{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T06:21:30Z","timestamp":1783059690382,"version":"3.54.6"},"reference-count":55,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T00:00:00Z","timestamp":1773705600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T00:00:00Z","timestamp":1773705600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100003395","name":"Shanghai Municipal Education Commission","doi-asserted-by":"publisher","award":["23CGA33"],"award-info":[{"award-number":["23CGA33"]}],"id":[{"id":"10.13039\/501100003395","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,3,17]]},"DOI":"10.1109\/saner67736.2026.00095","type":"proceedings-article","created":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T19:41:17Z","timestamp":1783021277000},"page":"814-825","source":"Crossref","is-referenced-by-count":0,"title":["Understanding the Effectiveness of Mutators in Mutation-Based Protocol Fuzzing"],"prefix":"10.1109","author":[{"given":"Xiyuan","family":"Zhang","sequence":"first","affiliation":[{"name":"East China Normal University,Shanghai Key Laboratory of Trustworthy Computing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiayi","family":"Jiang","sequence":"additional","affiliation":[{"name":"East China Normal University,Shanghai Key Laboratory of Trustworthy Computing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yiutak","family":"Choi","sequence":"additional","affiliation":[{"name":"East China Normal University,Shanghai Key Laboratory of Trustworthy Computing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ting","family":"Su","sequence":"additional","affiliation":[{"name":"East China Normal University,Shanghai Key Laboratory of Trustworthy Computing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haiying","family":"Sun","sequence":"additional","affiliation":[{"name":"East China Normal University,Shanghai Key Laboratory of Trustworthy Computing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chengcheng","family":"Wan","sequence":"additional","affiliation":[{"name":"East China Normal University,Shanghai Key Laboratory of Trustworthy Computing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Geguang","family":"Pu","sequence":"additional","affiliation":[{"name":"East China Normal University,Shanghai Key Laboratory of Trustworthy Computing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/356859.356864"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/IMCEC51613.2021.9482063"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12132904"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45139-0_7"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24556"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3580599"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00095"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3358227"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00066"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484543"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519591"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3192991"},{"key":"ref15","first-page":"19","article-title":"Frankenstein: Advanced wireless fuzzing to exploit new bluetooth escalation targets","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Ruge"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN54977.2022.9868872"},{"key":"ref17","volume-title":"A fuzzing framework which uses a DSL for building fuzzers and an observer based architecture to execute and monitor them","year":"2025"},{"key":"ref18","volume-title":"A fork and successor of the Sulley Fuzzing Framework","year":"2025"},{"key":"ref19","volume-title":"American fuzzy lop (AFL) fuzzer","year":"2025"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2025.3535925"},{"key":"ref21","article-title":"The challenges of fuzzing 5g protocols","author":"Group","year":"2021","journal-title":"5G Secur. Smart Environ."},{"key":"ref22","article-title":"How to hack medical imaging applications via dicom","volume-title":"Hack In The Box Security Conference","author":"Nedyak"},{"key":"ref23","volume-title":"Demystifying a current trend - security fuzz testing in the context of iso\/sae 21434","year":"2025"},{"key":"ref24","volume-title":"A use-after-free vulnerability discovered by aflnet","year":"2025"},{"key":"ref25","volume-title":"A critical memory (heap) leak vulnerability discovered by aflnet","year":"2025"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534376"},{"key":"ref27","article-title":"A survey of network protocol fuzzing: Model, techniques and directions","author":"Jiang","year":"2024","journal-title":"arXiv preprint"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3696788"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3469077"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10233-3"},{"key":"ref31","volume-title":"A robust, commercial-grade, full-featured Open Source Toolkit for the TLS (formerly SSL), DTLS and QUIC protocols","year":"2025"},{"key":"ref32","volume-title":"A complete RTSP server application","year":"2025"},{"key":"ref33","volume-title":"A library for Datagram Transport Layer Security (DTLS) covering both the client and the server state machine","year":"2025"},{"key":"ref34","first-page":"3255","article-title":"Stateful greybox fuzzing","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Ba","year":"2022"},{"key":"ref35","volume-title":"A library for coverage-guided fuzz testing","year":"2025"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.39"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427662"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978411"},{"key":"ref39","first-page":"911","article-title":"SweynTooth: Unleashing mayhem over bluetooth low energy","volume-title":"2020 USENIX Annual Technical Conference (USENIX ATC 20)","author":"Garbelini"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3014624"},{"key":"ref41","first-page":"1025","article-title":"BrakTooth: Causing havoc on bluetooth link manager via directed fuzzing","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Garbelini"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23068"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3680387"},{"key":"ref44","article-title":"AFL++: Combining incremental steps of fuzzing research","volume-title":"14th USENIX Workshop on Offensive Technologies (WOOT 20)","author":"Fioraldi","year":"2020"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3428334"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510174"},{"key":"ref47","first-page":"1949","article-title":"\\{MOPT\\}: Optimized mutation scheduling for fuzzers","volume-title":"28th USENIX security symposium (USENIX security 19)","author":"Lyu","year":"2019"},{"key":"ref48","first-page":"4481","article-title":"Bleem: Packet sequence oriented fuzzing for protocol implementations","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Luo","year":"2023"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2022.23008"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586321"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218603"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104621"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104581"},{"key":"ref54","volume-title":"A stateless coverage-guided fuzzer","year":"2025"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SANER53432.2022.00089"}],"event":{"name":"2026 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)","location":"Limassol, Cyprus","start":{"date-parts":[[2026,3,17]]},"end":{"date-parts":[[2026,3,20]]}},"container-title":["2026 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11576582\/11576527\/11576685.pdf?arnumber=11576685","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T05:42:51Z","timestamp":1783057371000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11576685\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,17]]},"references-count":55,"URL":"https:\/\/doi.org\/10.1109\/saner67736.2026.00095","relation":{},"subject":[],"published":{"date-parts":[[2026,3,17]]}}}