{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:00:39Z","timestamp":1781283639215,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":107,"publisher":"ACM","funder":[{"name":"National Science Foundation","award":["2339350"],"award-info":[{"award-number":["2339350"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"DOI":"10.1145\/3800506.3803511","type":"proceedings-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:24:42Z","timestamp":1781281482000},"page":"321-334","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["KnitFuzz: LLM-guided Kernel Fuzzing via Context-Sensitive Socket System Calls"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-4729-2314","authenticated-orcid":false,"given":"Siwei","family":"Zhang","sequence":"first","affiliation":[{"name":"Syracuse University, Syracuse, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6682-9618","authenticated-orcid":false,"given":"Endadul","family":"Hoque","sequence":"additional","affiliation":[{"name":"Syracuse University, Syracuse, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Peach Fuzzer: Discover unknown vulnerabilities. https:\/\/gitlab.com\/peachtech\/peach-fuzzer-community. accessed","year":"2022","unstructured":"2011. Peach Fuzzer: Discover unknown vulnerabilities. https:\/\/gitlab.com\/peachtech\/peach-fuzzer-community. accessed Jul 2022."},{"key":"e_1_3_2_1_2_1","volume-title":"boofuzz: Network Protocol Fuzzing for Humans. https:\/\/github.com\/jtpereyda\/boofuzz. accessed","year":"2022","unstructured":"2012. boofuzz: Network Protocol Fuzzing for Humans. https:\/\/github.com\/jtpereyda\/boofuzz. accessed Jul 2022."},{"key":"e_1_3_2_1_3_1","unstructured":"2014. OPENRCE. Sulley: A pure-python fully automated and unattended fuzzing framework. https:\/\/github.com\/OpenRCE\/sulley."},{"key":"e_1_3_2_1_4_1","unstructured":"2019. LLDBFuzzer: Debugging and fuzzing the apple kernel. https:\/\/www.trendmicro.com\/en_us\/research\/19\/h\/lldbfuzzer-debugging-andfuzzing-the-apple-kernel-with-lldb-script.html."},{"key":"e_1_3_2_1_5_1","volume-title":"https:\/\/www.kali.org\/tools\/spike\/. accessed","author":"SPIKE.","year":"2022","unstructured":"2019. SPIKE. https:\/\/www.kali.org\/tools\/spike\/. accessed Jul 2022."},{"key":"e_1_3_2_1_6_1","volume-title":"ISSTA FUZZING","author":"Ackerman Joshua","year":"2023","unstructured":"Joshua Ackerman and George Cybenko. 2023. Large language models for fuzzing parsers (registered report). In ISSTA FUZZING 2023."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","unstructured":"Anastasios Andronidis and Cristian Cadar. 2022. SnapFuzz: High-Throughput Fuzzing of Network Applications. In ISSTA. doi:10.1145\/3533767.3534376","DOI":"10.1145\/3533767.3534376"},{"key":"e_1_3_2_1_8_1","unstructured":"Anthropic. 2023. Claude. https:\/\/claude.ai\/."},{"key":"e_1_3_2_1_9_1","unstructured":"Trinity Authors. 2012. trinity: Linux system call fuzzer. https:\/\/github.com\/kernelslacker\/trinity."},{"key":"e_1_3_2_1_10_1","first-page":"3255","article-title":"Stateful greybox fuzzing","volume":"22","author":"Ba Jinsheng","year":"2022","unstructured":"Jinsheng Ba, Marcel B\u00f6hme, Zahra Mirzamomen, and Abhik Roychoudhury. 2022. Stateful greybox fuzzing. In USENIX Security 22. 3255-3272.