{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T01:54:48Z","timestamp":1784426088603,"version":"3.55.0"},"reference-count":74,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T00:00:00Z","timestamp":1689897600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Defence Science and Technology Group Next Generation Technologies Fund (Cyber) program via the Data61 Collaborative Research Project","award":["SNSF\u00a0PCEGP2_186974"],"award-info":[{"award-number":["SNSF\u00a0PCEGP2_186974"]}]},{"name":"ERC\u00a0H2020","award":["StG\u00a0850868"],"award-info":[{"award-number":["StG\u00a0850868"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2023,9,30]]},"abstract":"<jats:p>\n            Coverage-guided greybox fuzzers rely on\n            <jats:italic>control-flow<\/jats:italic>\n            coverage feedback to explore a target program and uncover bugs. Compared to control-flow coverage,\n            <jats:italic>data-flow<\/jats:italic>\n            coverage offers a more fine-grained approximation of program behavior. Data-flow coverage captures behaviors not visible as control flow and should intuitively discover more (or different) bugs. Despite this advantage, fuzzers guided by data-flow coverage have received relatively little attention, appearing mainly in combination with heavyweight program analyses (e.g., taint analysis, symbolic execution). Unfortunately, these more accurate analyses incur a high run-time penalty, impeding fuzzer throughput. Lightweight data-flow alternatives to control-flow fuzzing remain unexplored.\n          <\/jats:p>\n          <jats:p>\n            We present\n            <jats:sc>datAFLow<\/jats:sc>\n            , a greybox fuzzer guided by lightweight data-flow profiling. We also establish a framework for reasoning about data-flow coverage, allowing the computational cost of exploration to be balanced with precision. Using this framework, we extensively evaluate\n            <jats:sc>datAFLow<\/jats:sc>\n            across different precisions, comparing it against state-of-the-art fuzzers guided by control flow, taint analysis, and data flow.\n          <\/jats:p>\n          <jats:p>\n            Our results suggest that the ubiquity of control-flow-guided fuzzers is well-founded. The high run-time costs of data-flow-guided fuzzing (~10 \u00d7 higher than control-flow-guided fuzzing) significantly reduces fuzzer iteration rates, adversely affecting bug discovery and coverage expansion. Despite this,\n            <jats:sc>datAFLow<\/jats:sc>\n            uncovered bugs that state-of-the-art control-flow-guided fuzzers (notably, AFL++) failed to find. This was because data-flow coverage revealed states in the target not visible under control-flow coverage. Thus, we encourage the community to continue exploring lightweight data-flow profiling; specifically, to lower run-time costs and to combine this profiling with control-flow coverage to maximize bug-finding potential.\n          <\/jats:p>","DOI":"10.1145\/3587156","type":"journal-article","created":{"date-parts":[[2023,3,10]],"date-time":"2023-03-10T11:47:45Z","timestamp":1678448865000},"page":"1-31","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["<scp>DatAFLow<\/scp>\n            : Toward a Data-Flow-Guided Fuzzer"],"prefix":"10.1145","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9234-1694","authenticated-orcid":false,"given":"Adrian","family":"Herrera","sequence":"first","affiliation":[{"name":"Australian National University, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5054-7547","authenticated-orcid":false,"given":"Mathias","family":"Payer","sequence":"additional","affiliation":[{"name":"\u00c9cole Polytechnique F\u00e9d\u00e9rale de Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4487-6923","authenticated-orcid":false,"given":"Antony L.","family":"Hosking","sequence":"additional","affiliation":[{"name":"Australian National University, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,7,21]]},"reference":[{"key":"e_1_3_2_2_2","volume-title":"Program Analysis and Specialization for the C Programming Language","author":"Andersen Lars Ole","year":"1994","unstructured":"Lars Ole Andersen. 1994. Program Analysis and Specialization for the C Programming Language. Ph.D. Dissertation. University of Copenhagen."