{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,29]],"date-time":"2026-01-29T20:04:15Z","timestamp":1769717055884,"version":"3.49.0"},"reference-count":80,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,11,16]],"date-time":"2025-11-16T00:00:00Z","timestamp":1763251200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,16]],"date-time":"2025-11-16T00:00:00Z","timestamp":1763251200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,11,16]]},"DOI":"10.1109\/ase63991.2025.00224","type":"proceedings-article","created":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T20:54:38Z","timestamp":1769633678000},"page":"2733-2745","source":"Crossref","is-referenced-by-count":0,"title":["Tephra: Principled Discovery of Fuzzer Limitations"],"prefix":"10.1109","author":[{"given":"Vasil","family":"Sarafov","sequence":"first","affiliation":[{"name":"Universit&#x00E4;t der Bundeswehr M&#x00FC;nchen,&#x03BC;CSRL &#x2014; CODE Research Institute,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Markvica","sequence":"additional","affiliation":[{"name":"Universit&#x00E4;t der Bundeswehr M&#x00FC;nchen,&#x03BC;CSRL &#x2014; CODE Research Institute,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan","family":"Brunthaler","sequence":"additional","affiliation":[{"name":"Universit&#x00E4;t der Bundeswehr M&#x00FC;nchen,&#x03BC;CSRL &#x2014; CODE Research Institute,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978428"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.2307\/1990888"},{"key":"ref4","volume-title":"Principles of abstract interpretation","author":"Cousout","year":"2021"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/512950.512973"},{"key":"ref6","volume-title":"Principles of model checking","author":"Baier","year":"2008"},{"key":"ref7","doi-asserted-by":"crossref","DOI":"10.1007\/3-540-45949-9","volume-title":"Isabelle\/HOL: a proof assistant for higher-order logic","author":"Nipkow","year":"2002"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3473932"},{"key":"ref9","article-title":"Imagemagick"},{"key":"ref10","volume-title":"OSS-Fuzz - google\u2019s continuous fuzzing service for open source software","author":"Serebryany","year":"2017"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00117"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.15"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3428334"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-023-10430-8"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3556908"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00056"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1993498.1993532"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3624007.3624056"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690229"},{"key":"ref20","volume-title":"American fuzzy lop-whitepaper","author":"Zalewski","year":"2015"},{"key":"ref21","article-title":"AFL++: Combining incremental steps of fuzzing research","volume-title":"14th USENIX Workshop on Offensive Technologies (WOOT 20)","author":"Fioraldi"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23371"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-37963-5_96"},{"key":"ref24","volume-title":"LAF-INTEL: Circumventing Fuzzing Roadblocks with Compiler Transformations","author":"Authors","year":"2016"},{"key":"ref25","first-page":"1949","article-title":"MOPT: Optimized mutation scheduling for fuzzers","volume-title":"Proceedings of the 28th USENIX Security Symposium","author":"Lyu"},{"key":"ref26","article-title":"Compare coverage for AFL++ QEMU","author":"Fioraldi","year":"2019"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00046"},{"key":"ref29","article-title":"DARWIN: survival of the fittest fuzzing mutators","volume-title":"CoRR","author":"Jauernig","year":"2022"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3587159"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00026"},{"key":"ref32","first-page":"2307","article-title":"EcoFuzz: Adaptive Energy-Saving greybox fuzzing as a variant of the adversarial Multi-Armed bandit","volume-title":"Proceedings of the 29th USENIX Security Symposium","author":"Yue"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2023.3326144"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238176"},{"key":"ref35","article-title":"Honggfuzz","author":"Swiecki","year":"2016"},{"key":"ref36","first-page":"209","article-title":"Klee: unassisted and automatic generation of high-coverage tests for complex systems programs","volume-title":"Proceedings of the 8th USENIX Conference on Operating Systems Design and Implementation","author":"Cadar"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560602"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SBFT59156.2023.00021"},{"key":"ref39","article-title":"libfuzzer \u2013 a library for coverage-guided fuzz testing","author":"Serebryany","year":"2015"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409748"},{"key":"ref41","article-title":"Radamsa: A general-purpose fuzzer","author":"Helin","year":"2016"},{"key":"ref42","first-page":"181","article-title":"Symbolic execution with SymCC: Don\u2019t interpret, compile!","volume-title":"Proceedings