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_11_1","volume-title":"SNOOZE: Toward a stateful network protocol fuzzer","author":"Banks G.","year":"2006","unstructured":"G. Banks, M. Cova, V. Felmetsger, K. Almeroth, R. Kemmerer, and G. Vigna. 2006. SNOOZE: Toward a stateful network protocol fuzzer. In ISC. Springer."},{"key":"e_1_3_2_1_12_1","first-page":"10","article-title":"QEMU, a fast and portable dynamic translator","volume":"41","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard. 2005. QEMU, a fast and portable dynamic translator. In USENIX ATC, Vol. 41. 10-5555.","journal-title":"USENIX ATC"},{"key":"e_1_3_2_1_13_1","first-page":"535","article-title":"A messy state of the union: Taming the composite state machines of TLS","author":"Beurdouche Benjamin","year":"2015","unstructured":"Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, C\u00e9dric Fournet, Markulf Kohlweiss, Alfredo Pironti, Pierre-Yves Strub, and Jean Karim Zinzindohoue. 2015. A messy state of the union: Taming the composite state machines of TLS. In IEEE S&P. 535-552.","journal-title":"IEEE S&P."},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. 1032-1043","author":"B\u00f6hme Marcel","year":"2016","unstructured":"Marcel B\u00f6hme, Van-Thuan Pham, and Abhik Roychoudhury. 2016. Coveragebased Greybox Fuzzing as Markov Chain. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. 1032-1043."},{"key":"e_1_3_2_1_15_1","unstructured":"Marco Bonelli. 2025. Linux kernel syscall tables. https:\/\/syscalls.mebeim.net\/?table=x86\/64\/x64\/v6.10."},{"key":"e_1_3_2_1_16_1","volume-title":"No Grammar","author":"Bulekov Alexander","unstructured":"Alexander Bulekov, Bandan Das, Stefan Hajnoczi, and Manuel Egele. 2023. No Grammar, No Problem: Towards Fuzzing the Linux Kernel without System-Call Descriptions. In NDSS."},{"key":"e_1_3_2_1_17_1","volume-title":"Menghan Sun, Ronghai Yang, and Kehuan Zhang.","author":"Chen Jiongyi","year":"2018","unstructured":"Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin, XiaoFeng Wang, Wing Cheong Lau, Menghan Sun, Ronghai Yang, and Kehuan Zhang. 2018. IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing. In NDSS."},{"key":"e_1_3_2_1_18_1","volume-title":"Dependency Inference for Augmenting Kernel Driver Fuzzing","author":"Chen Weiteng","unstructured":"Weiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou, Dhilung Kirat, Shachee Mishra, Douglas Schales, Jiyong Jang, and Zhiyun Qian. 2024. SyzGen++: Dependency Inference for Augmenting Kernel Driver Fuzzing. In IEEE S&P."},{"key":"e_1_3_2_1_19_1","first-page":"749","article-title":"Syzgen: Automated generation of syscall specification of closed-source macos drivers","author":"Chen Weiteng","year":"2021","unstructured":"Weiteng Chen, Yu Wang, Zheng Zhang, and Zhiyun Qian. 2021. Syzgen: Automated generation of syscall specification of closed-source macos drivers. In ACM CCS. 749-763.","journal-title":"ACM CCS."},{"key":"e_1_3_2_1_20_1","volume-title":"SDD: Self-Degraded Defense against Malicious Fine-tuning. arXiv preprint arXiv:2507.21182","author":"Chen Zixuan","year":"2025","unstructured":"Zixuan Chen, Weikai Lu, Xin Lin, and Ziqian Zeng. 2025. SDD: Self-Degraded Defense against Malicious Fine-tuning. arXiv preprint arXiv:2507.21182 (2025)."