{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:33:57Z","timestamp":1784302437786,"version":"3.55.0"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2023,3,29]],"date-time":"2023-03-29T00:00:00Z","timestamp":1680048000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"crossref","award":["FA875019C0003"],"award-info":[{"award-number":["FA875019C0003"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2023,4,30]]},"abstract":"<jats:p>AFL is one of the most used and extended fuzzers, adopted by industry and academic researchers alike. Although the community agrees on AFL\u2019s effectiveness at discovering new vulnerabilities and its outstanding usability, many of its internal design choices remain untested to date. Security practitioners often clone the project \u201cas-is\u201d and use it as a starting point to develop new techniques, usually taking everything under the hood for granted. Instead, we believe that a careful analysis of the different parameters could help modern fuzzers improve their performance and explain how each choice can affect the outcome of security testing, either negatively or positively.<\/jats:p>\n          <jats:p>The goal of this work is to provide a comprehensive understanding of the internal mechanisms of AFL by performing experiments and by comparing different metrics used to evaluate fuzzers. This can help to show the effectiveness of some techniques and to clarify which aspects are instead outdated. To perform our study, we performed nine unique experiments that we carried out on the popular Fuzzbench platform. Each test focuses on a different aspect of AFL, ranging from its mutation approach to the feedback encoding scheme and its scheduling methodologies.<\/jats:p>\n          <jats:p>Our findings show that each design choice affects different factors of AFL. Some of these are positively correlated with the number of detected bugs or the coverage of the target application, whereas other features are related to usability and reliability. Most important, we believe that the outcome of our experiments indicates which parts of AFL we should preserve in the design of modern fuzzers.<\/jats:p>","DOI":"10.1145\/3580596","type":"journal-article","created":{"date-parts":[[2023,1,20]],"date-time":"2023-01-20T11:06:15Z","timestamp":1674212775000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Dissecting American Fuzzy Lop: A FuzzBench Evaluation"],"prefix":"10.1145","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0976-4395","authenticated-orcid":false,"given":"Andrea","family":"Fioraldi","sequence":"first","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4813-8562","authenticated-orcid":false,"given":"Alessandro","family":"Mantovani","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5588-5008","authenticated-orcid":false,"given":"Dominik","family":"Maier","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5957-6213","authenticated-orcid":false,"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,3,29]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"CERT. (n.d.). CERT BFF - Basic Fuzzing Framework. Retrieved September 1 2022 from https:\/\/vuls.cert.org\/confluence\/display\/tools\/CERT+BFF+-+Basic+Fuzzing+Framework."},{"key":"e_1_3_2_3_2","unstructured":"GitHub. (n.d.). Funfuzz MozillaSecurity. Retrieved September 1 2022 from https:\/\/github.com\/MozillaSecurity\/funfuzz."},{"key":"e_1_3_2_4_2","unstructured":"GitHub. (n.d.). Google OSS-Fuzz: Continuous Fuzzing of Open Source Software. Retrieved September 1 2022 from https:\/\/github.com\/google\/oss-fuzz."},{"key":"e_1_3_2_5_2","unstructured":"Clang. 2016. Undefined Behavior Sanitizer. Retrieved December 22 2021 from https:\/\/clang.llvm.org\/docs\/UndefinedBehaviorSanitizer.html."},{"key":"e_1_3_2_6_2","volume-title":"Proceedings of the 2019 Network and Distributed System Security Symposium (NDSS\u201919)","author":"Aschermann Cornelius","year":"2019","unstructured":"Cornelius Aschermann, Tommaso Frassetto, T. Holz, Patrick Jauernig, A. Sadeghi, and Daniel Teuchert. 2019. NAUTILUS: Fishing for deep bugs with grammars. In Proceedings of the 2019 Network and Distributed System Security Symposium (NDSS\u201919)."