},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1985795"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23412"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00117"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23371"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468570"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978428"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510230"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.5555\/1298455.1298470"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST49551.2021.00021"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00046"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC.1995.496950"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-015-9362-z"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23339"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2019.00015"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW.2012.24"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00026"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/24039.24041"},{"key":"e_1_3_2_21_2","first-page":"2829","volume-title":"USENIX Security Symposium (SEC)","author":"Fioraldi Andrea","year":"2021","unstructured":"Andrea Fioraldi, Daniele Cono D\u2019Elia, and Davide Balzarotti. 2021. The use of likely invariants as feedback for fuzzers. In USENIX Security Symposium (SEC). 2829\u20132846. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/fioraldi."},{"key":"e_1_3_2_22_2","volume-title":"USENIX Workshop on Offensive Technologies (WOOT)","author":"Fioraldi Andrea","year":"2020","unstructured":"Andrea Fioraldi, Dominik Maier, Heiko Ei\u00dffeldt, and Marc Heuse. 2020. AFL++: Combining incremental steps of fuzzing research. In USENIX Workshop on Offensive Technologies (WOOT). 12. https:\/\/www.usenix.org\/conference\/woot20\/presentation\/fioraldi."},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/32.238581"},{"key":"e_1_3_2_24_2","first-page":"2577","volume-title":"USENIX Security Symposium (SEC)","author":"Gan Shuitao","year":"2020","unstructured":"Shuitao Gan, Chao Zhang, Peng Chen, Bodong Zhao, Xiaojun Qin, Dong Wu, and Zuoning Chen. 2020. GREYONE: Data flow sensitive fuzzing. In USENIX Security Symposium (SEC). 2577\u20132594. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/gan."},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00040"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510228"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3428334"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2015.30"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/1186736.1186737"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464795"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.14722\/fuzzing.2022.23001"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/120807.120815"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/2.312032"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2018.23014"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.1994.296778"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134062"},{"key":"e_1_3_2_37_2","volume-title":"Network and Distributed Systems Security Symposium (NDSS)","author":"Kang Min Gyung","year":"2011","unstructured":"Min Gyung Kang, Stephen McCamant, Pongsin Poosankam, and Dawn Song. 2011. DTA++: Dynamic taint analysis with targeted control-flow propagation. In Network and Distributed Systems Security Symposium (NDSS). The Internet Society, 14."},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3230624"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510628"},{"key":"e_1_3_2_41_2","first-page":"2777","volume-title":"USENIX Security Symposium (SEC)","author":"Li Yuwei","year":"2021","unstructured":"Yuwei Li, Shouling Ji, Yuan Chen, Sizhuang Liang, Wei-Han Lee, Yueyao Chen, Chenyang Lyu, Chunming Wu, Raheem Beyah, Peng Cheng, Kangjie Lu, and Ting Wang. 2021. UNIFUZZ: A holistic and pragmatic metrics-driven platform for evaluating fuzzers. In USENIX Security Symposium (SEC). 2777\u20132794. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/li-yuwei."},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3092255.3092268"},{"key":"e_1_3_2_43_2","unstructured":"LLVM Project. 2022. libFuzzer\u2014a library for coverage-guided fuzz testing. (2022). https:\/\/llvm.org\/docs\/LibFuzzer.html."},{"key":"e_1_3_2_44_2","first-page":"1949","volume-title":"USENIX Security Symposium (SEC)","author":"Lyu Chenyang","year":"2019","unstructured":"Chenyang Lyu, Shouling Ji, Chao Zhang, Yuwei Li, Wei-Han Lee, Yu Song, and Raheem Beyah. 2019. MOPT: Optimized mutation scheduling for fuzzers. In USENIX Security Symposium (SEC). 1949\u20131966. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/lyu."},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2946563"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177730491"},{"issue":"3","key":"e_1_3_2_47_2","first-page":"163","article-title":"Evaluation of survival data and two new rank order statistics arising in its consideration","volume":"50","author":"Mantel Nathan","year":"1966","unstructured":"Nathan Mantel. 