},{"key":"e_1_3_2_1_21_1","unstructured":"Cloudflare. 2019. A gentle introduction to Linux Kernel fuzzing. https:\/\/blog. cloudflare.com\/a-gentle-introduction-to-linux-kernel-fuzzing\/."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1098\/rsta.2015.0403"},{"key":"e_1_3_2_1_23_1","unstructured":"Joeri de Ruiter and Erik Poll. 2015. Protocol State Fuzzing of TLS Implementations. In USENIX Security."},{"key":"e_1_3_2_1_24_1","volume-title":"Target: Traffic rule-based test generation for autonomous driving systems","author":"Deng Yao","year":"2025","unstructured":"Yao Deng, Zhi Tu, Jiaohong Yao, Mengshi Zhang, Tianyi Zhang, and Xi Zheng. 2025. Target: Traffic rule-based test generation for autonomous driving systems. IEEE Transactions on Software Engineering (2025)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Y. Deng C. Xia C. Yang S. Zhang S. Yang and L. Zhang. 2024. Large Language Models are Edge-Case Generators: Crafting Unusual Programs for Fuzzing Deep Learning Libraries. In ICSE.","DOI":"10.1145\/3597503.3623343"},{"key":"e_1_3_2_1_26_1","volume-title":"Haoran Peng, Chenyuan Yang, and Lingming Zhang.","author":"Deng Yinlin","year":"2023","unstructured":"Yinlin Deng, Chunqiu Steven Xia, Haoran Peng, Chenyuan Yang, and Lingming Zhang. 2023. Large language models are zero-shot fuzzers: Fuzzing deeplearning libraries via large language models. In ISSTA."},{"key":"e_1_3_2_1_27_1","first-page":"1497","article-title":"Retrowrite: Statically instrumenting cots binaries for fuzzing and sanitization","author":"Dinesh Sushant","year":"2020","unstructured":"Sushant Dinesh, Nathan Burow, Dongyan Xu, and Mathias Payer. 2020. Retrowrite: Statically instrumenting cots binaries for fuzzing and sanitization. In IEEE S&P. IEEE, 1497-1511.","journal-title":"IEEE S&P. IEEE"},{"key":"e_1_3_2_1_28_1","first-page":"131","article-title":"An Empirical Study of OSS-Fuzz Bugs","author":"Ding Zhen Yu","year":"2021","unstructured":"Zhen Yu Ding and Claire Le Goues. 2021. An Empirical Study of OSS-Fuzz Bugs. In MSR. IEEE, 131-142.","journal-title":"MSR. IEEE"},{"key":"e_1_3_2_1_29_1","first-page":"1031","article-title":"Fuzzing embedded systems using debug interfaces","author":"Eisele Max","year":"2023","unstructured":"Max Eisele, Daniel Ebert, Christopher Huth, and Andreas Zeller. 2023. Fuzzing embedded systems using debug interfaces. In ISSTA. 1031-1042.","journal-title":"ISSTA."},{"key":"e_1_3_2_1_30_1","volume-title":"Codebert: A pre-trained model for programming and natural languages. arXiv:2002.08155","author":"Feng Zhangyin","year":"2020","unstructured":"Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, and Daxin Jiang. 2020. Codebert: A pre-trained model for programming and natural languages. arXiv:2002.08155 (2020)."},{"key":"e_1_3_2_1_31_1","unstructured":"Andrea Fioraldi Dominik Maier Heiko Ei\u00dffeldt and Marc Heuse. 2020. AFL++: Combining incremental steps of fuzzing research. In USENIX WOOT 20."},{"key":"e_1_3_2_1_32_1","volume-title":"Combining Model Learning and Model Checking to Analyze TCP Implementations","author":"Fiter\u0103u-Bro\u015ftean Paul","unstructured":"Paul Fiter\u0103u-Bro\u015ftean, Ramon Janssen, and Frits Vaandrager. 2016. Combining Model Learning and Model Checking to Analyze TCP Implementations. In CAV. Springer International Publishing."