{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T02:23:41Z","timestamp":1769048621620,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,3,30]],"date-time":"2025-03-30T00:00:00Z","timestamp":1743292800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS-2140305, CNS-2145888"],"award-info":[{"award-number":["CNS-2140305, CNS-2145888"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,3,30]]},"DOI":"10.1145\/3676641.3716019","type":"proceedings-article","created":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T16:47:32Z","timestamp":1743094052000},"page":"1124-1138","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["S\n            <scp>nowplow<\/scp>\n            : Effective Kernel Fuzzing with a Learned White-box Test Mutator"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2784-2617","authenticated-orcid":false,"given":"Sishuai","family":"Gong","sequence":"first","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-0343-7860","authenticated-orcid":false,"given":"Wang","family":"Rui","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4558-2847","authenticated-orcid":false,"given":"Deniz","family":"Altinb\u00fcken","sequence":"additional","affiliation":[{"name":"Google DeepMind, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2480-4487","authenticated-orcid":false,"given":"Pedro","family":"Fonseca","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3777-5291","authenticated-orcid":false,"given":"Petros","family":"Maniatis","sequence":"additional","affiliation":[{"name":"Google DeepMind, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,3,30]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"SHARD: Fine-Grained Kernel Specialization with Context-Aware Hardening. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Abubakar Muhammad","year":"2021","unstructured":"Muhammad Abubakar, Adil Ahmad, Pedro Fonseca, and Dongyan Xu. 2021. SHARD: Fine-Grained Kernel Specialization with Context-Aware Hardening. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2435--2452. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/abubakar"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/2486788.2486805"},{"key":"e_1_3_2_1_4_1","volume-title":"Ardalan Amiri Sani, and Zhiyun Qian","author":"Bursey Joseph","year":"2024","unstructured":"Joseph Bursey, Ardalan Amiri Sani, and Zhiyun Qian. 2024. SyzRetrospector: A Large-Scale Retrospective Study of Syzbot. arXiv:2401.11642 [cs.SE] https:\/\/arxiv.org\/abs\/2401.11642"},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the 8th USENIX Conference on Operating Systems Design and Implementation","author":"Cadar Cristian","year":"2008","unstructured":"Cristian Cadar, Daniel Dunbar, and Dawson Engler. 2008. KLEE: unassisted and automatic generation of high-coverage tests for complex systems programs. In Proceedings of the 8th USENIX Conference on Operating Systems Design and Implementation (San Diego, California) (OSDI'08). USENIX Association, USA, 209--224."},{"key":"e_1_3_2_1_6_1","volume-title":"Reinforcement Learning for Real Life (RL4RealLife) Workshop in the 36th International Conference on Machine Learning (ICML),. https:\/\/arxiv.org\/abs\/1810.00619","author":"Carbune Victor","unstructured":"Victor Carbune, Thierry Coppey, Alexander Daryin, Thomas Deselaers, Nikhil Sarda, and Jay Yagnik. 2019. SmartChoices: Hybridizing Programming and Machine Learning. In Reinforcement Learning for Real Life (RL4RealLife) Workshop in the 36th International Conference on Machine Learning (ICML),. https:\/\/arxiv.org\/abs\/1810.00619"},{"key":"e_1_3_2_1_7_1","unstructured":"Niklas Cassel. Online. [PATCH] ata: libata-sff: Ensure that we cannot write outside the allocated buffer. https:\/\/lore.kernel.org\/all\/ 173806124194.7504.9074817431897226887.b4-ty@kernel.org\/T\/."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.50"},{"key":"e_1_3_2_1_9_1","volume-title":"SyzGen: Dependency Inference for Augmenting Kernel Driver Fuzzing. In IEEE Symposium on Security and Privacy.","author":"Chen Weiteng","year":"2024","unstructured":"Weiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou, Dhilung Kirat, Shachee Mishra, Douglas Schales, Jiyong Jang, and Zhiyun Qian. 2024. SyzGen: Dependency Inference for Augmenting Kernel Driver Fuzzing. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2110356.2110358"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00082"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1995376.1995394"},{"key":"e_1_3_2_1_13_1","volume-title":"Lenssen","author":"Fey Matthias","year":"2019","unstructured":"Matthias Fey and Jan E. Lenssen. 2019. Fast Graph Representation Learning with PyTorch Geometric. In ICLRWorkshop on Representation Learning on Graphs and Manifolds."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575697"},{"key":"e_1_3_2_1_15_1","volume-title":"ACTOR: Action-Guided Kernel Fuzzing. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Fleischer Marius","year":"2023","unstructured":"Marius Fleischer, Dipanjan Das, Priyanka Bose, Weiheng Bai, Kangjie Lu, Mathias Payer, Christopher Kruegel, and Giovanni Vigna. 2023. ACTOR: Action-Guided Kernel Fuzzing. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 5003--5020. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/ presentation\/fleischer"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 11th USENIX Conference on Operating Systems Design and Implementation","author":"Fonseca Pedro","unstructured":"Pedro Fonseca, Rodrigo Rodrigues, and Bj\u00f6rn B. Brandenburg. 2014. SKI: exposing kernel concurrency bugs through systematic schedule exploration. In Proceedings of the 11th USENIX Conference on Operating Systems Design and Implementation (Broomfield, CO) (OSDI'14). USENIX Association, USA, 415--431."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190508.3190529"},{"key":"e_1_3_2_1_18_1","unstructured":"SecLab Fudan. 2023. SyzDirect evaluation dataset. https: \/\/github.com\/seclab-fudan\/SyzDirect\/blob\/main\/source\/syzdirect\/ Runner\/dataset.xlsx."},{"key":"e_1_3_2_1_19_1","unstructured":"SecLab Fudan. 2023. SyzDirect kernel modification. https: \/\/raw.githubusercontent.com\/seclab-fudan\/SyzDirect\/refs\/heads\/ main\/source\/syzdirect\/kcov.diff."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2093548.2093564"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483549"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3600006.3613148"},{"key":"e_1_3_2_1_23_1","unstructured":"Google. Online. Filesystem related system call variants in Syzkaller. https:\/\/github.com\/google\/syzkaller\/blob\/master\/sys\/linux\/ filesystem.txt."},{"key":"e_1_3_2_1_24_1","unstructured":"Google. Online. Syscall description language. https:\/\/github.com\/ google\/syzkaller\/blob\/master\/docs\/syscall_descriptions_syntax.md."},{"key":"e_1_3_2_1_25_1","unstructured":"Google. Online. syz-symbolize. https:\/\/github.com\/google\/syzkaller\/blob\/master\/tools\/syz-symbolize\/symbolize.go."},{"key":"e_1_3_2_1_26_1","unstructured":"Google. Online. Syzkaller-kernel fuzzer. https:\/\/github.com\/google\/syzkaller."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510126"},{"key":"e_1_3_2_1_28_1","unstructured":"Intel. Online. HW-assisted Feedback Fuzzer for x86 VMs. https: \/\/github.com\/IntelLabs\/kAFL."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00045"},{"key":"e_1_3_2_1_30_1","unstructured":"Dave Jones. Online. Trinity: Linux system call fuzzer. https:\/\/github. com\/kernelslacker\/trinity."},{"key":"e_1_3_2_1_31_1","unstructured":"The kernel development community. Online. KCOV: code coverage for fuzzing. https:\/\/docs.kernel.org\/dev-tools\/kcov.html."},{"key":"e_1_3_2_1_32_1","volume-title":"HFL: Hybrid Fuzzing on the Linux Kernel. In 27th Annual Network and Distributed System Security Symposium, NDSS 2020","author":"Kim Kyungtae","year":"2020","unstructured":"Kyungtae Kim, Dae R. Jeong, Chung Hwan Kim, Yeongjin Jang, Insik Shin, and Byoungyoung Lee. 2020. HFL: Hybrid Fuzzing on the Linux Kernel. In 27th Annual Network and Distributed System Security Symposium, NDSS 2020, San Diego, California, USA, February 23-26, 2020. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss-paper\/hflhybrid- fuzzing-on-the-linux-kernel\/"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-39650-5_19"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238176"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575731"},{"key":"e_1_3_2_1_36_1","unstructured":"Yinhan Liu Myle Ott Naman Goyal Jingfei Du Mandar Joshi Danqi Chen Omer Levy Mike Lewis Luke Zettlemoyer and Veselin Stoyanov. 2019. RoBERTa: A Robustly Optimized BERT Pretraining Approach. arXiv:1907.11692 [cs.CL]"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-4009"},{"key":"e_1_3_2_1_38_1","volume-title":"MoonShine: Optimizing OS Fuzzer Seed Selection with Trace Distillation. In 27th USENIX Security Symposium (USENIX Security 18)","author":"Pailoor Shankara","year":"2018","unstructured":"Shankara Pailoor, Andrew Aday, and Suman Jana. 2018. MoonShine: Optimizing OS Fuzzer Seed Selection with Trace Distillation. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, 729--743. https:\/\/www.usenix.org\/conference\/ usenixsecurity18\/presentation\/pailoor"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24118"},{"key":"e_1_3_2_1_40_1","unstructured":"pytorch. Online. TorchServe. https:\/\/github.com\/pytorch\/serve."},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of the 26th USENIX Conference on Security Symposium","author":"Schumilo Sergej","year":"2017","unstructured":"Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, and Thorsten Holz. 2017. kAFL: hardware-assisted feedback fuzzing for OS kernels. In Proceedings of the 26th USENIX Conference on Security Symposium (Vancouver, BC, Canada) (SEC'17). USENIX Association, USA, 167--182."