},{"key":"e_1_3_2_7_2","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (Oakland)","author":"Aschermann Cornelius","year":"2020","unstructured":"Cornelius Aschermann, Sergej Schumilo, Ali Abbasi, and Thorsten Holz. 2020. IJON: Exploring deep state spaces via fuzzing. In Proceedings of the IEEE Symposium on Security and Privacy (Oakland)."},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3182657"},{"key":"e_1_3_2_9_2","first-page":"1985","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919)","author":"Blazytko Tim","year":"2019","unstructured":"Tim Blazytko, Cornelius Aschermann, Moritz Schl\u00f6gel, Ali Abbasi, Sergej Schumilo, Simon W\u00f6rner, and Thorsten Holz. 2019. GRIMOIRE: Synthesizing structure while fuzzing. In Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919). 1985\u20132002. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/blazytko."},{"key":"e_1_3_2_10_2","first-page":"1","volume-title":"Proceedings of the 14th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on the Foundations of Software Engineering (ESEC\/FSE\u201920)","author":"B\u00f6hme Marcel","year":"2020","unstructured":"Marcel B\u00f6hme, Valentin Man\u00e8s, and Sang Kil Cha. 2020. Boosting fuzzer efficiency: An information theoretic perspective. In Proceedings of the 14th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on the Foundations of Software Engineering (ESEC\/FSE\u201920). 1\u201311."},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978428"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2015.2487274"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00046"},{"key":"e_1_3_2_14_2","first-page":"77","volume-title":"Proceedings of the 23rd International Symposium on Research in Attacks, Intrusions, and Defenses (RAID\u201920)","author":"Chen Yaohui","unstructured":"Yaohui Chen, Mansour Ahmadi, Boyu Wang, Long Lu, et\u00a0al. 2020. MEUZZ: Smart seed scheduling for hybrid fuzzing. In Proceedings of the 23rd International Symposium on Research in Attacks, Intrusions, and Defenses (RAID\u201920). 77\u201392."},{"key":"e_1_3_2_15_2","unstructured":"Jared D. DeMott and R. Enbody. 2007. Revolutionizing the field of grey-box attack surface testing with evolutionary fuzzing. In Proceedings of the 2007 Black Hat Conference ."},{"key":"e_1_3_2_16_2","article-title":"Peach Fuzzing Platform","author":"Eddington M.","unstructured":"M. Eddington. (n.d.). Peach Fuzzing Platform. Retrieved December 22, 2021 from https:\/\/web.archive.org\/web\/20180621074520http:\/\/community.peachfuzzer.com\/WhatIsPeach.html.","journal-title":"https:\/\/web.archive.org\/web\/20180621074520http:\/\/community.peachfuzzer.com\/WhatIsPeach.html."},{"key":"e_1_3_2_17_2","first-page":"2829","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921)","author":"Fioraldi Andrea","year":"2021","unstructured":"Andrea Fioraldi, Daniele Cono D\u2019Elia, and Davide Balzarotti. 2021. The use of likely invariants as feedback for fuzzers. In Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921). 2829\u20132846. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/fioraldi."},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3395363.3397372"},{"key":"e_1_3_2_19_2","volume-title":"Proceedings of the 14th USENIX Workshop on Offensive Technologies (WOOT\u201920)","author":"Fioraldi Andrea","year":"2020","unstructured":"Andrea Fioraldi, Dominik Maier, Heiko Ei\u00dffeldt, and Marc Heuse. 2020. AFL++: Combining incremental steps of fuzzing research. In Proceedings of the 14th USENIX Workshop on Offensive Technologies (WOOT\u201920)."},{"key":"e_1_3_2_20_2","doi-asserted-by":"crossref","unstructured":"Andrea Fioraldi Dominik Maier Dongjia Zhang and Davide Balzarotti. 2022. LibAFL: A framework to build modular and reusable fuzzers. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS\u201922) . 1051\u20131065.","DOI":"10.1145\/3548606.3560602"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/1292414.1292416"},{"key":"e_1_3_2_22_2","doi-asserted-by":"crossref","first-page":"517","DOI":"10.1145\/2976749.2978405","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS\u201916)","author":"Haller Istvan","year":"2016","unstructured":"Istvan Haller, Yuseok Jeon, Hui Peng, Mathias Payer, Cristiano Giuffrida, Herbert Bos, and Erik Van Der Kouwe. 2016. TypeSan: Practical type confusion detection. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS\u201916). 517\u2013528."