},{"key":"e_1_3_2_1_33_1","first-page":"2523","article-title":"Analysis of DTLS implementations using protocol state fuzzing","volume":"20","author":"Fiter\u0103u-Bro\u015ftean Paul","year":"2020","unstructured":"Paul Fiter\u0103u-Bro\u015ftean, Bengt Jonsson, Robert Merget, Joeri De Ruiter, Konstantinos Sagonas, and Juraj Somorovsky. 2020. Analysis of DTLS implementations using protocol state fuzzing. In USENIX Security 20. 2523-2540.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_34_1","volume-title":"2022 IEEE Conference on Software Testing, Verification and Validation (ICST). IEEE, 456-458","author":"Fiter\u0103u-Bro\u015ftean Paul","year":"2022","unstructured":"Paul Fiter\u0103u-Bro\u015ftean, Bengt Jonsson, Konstantinos Sagonas, and Fredrik T\u00e5quist. 2022. Dtls-fuzzer: A dtls protocol state fuzzer. In 2022 IEEE Conference on Software Testing, Verification and Validation (ICST). IEEE, 456-458."},{"key":"e_1_3_2_1_35_1","volume-title":"Proc. of SPIN. ACM.","author":"Fiter\u0103u-Bro\u015ftean Paul","year":"2017","unstructured":"Paul Fiter\u0103u-Bro\u015ftean, Toon Lenaerts, Erik Poll, Joeri de Ruiter, Frits Vaandrager, and Patrick Verleg. 2017. Model Learning and Model Checking of SSH Implementations. In Proc. of SPIN. ACM."},{"key":"e_1_3_2_1_36_1","first-page":"5003","article-title":"ACTOR:Action- Guided Kernel Fuzzing","volume":"23","author":"Fleischer Marius","year":"2023","unstructured":"Marius Fleischer, Dipanjan Das, Priyanka Bose, Weiheng Bai, Kangjie Lu, Mathias Payer, Christopher Kruegel, and Giovanni Vigna. 2023. ACTOR:Action- Guided Kernel Fuzzing. In USENIX Security 23. 5003-5020.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_37_1","unstructured":"Google. 2013. AddressSanitizer ThreadSanitizer MemorySanitizer. https:\/\/github.com\/google\/sanitizers."},{"key":"e_1_3_2_1_38_1","unstructured":"Google. 2015. External network fuzzing for Linux kernel. https:\/\/github.com\/google\/syzkaller\/blob\/master\/docs\/linux\/external_fuzzing_network.md."},{"key":"e_1_3_2_1_39_1","unstructured":"Google. 2015. Extract tcp sequence numbers from \/dev\/net\/tun. https:\/\/github.com\/google\/syzkaller\/pull\/175."},{"key":"e_1_3_2_1_40_1","unstructured":"Google. 2015. Syzkaller. https:\/\/github.com\/google\/syzkaller."},{"key":"e_1_3_2_1_41_1","unstructured":"Google. 2015. Syzkaller syscall descriptions. https:\/\/github.com\/google\/syzkaller\/blob\/master\/docs\/syscall_descriptions.md."},{"key":"e_1_3_2_1_42_1","unstructured":"Google. 2023. Gemini. https:\/\/gemini.google.com\/."},{"key":"e_1_3_2_1_43_1","unstructured":"Google. 2025. Syzbot. https:\/\/syzkaller.appspot.com\/."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2934872.2934908"},{"key":"e_1_3_2_1_45_1","first-page":"2345","article-title":"Imf: Inferred model-based fuzzer","volume":"17","author":"Han HyungSeok","year":"2017","unstructured":"HyungSeok Han and Sang Kil Cha. 2017. Imf: Inferred model-based fuzzer. In CCS 17. 2345-2358.","journal-title":"CCS"},{"key":"e_1_3_2_1_46_1","first-page":"1","article-title":"Towards porting operating systems with program synthesis","volume":"45","author":"Hu Jingmei","year":"2023","unstructured":"Jingmei Hu, Eric Lu, David A Holland, Ming Kawaguchi, Stephen Chong, and Margo Seltzer. 