of the 29th USENIX Security Symposium","author":"Poeplau"},{"key":"ref43","first-page":"2511","article-title":"Data coverage for guided fuzzing","volume-title":"Proceedings of the 33rd USENIX Security Symposium","author":"Wang"},{"key":"ref44","first-page":"479","article-title":"WingFuzz: Implementing continuous fuzzing for DBMSs","volume-title":"2024 USENIX Annual Technical Conference (USENIX ATC 24)","author":"Liang"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3582813"},{"key":"ref46","first-page":"1343","article-title":"{FISHFUZZ}: Catch deeper bugs by throwing larger nets","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"Zheng"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670362"},{"key":"ref48","first-page":"4931","article-title":"DAFL: Directed grey-box fuzzing guided by data dependency","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"Kim"},{"key":"ref49","first-page":"1967","article-title":"Enfuzz: ensemble fuzzing with seed synchronization among diverse fuzzers","volume-title":"Proceedings of the 28th USENIX Security Symposium","author":"Chen"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00137"},{"key":"ref52","first-page":"2777","article-title":"UNIFUZZ: A holistic and pragmatic Metrics-Driven platform for evaluating fuzzers","volume-title":"Proceedings of the 30th USENIX Security Symposium","author":"Li"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/C-M.1978.218136"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.62"},{"key":"ref55","first-page":"4535","article-title":"Systematic assessment of fuzzers using mutation analysis","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"G\u00f6rz"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3503222.3507764"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3178372.3179521"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3446804.3446849"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3605157.3605177"},{"key":"ref60","article-title":"Introducing fuzz introspector, an openssf tool to improve fuzzing coverage","author":"Chang","year":"2022"},{"key":"ref61","first-page":"319","article-title":"Interrogation testing of program analyzers for soundness and precision issues","volume-title":"Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering","author":"Kaindlstorfer"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3368826.3377927"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338932"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.30420\/566438006"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409763"},{"key":"ref66","first-page":"344","article-title":"Constraint-based test oracles for program analyzers","volume-title":"Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering","author":"Fleischmann"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28891-3_12"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884879"},{"key":"ref69","article-title":"Juliet c\/c++ test suite","year":"2017"},{"key":"ref70","article-title":"Bugbench: Benchmarks for evaluating bug detection tools","volume-title":"Workshop on the evaluation of software defect detection tools","volume":"5","author":"Lu"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/1555860.1555866"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534380"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3340456"},{"key":"ref74","first-page":"2271","article-title":"FuzzGen: Automatic fuzzer generation","volume-title":"Proceedings of the 29th USENIX Security Symposium","author":"Ispoglou"},{"key":"ref75","article-title":"Anti-fuzzing","author":"Miller","year":"2010"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545981"},{"key":"ref77","article-title":"Escaping the fuzz - evaluating fuzzing techniques and fooling them with anti-fuzzing","volume-title":"Master\u2019s thesis","author":"Edholm","year":"2016"},{"key":"ref78","first-page":"1931","article-title":"AntiFuzz: Impeding fuzzing audits of binary executables","volume-title":"Proceedings of the 28th USENIX Security Symposium","author":"G\u00fcler"},{"key":"ref79","first-page":"1913","article-title":"Fuzzification: Anti-fuzzing techniques","volume-title":"Proceedings of the 28th USENIX Security Symposium","author":"Jung"},{"key":"ref80","article-title":"Introduction to anti-fuzzing: A defence in depth aid","author":"Whitehouse","year":"2014"}],"event":{"name":"2025 40th IEEE\/ACM International Conference on Automated Software Engineering (ASE)","location":"Seoul, Korea, Republic of","start":{"date-parts":[[2025,11,16]]},"end":{"date-parts":[[2025,11,20]]}},"container-title":["2025 40th IEEE\/ACM International Conference on Automated Software Engineering (ASE)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11334056\/11334198\/11334676.pdf?arnumber=11334676","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,29]],"date-time":"2026-01-29T09:21:22Z","timestamp":1769678482000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11334676\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,16]]},"references-count":80,"URL":"https:\/\/doi.org\/10.1109\/ase63991.2025.00224","relation":{},"subject":[],"published":{"date-parts":[[2025,11,16]]}}}