},{"key":"e_1_3_2_23_2","unstructured":"Jesse Hertz and Tim Newsham. (n.d.) Project Triforce: Run AFL on Everything! Retrieved September 1 2022 fromhttps:\/\/www.nccgroup.trust\/us\/about-us\/newsroom-and-events\/blog\/2016\/june\/project-triforce-run-afl-on-everything\/."},{"key":"e_1_3_2_24_2","article-title":"afl-clang-lto - Collision Free Instrumentation at Link Time","author":"Heuse Marc","year":"2020","unstructured":"Marc Heuse. 2020. afl-clang-lto - Collision Free Instrumentation at Link Time. Retrieved September 1, 2022 from https:\/\/github.com\/AFLplusplus\/AFLplusplus\/blob\/stable\/instrumentation\/README.lto.md.","journal-title":"https:\/\/github.com\/AFLplusplus\/AFLplusplus\/blob\/stable\/instrumentation\/README.lto.md."},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.5555\/977395.977673"},{"key":"e_1_3_2_27_2","article-title":"SanitizerCoverage - Edge Coverage","unstructured":"LLVM. (n.d.) SanitizerCoverage - Edge Coverage. Retrieved September 1, 2022 from https:\/\/clang.llvm.org\/docs\/SanitizerCoverage.html#edge-coverage.","journal-title":"https:\/\/clang.llvm.org\/docs\/SanitizerCoverage.html#edge-coverage."},{"key":"e_1_3_2_28_2","article-title":"libFuzzer \u2013 A Library for Coverage-Guided Fuzz Testing. Retrieved September 1, 2022 from","author":"Project LLVM","year":"2018","unstructured":"LLVM Project. 2018. libFuzzer \u2013 A Library for Coverage-Guided Fuzz Testing. Retrieved September 1, 2022 fromhttps:\/\/llvm.org\/docs\/LibFuzzer.html.","journal-title":"https:\/\/llvm.org\/docs\/LibFuzzer.html."},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2946563"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380421"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3387940.3391457"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3473932"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3293882.3330576"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3360600"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2941681"},{"key":"e_1_3_2_37_2","volume-title":"Proceedings of the 13th IEEE International Conference on Software Testing, Verification, and Validation: Testing Tools Track","author":"Pham Van-Thuan","year":"2020","unstructured":"Van-Thuan Pham, Marcel B\u00f6hme, and Abhik Roychoudhury. 2020. AFLNet: A greybox fuzzer for network protocols. In Proceedings of the 13th IEEE International Conference on Software Testing, Verification, and Validation: Testing Tools Track."},{"key":"e_1_3_2_38_2","first-page":"181","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920)","author":"Poeplau Sebastian","year":"2020","unstructured":"Sebastian Poeplau and Aur\u00e9lien Francillon. 2020. Symbolic execution with SymCC: Don\u2019t interpret, compile! In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920). 181\u2013198."},{"key":"e_1_3_2_39_2","volume-title":"Proceedings of the 24th Annual Network and Distributed System Security Symposium (NDSS\u201917)","author":"Rawat Sanjay","year":"2017","unstructured":"Sanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar, Cristiano Giuffrida, and Herbert Bos. 2017. VUzzer: Application-aware evolutionary fuzzing. In Proceedings of the 24th Annual Network and Distributed System Security Symposium (NDSS\u201917). https:\/\/www.ndss-symposium.org\/ndss2017\/ndss-2017-programme\/vuzzer-application-aware-evolutionary-fuzzing\/."},{"key":"e_1_3_2_40_2","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921)","author":"Schumilo Sergej","year":"2021","unstructured":"Sergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon W\u00f6rner, and Thorsten Holz. 2021. Nyx: Greybox hypervisor fuzzing using fast snapshots and affine types. In Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921). https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/schumilo."},{"key":"e_1_3_2_41_2","first-page":"167","volume-title":"Proceedings of the 26th USENIX Conference on Security Symposium (SEC\u201917)","author":"Schumilo Sergej","year":"2017","unstructured":"Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, and Thorsten Holz. 2017. KAFL: Hardware-assisted feedback fuzzing for OS kernels. In Proceedings of the 26th USENIX Conference on Security Symposium (SEC\u201917). 167\u2013182."