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00052"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP"},{"key":"e_1_3_2_1_44_1","first-page":"1","article-title":"Driller: Augmenting fuzzing through selective symbolic execution","volume":"16","author":"Stephens Nick","year":"2016","unstructured":"Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016. Driller: Augmenting fuzzing through selective symbolic execution.. In NDSS, Vol. 16. 1--16.","journal-title":"NDSS"},{"key":"e_1_3_2_1_45_1","volume-title":"KSG: Augmenting Kernel Fuzzing with System Call Specification Generation. In 2022 USENIX Annual Technical Conference (USENIX ATC. USENIX Association","author":"Sun Hao","year":"2022","unstructured":"Hao Sun, Yuheng Shen, Jianzhong Liu, Yiru Xu, and Yu Jiang. 2022. KSG: Augmenting Kernel Fuzzing with System Call Specification Generation. In 2022 USENIX Annual Technical Conference (USENIX ATC. USENIX Association, Carlsbad, CA, 351--366. https:\/\/www.usenix. org\/conference\/atc22\/presentation\/sun"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483547"},{"key":"e_1_3_2_1_47_1","unstructured":"SyzBot. Online. KASAN: slab-use-after-free Read in unix_stream_read_actor (2). https:\/\/syzkaller.appspot.com\/ bug?extid=8811381d455e3e9ec788."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623146"},{"key":"e_1_3_2_1_49_1","volume-title":"C. Richard Ho, and Charles Sutton.","author":"Vasudevan Shobha","year":"2021","unstructured":"Shobha Vasudevan, Wenjie (Joe) Jiang, David Bieber, Rishabh Singh, hamid shojaei, C. Richard Ho, and Charles Sutton. 2021. Learning Semantic Representations to Verify Hardware Designs. In Advances in Neural Information Processing Systems, M. Ranzato, A. Beygelzimer, Y. Dauphin, P.S. Liang, and J.Wortman Vaughan (Eds.), Vol. 34. Curran Associates, Inc., 23491--23504. https:\/\/proceedings.neurips.cc\/paper\/2021\/file\/c5aa65949d20f6b20e1a922c13d974e7-Paper.pdf"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/3295222.3295349"},{"key":"e_1_3_2_1_51_1","unstructured":"Dmitry Vyukov. 2018. Introducing the syzbot dashboard. https:\/\/lwn.net\/Articles\/749910\/."},{"key":"e_1_3_2_1_52_1","volume-title":"SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement Learning. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Wang Daimeng","year":"2021","unstructured":"Daimeng Wang, Zheng Zhang, Hang Zhang, Zhiyun Qian, Srikanth V. Krishnamurthy, and Nael Abu-Ghazaleh. 2021. SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement Learning. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2741--2758. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/wang-daimeng"},{"key":"e_1_3_2_1_53_1","unstructured":"Jiacheng Xu Xuhong Zhang Shouling Ji Yuan Tian Binbin Zhao Qinying Wang Peng Cheng and Jiming Chen. [n. d.]. MOCK: Optimizing Kernel Fuzzing Mutation with Context-aware Dependency. ([n. d.])."},{"key":"e_1_3_2_1_54_1","unstructured":"Chenyuan Yang Zijie Zhao and Lingming Zhang. 2023. KernelGPT: Enhanced Kernel Fuzzing via Large Language Models. https:\/\/arxiv.org\/abs\/2401.00563. arXiv:2401.00563 [cs.CR]"},{"key":"e_1_3_2_1_55_1","volume-title":"QSYM: A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing. In 27th USENIX Security Symposium (USENIX Security 18)","author":"Yun Insu","year":"2018","unstructured":"Insu Yun, Sangho Lee, Meng Xu, Yeongjin Jang, and Taesoo Kim. 2018. QSYM: A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, 745--761. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/yun"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575714"}],"event":{"name":"ASPLOS '25: 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems","location":"Rotterdam Netherlands","acronym":"ASPLOS '25","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages","SIGOPS ACM Special Interest Group on Operating Systems","SIGARCH ACM Special Interest Group on Computer Architecture"]},"container-title":["Proceedings of the 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3676641.3716019","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3676641.3716019","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T11:09:11Z","timestamp":1755774551000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3676641.3716019"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,30]]},"references-count":56,"alternative-id":["10.1145\/3676641.3716019","10.1145\/3676641"],"URL":"https:\/\/doi.org\/10.1145\/3676641.3716019","relation":{},"subject":[],"published":{"date-parts":[[2025,3,30]]},"assertion":[{"value":"2025-03-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}