2023. Towards porting operating systems with program synthesis. TOPLAS 45, 1 (2023), 1-70.","journal-title":"TOPLAS"},{"key":"e_1_3_2_1_47_1","volume-title":"Augmenting greybox fuzzing with generative ai. arXiv preprint arXiv:2306.06782","author":"Hu Jie","year":"2023","unstructured":"Jie Hu, Qian Zhang, and Heng Yin. 2023. Augmenting greybox fuzzing with generative ai. arXiv preprint arXiv:2306.06782 (2023)."},{"key":"e_1_3_2_1_48_1","volume-title":"Proc. of NDSS.","author":"Jero Samuel","year":"2018","unstructured":"Samuel Jero, Endadul Hoque, David Choffnes, Alan Mislove, and Cristina Nita- Rotaru. 2018. Automated Attack Discovery in TCP Congestion Control Using a Model-guided Approach. In Proc. of NDSS."},{"key":"e_1_3_2_1_49_1","first-page":"1","article-title":"Leveraging state information for automated attack discovery in transport protocol implementations","author":"Jero Samuel","year":"2015","unstructured":"Samuel Jero, Hyojeong Lee, and Cristina Nita-Rotaru. 2015. Leveraging state information for automated attack discovery in transport protocol implementations. In DSN. IEEE, 1-12.","journal-title":"DSN. IEEE"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.4204\/eptcs.157.10"},{"key":"e_1_3_2_1_51_1","volume-title":"The Twelfth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=VTF8yNQM66","author":"Jimenez Carlos E","year":"2024","unstructured":"Carlos E Jimenez, John Yang, Alexander Wettig, Shunyu Yao, Kexin Pei, Ofir Press, and Karthik R Narasimhan. 2024. SWE-bench: Can Language Models Resolve Real-world Github Issues?. In The Twelfth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=VTF8yNQM66"},{"key":"e_1_3_2_1_52_1","volume-title":"Yeongjin Jang, Insik Shin, and Byoungyoung Lee.","author":"Kim Kyungtae","year":"2020","unstructured":"Kyungtae Kim, Dae R Jeong, Chung Hwan Kim, Yeongjin Jang, Insik Shin, and Byoungyoung Lee. 2020. HFL: Hybrid Fuzzing on the Linux Kernel.. In NDSS."},{"key":"e_1_3_2_1_53_1","first-page":"2123","article-title":"Evaluating fuzz testing","author":"Klees George","year":"2018","unstructured":"George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, and Michael Hicks. 2018. Evaluating fuzz testing. In ACM CCS. 2123-2138.","journal-title":"ACM CCS."},{"key":"e_1_3_2_1_54_1","volume-title":"SNPSFuzzer: A Fast Greybox Fuzzer for Stateful Network Protocols using Snapshots. arXiv preprint arXiv:2202.03643","author":"Li Junqiang","year":"2022","unstructured":"Junqiang Li, Senyi Li, Gang Sun, Ting Chen, and Hongfang Yu. 2022. SNPSFuzzer: A Fast Greybox Fuzzer for Stateful Network Protocols using Snapshots. arXiv preprint arXiv:2202.03643 (2022)."},{"key":"e_1_3_2_1_55_1","first-page":"1","article-title":"\u03bcAFL: non-intrusive feedback-driven fuzzing for microcontroller firmware","author":"Li Wenqiang","year":"2022","unstructured":"Wenqiang Li, Jiameng Shi, Fengjun Li, Jingqiang Lin, Wei Wang, and Le Guan. 2022. \u03bcAFL: non-intrusive feedback-driven fuzzing for microcontroller firmware. In ICSE. 1-12.","journal-title":"ICSE."},{"key":"e_1_3_2_1_56_1","article-title":"Fuzzing: State of the art","volume":"67","author":"Liang Hongliang","year":"2018","unstructured":"Hongliang Liang, Xiaoxiao Pei, Xiaodong Jia, Wuwei Shen, and Jian Zhang. 