},{"key":"e_1_3_2_42_2","article-title":"Nyx-Net: Network fuzzing with incremental snapshots","author":"Schumilo Sergej","year":"2021","unstructured":"Sergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi, and Thorsten Holz. 2021. Nyx-Net: Network fuzzing with incremental snapshots. arXiv preprint arXiv:2111.03013 (2021).","journal-title":"arXiv preprint arXiv:2111.03013"},{"key":"e_1_3_2_43_2","first-page":"28","volume-title":"Proceedings of the 2012 USENIX Annual Technical Conference (USENIX ATC\u201912)","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitry Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In Proceedings of the 2012 USENIX Annual Technical Conference (USENIX ATC\u201912). 28."},{"key":"e_1_3_2_44_2","doi-asserted-by":"crossref","first-page":"138","DOI":"10.1109\/SP.2016.17","volume-title":"Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP\u201917)","author":"Shoshitaishvili Yan","year":"2016","unstructured":"Yan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens, Mario Polino, Andrew Dutcher, John Grosen, et\u00a0al. 2016. Sok: (State of) the art of war: Offensive techniques in binary analysis. In Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP\u201917). IEEE, Los Alamitos, CA, 138\u2013157."},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","unstructured":"Prashast Srivastava and Mathias Payer. 2021. Gramatron: Effective grammar-aware fuzzing. In Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA\u201921) . 244\u2013256.","DOI":"10.1145\/3460319.3464814"},{"key":"e_1_3_2_46_2","first-page":"1","volume-title":"Proceedings of the 2016 Network and Distributed System Security Symposium (NDSS\u201916)","author":"Stephens Nick","year":"2016","unstructured":"Nick Stephens, John Grosen, Christopher Salls, Audrey Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016. Driller: Augmenting fuzzing through selective symbolic execution. In Proceedings of the 2016 Network and Distributed System Security Symposium (NDSS\u201916). 1\u201316."},{"key":"e_1_3_2_47_2","volume-title":"The Automatic Generation of Software Test Data Using Genetic Algorithms","author":"Sthamer Harmen-Hinrich","year":"1995","unstructured":"Harmen-Hinrich Sthamer. 1995. The Automatic Generation of Software Test Data Using Genetic Algorithms. Ph. D. Dissertation. University of Glamorgan."},{"key":"e_1_3_2_48_2","article-title":"Honggfuzz","author":"Swiecki Robert","unstructured":"Robert Swiecki. n.d. Honggfuzz. Retrieved September 1, 2022 from https:\/\/github.com\/google\/honggfuzz.","journal-title":"https:\/\/github.com\/google\/honggfuzz."},{"key":"e_1_3_2_49_2","first-page":"48","volume-title":"Proceedings of the 24th International Symposium on Research in Attacks, Intrusions, and Defenses","author":"Toepfer Fabian","year":"2021","unstructured":"Fabian Toepfer and Dominik Maier. 2021. BSOD: Binary-only scalable fuzzing of device drivers. In Proceedings of the 24th International Symposium on Research in Attacks, Intrusions, and Defenses(RAID\u201921). 48\u201361."},{"key":"e_1_3_2_50_2","unstructured":"Dmitry Vyukov. n.d. syzkaller - Kernel Fuzzer. Retrieved September 1 2022 from https:\/\/github.com\/google\/syzkaller."},{"key":"e_1_3_2_51_2","first-page":"1","volume-title":"Proceedings of the 22nd International Symposium on Research in Attacks, Intrusions, and Defenses (RAID\u201919)","author":"Wang Jinghan","year":"2019","unstructured":"Jinghan Wang, Yue Duan, Wei Song, Heng Yin, and Chengyu Song. 2019. Be sensitive and collaborative: Analyzing impact of coverage metrics in greybox fuzzing. In Proceedings of the 22nd International Symposium on Research in Attacks, Intrusions, and Defenses (RAID\u201919). 1\u201315. https:\/\/www.usenix.org\/conference\/raid2019\/presentation\/wang."},{"key":"e_1_3_2_52_2","volume-title":"Proceedings of the 2021 Network and Distributed System Security Symposium (NDSS\u201921)","author":"Wang Jinghan","year":"2021","unstructured":"Jinghan Wang, Chengyu Song, and Heng Yin. 2021. Reinforcement learning-based hierarchical seed scheduling for greybox fuzzing. In Proceedings of the 2021 Network and Distributed System Security Symposium (NDSS\u201921)."