (2022)"},{"key":"610_CR28","unstructured":"Eberhardt, M., Karlsson, L.: Protocol fuzzing-a comparison between llm-assisted and mutation-based fuzzers (2025)"},{"issue":"8","key":"610_CR29","doi-asserted-by":"publisher","first-page":"0237749","DOI":"10.1371\/journal.pone.0237749","volume":"15","author":"Y Wang","year":"2020","unstructured":"Wang, Y., Jia, P., Liu, L., Huang, C., Liu, Z.: A systematic review of fuzzing based on machine learning techniques. PLoS ONE 15(8), 0237749 (2020)","journal-title":"PLoS ONE"},{"issue":"2","key":"610_CR30","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/s10207-024-00979-w","volume":"24","author":"IPA Dharmaadi","year":"2025","unstructured":"Dharmaadi, I.P.A., Athanasopoulos, E., Turkmen, F.: Fuzzing frameworks for server-side web applications: a survey. Int. J. Inf. Secur. 24(2), 73 (2025)","journal-title":"Int. J. Inf. Secur."},{"key":"610_CR31","doi-asserted-by":"crossref","unstructured":"Yu, Z., Liu, Z., Cong, X., Li, X., Yin, L.: Fuzzing: Progress, challenges, and perspectives. Computers, Materials & Continua 78(1) (2024)","DOI":"10.32604\/cmc.2023.042361"},{"key":"610_CR32","doi-asserted-by":"crossref","unstructured":"Godefroid, P., Peleg, H., Singh, R.: Learn&fuzz: Machine learning for input fuzzing. In: 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE), pp. 50\u201359 (2017). IEEE","DOI":"10.1109\/ASE.2017.8115618"},{"key":"610_CR33","doi-asserted-by":"crossref","unstructured":"Masud, M.T., Koroniotis, N., Keshk, M., Turnbull, B., Kermanshahi, S.K., Moustafa, N.: Generative fuzzer-driven vulnerability detection in the internet of things networks. Appl. Soft Comput. 174, 112973 (2025)","DOI":"10.1016\/j.asoc.2025.112973"},{"key":"610_CR34","unstructured":"Sablotny, M., Jensen, B.S., Singer, J.: Reinforcement learning guided fuzz testing for a browser\u2019s html rendering engine. arXiv preprint arXiv:2307.14556 (2023)"},{"key":"610_CR35","doi-asserted-by":"crossref","unstructured":"Huang, L., Zhao, P., Ma, L., Chen, H.: On the challenges of fuzzing techniques via large language models. In: 2025 IEEE International Conference on Software Services Engineering (SSE), pp. 162\u2013171 (2025). IEEE","DOI":"10.1109\/SSE67621.2025.00028"},{"key":"610_CR36","unstructured":"Dharmaadi, I., Alhanahnah, M., Pham, V.-T., Mohsen, F., Turkmen, F.: Bacfuzz: Exposing the silence on broken access control vulnerabilities in web applications. arXiv preprint arXiv:2507.15984 (2025)"},{"key":"610_CR37","doi-asserted-by":"crossref","unstructured":"Deng, Y., Xia, C.S., Peng, H., Yang, C., Zhang, L.: Large language models are zero-shot fuzzers: Fuzzing deep-learning libraries via large language models. In: Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 423\u2013435 (2023)","DOI":"10.1145\/3597926.3598067"},{"key":"610_CR38","doi-asserted-by":"crossref","unstructured":"Hatfield-Dodds, Z., Dygalo, D.: Deriving semantics-aware fuzzers from web api schemas. In: Proceedings of the ACM\/IEEE 44th International Conference on Software Engineering: Companion Proceedings, pp. 345\u2013346 (2022)","DOI":"10.1145\/3510454.3528637"},{"key":"610_CR39","doi-asserted-by":"crossref","unstructured":"Yang, C., Deng, Y., Yao, J., Tu, Y., Li, H., Zhang, L.: Fuzzing automatic differentiation in deep-learning libraries. In: 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE), pp. 1174\u20131186 (2023). IEEE","DOI":"10.1109\/ICSE48619.2023.00105"},{"key":"610_CR40","doi-asserted-by":"crossref","unstructured":"Lyu, Y., Xie, Y., Chen, P., Chen, H.: Prompt fuzzing for fuzz driver generation. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pp. 3793\u20133807 (2024)","DOI":"10.1145\/3658644.3670396"},{"key":"610_CR41","doi-asserted-by":"crossref","unstructured":"She, D., Storek, A., Xie, Y., Kweon, S., Srivastava, P., Jana, S.: Fox: Coverage-guided fuzzing as online stochastic control. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pp. 765\u2013779 (2024)","DOI":"10.1145\/3658644.3670362"},{"key":"610_CR42","unstructured":"Wang, M., Liang, J., Zhou, C., Wu, Z., Fu, J., Su, Z., Liao, Q., Gu, B., Wu, B., Jiang, Y.: Data coverage for guided fuzzing. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 2511\u20132526 (2024)"},{"key":"610_CR43","doi-asserted-by":"crossref","unstructured":"Neef, S., Kleissner, L., Seifert, J.-P.: What all the phuzz is about: A coverage-guided fuzzer for finding vulnerabilities in php web applications. In: Proceedings of the 19th ACM Asia Conference on Computer and Communications Security, pp. 1523\u20131538 (2024)","DOI":"10.1145\/3634737.3661137"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-026-00610-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11416-026-00610-7","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-026-00610-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T04:25:27Z","timestamp":1773116727000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11416-026-00610-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,10]]},"references-count":43,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["610"],"URL":"https:\/\/doi.org\/10.1007\/s11416-026-00610-7","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,10]]},"assertion":[{"value":"13 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 February 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"25"}}