2018. Fuzzing: State of the art. IEEE Transactions on Reliability 67, 3 (2018).","journal-title":"IEEE Transactions on Reliability"},{"key":"e_1_3_2_1_57_1","first-page":"809","article-title":"Pafl: extend fuzzing optimizations of single mode to industrial parallel mode","author":"Liang Jie","year":"2018","unstructured":"Jie Liang, Yu Jiang, Yuanliang Chen, Mingzhe Wang, Chijin Zhou, and Jiaguang Sun. 2018. Pafl: extend fuzzing optimizations of single mode to industrial parallel mode. In ESEC\/FSE. 809-814.","journal-title":"ESEC\/FSE."},{"key":"e_1_3_2_1_58_1","unstructured":"Linux Kernel. 2025. KCOV: code coverage for fuzzing. https:\/\/docs.kernel.org\/dev-tools\/kcov.html."},{"key":"e_1_3_2_1_59_1","unstructured":"Linux Kernel. 2025. Universal TUN\/TAP device driver. https:\/\/docs.kernel.org\/networking\/tuntap.html."},{"key":"e_1_3_2_1_60_1","unstructured":"LLVM. 2025. libFuzzer - a library for coverage-guided fuzz testing. https:\/\/llvm.org\/docs\/LibFuzzer.html."},{"key":"e_1_3_2_1_61_1","volume-title":"Unicorefuzz: On the viability of emulation for kernelspace fuzzing. In USENIX WOOT 19.","author":"Maier Dominik","year":"2019","unstructured":"Dominik Maier, Benedikt Radtke, and Bastian Harren. 2019. Unicorefuzz: On the viability of emulation for kernelspace fuzzing. In USENIX WOOT 19."},{"key":"e_1_3_2_1_62_1","volume-title":"Manuel Egele, Edward J Schwartz, and Maverick Woo.","author":"Marie Man\u00e8s Valentin Jean","year":"2019","unstructured":"Valentin Jean Marie Man\u00e8s, HyungSeok Han, Choongwoo Han, Sang Kil Cha, Manuel Egele, Edward J Schwartz, and Maverick Woo. 2019. The art, science, and engineering of fuzzing: A survey. IEEE TSE (2019)."},{"key":"e_1_3_2_1_63_1","first-page":"1986","volume-title":"ICACCS","volume":"1","author":"Mathur Alok","year":"2023","unstructured":"Alok Mathur, Shreyaan Pradhan, Prasoon Soni, Dhruvil Patel, and Rajeshkannan Regunathan. 2023. Automated test case generation using t5 and GPT-3. In ICACCS, Vol. 1. IEEE, 1986-1992."},{"key":"e_1_3_2_1_64_1","volume-title":"NDSS","volume":"2024","author":"Meng Ruijie","year":"2024","unstructured":"Ruijie Meng, Martin Mirchev, Marcel B\u00f6hme, and Abhik Roychoudhury. 2024. Large language model guided protocol fuzzing. In NDSS, Vol. 2024."},{"key":"e_1_3_2_1_65_1","first-page":"1683","article-title":"Breaking through binaries: Compiler-quality instrumentation for better binary-only fuzzing","volume":"21","author":"Nagy Stefan","year":"2021","unstructured":"Stefan Nagy, Anh Nguyen-Tuong, Jason D Hiser, JackWDavidson, and Matthew Hicks. 2021. Breaking through binaries: Compiler-quality instrumentation for better binary-only fuzzing. In USENIX Security 21. 1683-1700.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_66_1","volume-title":"StateAFL: Greybox Fuzzing for Stateful Network Servers. arXiv preprint arXiv:2110.06253","author":"Natella Roberto","year":"2021","unstructured":"Roberto Natella. 2021. StateAFL: Greybox Fuzzing for Stateful Network Servers. arXiv preprint arXiv:2110.06253 (2021)."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"crossref","unstructured":"Roberto Natella and Van-Thuan Pham. 2021. ProFuzzBench: A Benchmark for Stateful Protocol Fuzzing. In ISSTA.","DOI":"10.1145\/3460319.3469077"},{"key":"e_1_3_2_1_68_1","unstructured":"OpenAI. 