},{"key":"e_1_3_2_53_2","volume-title":"Proceedings of the 2020 Network and Distributed System Security Symposium (NDSS\u201921)","author":"Wang Yanhao","year":"2020","unstructured":"Yanhao Wang, Xiangkun Jia, Yuwei Liu, Kyle Zeng, Tiffany Bao, Dinghao Wu, and Purui Su. 2020. Not all coverage measurements are equal: Fuzzing by coverage accounting for input prioritization. In Proceedings of the 2020 Network and Distributed System Security Symposium (NDSS\u201921)."},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134046"},{"key":"e_1_3_2_55_2","first-page":"2307","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920)","author":"Yue Tai","year":"2020","unstructured":"Tai Yue, Pengfei Wang, Yong Tang, Enze Wang, Bo Yu, Kai Lu, and Xu Zhou. 2020. EcoFuzz: Adaptive energy-saving greybox fuzzing as a variant of the adversarial multi-armed bandit. In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920). 2307\u20132324. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/yue."},{"key":"e_1_3_2_56_2","article-title":"American Fuzzy Lop","author":"Zalewski Micha\u0142","unstructured":"Micha\u0142 Zalewski. n.d. American Fuzzy Lop. Retrieved September 1, 2022 from https:\/\/lcamtuf.coredump.cx\/afl\/.","journal-title":"https:\/\/lcamtuf.coredump.cx\/afl\/."},{"key":"e_1_3_2_57_2","article-title":"Binary Fuzzing Strategies: What Works, What Doesn\u2019t","author":"Zalewski Micha\u0142","year":"2014","unstructured":"Micha\u0142 Zalewski. 2014. Binary Fuzzing Strategies: What Works, What Doesn\u2019t. Retrieved September 1, 2022 from https:\/\/lcamtuf.blogspot.com\/2014\/08\/binary-fuzzing-strategies-what-works.html.","journal-title":"https:\/\/lcamtuf.blogspot.com\/2014\/08\/binary-fuzzing-strategies-what-works.html."},{"key":"e_1_3_2_58_2","article-title":"Fuzzing Random Programs Without execve()","author":"Zalewski Micha\u0142","year":"2014","unstructured":"Micha\u0142 Zalewski. 2014. Fuzzing Random Programs Without execve(). Retrieved September 1, 2022 from https:\/\/lcamtuf.blogspot.com\/2014\/10\/fuzzing-binaries-without-execve.html.","journal-title":"https:\/\/lcamtuf.blogspot.com\/2014\/10\/fuzzing-binaries-without-execve.html."},{"key":"e_1_3_2_59_2","article-title":"afl-fuzz: Making Up Grammar with a Dictionary in Hand","author":"Zalewski Micha\u0142","year":"2015","unstructured":"Micha\u0142 Zalewski. 2015. afl-fuzz: Making Up Grammar with a Dictionary in Hand. Retrieved September 1, 2022 from https:\/\/lcamtuf.blogspot.com\/2015\/01\/afl-fuzz-making-up-grammar-with.html.","journal-title":"https:\/\/lcamtuf.blogspot.com\/2015\/01\/afl-fuzz-making-up-grammar-with.html."},{"key":"e_1_3_2_60_2","article-title":"American Fuzzy Lop - Whitepaper","author":"Zalewski Micha\u0142","year":"2016","unstructured":"Micha\u0142 Zalewski. 2016. American Fuzzy Lop - Whitepaper. Retrieved September 1, 2022 from https:\/\/lcamtuf.coredump.cx\/afl\/technical_details.txt.","journal-title":"https:\/\/lcamtuf.coredump.cx\/afl\/technical_details.txt."},{"key":"e_1_3_2_61_2","article-title":"Bunny the Fuzzer","author":"Zalewski Micha\u0142","year":"2016","unstructured":"Micha\u0142 Zalewski. 2016. Bunny the Fuzzer. Retrieved September 1, 2022 from https:\/\/code.google.com\/archive\/p\/bunny-the-fuzzer\/.","journal-title":"https:\/\/code.google.com\/archive\/p\/bunny-the-fuzzer\/."},{"key":"e_1_3_2_62_2","article-title":"\u201cFidgetyAFL\u201d Implemented in 2.31b","author":"Zalewski Micha\u0142","year":"2016","unstructured":"Micha\u0142 Zalewski. 2016. \u201cFidgetyAFL\u201d Implemented in 2.31b. Retrieved September 1, 2022 from https:\/\/groups.google.com\/g\/afl-users\/c\/1PmKJC-EKZ0\/m\/zck6Iu77DgAJ.","journal-title":"https:\/\/groups.google.com\/g\/afl-users\/c\/1PmKJC-EKZ0\/m\/zck6Iu77DgAJ."}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3580596","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3580596","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:36Z","timestamp":1750178796000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3580596"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,29]]},"references-count":61,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2023,4,30]]}},"alternative-id":["10.1145\/3580596"],"URL":"https:\/\/doi.org\/10.1145\/3580596","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,29]]},"assertion":[{"value":"2022-06-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-14","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-03-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}