1966. Evaluation of survival data and two new rank order statistics arising in its consideration. Cancer Chemotherapy Reports 50, 3 (1966), 163\u2013170.","journal-title":"Cancer Chemotherapy Reports"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00026"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3473932"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"e_1_3_2_51_2","unstructured":"Matt Miller. 2019. Trends and Challenges in the Vulnerability Mitigation Landscape. (2019)."},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/1065887.1065892"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3228334"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2018.2832072"},{"key":"e_1_3_2_55_2","first-page":"181","volume-title":"USENIX Security Symposium (SEC)","author":"Poeplau Sebastian","year":"2020","unstructured":"Sebastian Poeplau and Aur\u00e9lien Francillon. 2020. Symbolic execution with SymCC: Don\u2019t interpret, compile!. In USENIX Security Symposium (SEC). 181\u2013198. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/poeplau."},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1985.232226"},{"key":"e_1_3_2_57_2","unstructured":"Matt Ruhstaller and Oliver Chang. 2018. A New Chapter for OSS-Fuzz. (2018). https:\/\/security.googleblog.com\/2018\/11\/a-new-chapter-for-oss-fuzz.html."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/CNS48642.2020.9162273"},{"key":"e_1_3_2_59_2","volume-title":"USENIX Security Symposium (SEC)","author":"Serebryany Kostya","year":"2017","unstructured":"Kostya Serebryany. 2017. OSS-Fuzz\u2014Google\u2019s continuous fuzzing service for open source software. In USENIX Security Symposium (SEC). https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/serebryany."},{"key":"e_1_3_2_60_2","first-page":"309","volume-title":"USENIX Annual Technical Conference (ATC)","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitry Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In USENIX Annual Technical Conference (ATC). 309\u2013318. https:\/\/www.usenix.org\/conference\/atc12\/technical-sessions\/presentation\/serebryany."},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00022"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00010"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/3020266"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/1882291.1882324"},{"key":"e_1_3_2_66_2","unstructured":"Robert Swiecki. 2016. honggfuzz. http:\/\/honggfuzz.com\/."},{"key":"e_1_3_2_67_2","unstructured":"The Clang Team. 2022. DataFlowSanitizer. https:\/\/clang.llvm.org\/docs\/DataFlowSanitizer.html."},{"key":"e_1_3_2_68_2","unstructured":"The Clang Team. 2022. Source-based Code Coverage. https:\/\/clang.llvm.org\/docs\/SourceBasedCodeCoverage.html."},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.5075\/epfl-thesis-7745"},{"key":"e_1_3_2_70_2","first-page":"1","volume-title":"USENIX International Symposium on Research in Attacks, Intrusions and Defenses (RAID)","author":"Wang Jinghan","year":"2019","unstructured":"Jinghan Wang, Yue Duan, Wei Song, Heng Yin, and Chengyu Song. 2019. Be sensitive and collaborative: Analyzing impact of coverage metrics in greybox fuzzing. In USENIX International Symposium on Research in Attacks, Intrusions and Defenses (RAID). 1\u201315. https:\/\/www.usenix.org\/conference\/raid2019\/presentation\/wang."},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24422"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/1375581.1375611"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134046"},{"key":"e_1_3_2_74_2","unstructured":"Micha\u0142 Zalewski. 2015. American Fuzzy Lop (AFL). (2015). http:\/\/lcamtuf.coredump.cx\/afl\/."},{"key":"e_1_3_2_75_2","first-page":"3699","volume-title":"USENIX Security Symposium (SEC)","author":"Zhang Zenong","year":"2022","unstructured":"Zenong Zhang, Zach Patterson, Michael Hicks, and Shiyi Wei. 2022. FIXREVERTER: A realistic bug injection methodology for benchmarking fuzz testing. In USENIX Security Symposium (SEC). 3699\u20133715. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/zhang-zenong."}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3587156","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3587156","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:15Z","timestamp":1750178835000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3587156"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,21]]},"references-count":74,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2023,9,30]]}},"alternative-id":["10.1145\/3587156"],"URL":"https:\/\/doi.org\/10.1145\/3587156","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,7,21]]},"assertion":[{"value":"2022-06-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-02-13","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-07-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}