2022. ChatGPT. https:\/\/chatgpt.com\/."},{"key":"e_1_3_2_1_69_1","unstructured":"Oracle. 2016. kernel-fuzzing: Fuzzers for the Linux kernel. https:\/\/github.com\/oracle\/kernel-fuzzing."},{"key":"e_1_3_2_1_70_1","unstructured":"Shankara Pailoor Andrew Aday and Suman Jana. 2018. MoonShine: Optimizing OS Fuzzer Seed Selection with Trace Distillation. In USENIX Security 18. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/pailoor"},{"key":"e_1_3_2_1_71_1","volume-title":"Digtool: A Virtualization- Based Framework for Detecting Kernel Vulnerabilities. In USENIX Security.","author":"Pan Jianfeng","year":"2017","unstructured":"Jianfeng Pan, Guanglu Yan, and Xiaocao Fan. 2017. Digtool: A Virtualization- Based Framework for Detecting Kernel Vulnerabilities. In USENIX Security."},{"key":"e_1_3_2_1_72_1","first-page":"225","volume-title":"RAID 2020","author":"Peterson Anthony","year":"2020","unstructured":"Anthony Peterson, Samuel Jero, Endadul Hoque, David Choffnes, and Cristina Nita-Rotaru. 2020. aBBRate: Automating BBR Attack Exploration Using a Model-Based Approach. In RAID 2020. USENIX Association, 225-240. https:\/\/www.usenix.org\/conference\/raid2020\/presentation\/peterson"},{"key":"e_1_3_2_1_73_1","volume-title":"AFLNet: a greybox fuzzer for network protocols","author":"Pham Van-Thuan","unstructured":"Van-Thuan Pham, Marcel B\u00f6hme, and Abhik Roychoudhury. 2020. AFLNet: a greybox fuzzer for network protocols. In IEEE ICST."},{"key":"e_1_3_2_1_74_1","unstructured":"NCC Group Plc. 2016. TriforceAFL. https:\/\/github.com\/nccgroup\/TriforceAFL."},{"key":"e_1_3_2_1_75_1","unstructured":"NCC Group Plc. 2016. TriforceLinuxSyscallFuzzer. https:\/\/github.com\/nccgroup\/TriforceLinuxSyscallFuzzer."},{"key":"e_1_3_2_1_76_1","first-page":"7346","article-title":"The effect of sampling temperature on problem solving in large language models. In Findings of the association for computational linguistics","volume":"2024","author":"Renze Matthew","year":"2024","unstructured":"Matthew Renze. 2024. The effect of sampling temperature on problem solving in large language models. In Findings of the association for computational linguistics: EMNLP 2024. 7346-7356.","journal-title":"EMNLP"},{"key":"e_1_3_2_1_77_1","first-page":"279","article-title":"SymDrive: Testing Drivers without Devices","volume":"12","author":"Renzelmann Matthew J","year":"2012","unstructured":"Matthew J Renzelmann, Asim Kadav, and Michael M Swift. 2012. SymDrive: Testing Drivers without Devices. In OSDI 12. 279-292.","journal-title":"OSDI"},{"key":"e_1_3_2_1_78_1","volume-title":"Sok: Prudent evaluation practices for fuzzing","author":"Schloegel Moritz","year":"2024","unstructured":"Moritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard, Tobias Scharnowski, Addison Crump, Arash Ale-Ebrahim, Nicolai Bissantz, Marius Muench, and Thorsten Holz. 2024. Sok: Prudent evaluation practices for fuzzing. In IEEE S&P."},{"key":"e_1_3_2_1_79_1","first-page":"167","article-title":"kAFL:Hardware-Assisted feedback fuzzing for OS kernels","volume":"17","author":"Schumilo Sergej","year":"2017","unstructured":"Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, and Thorsten Holz. 2017. kAFL:Hardware-Assisted feedback fuzzing for OS kernels. In USENIX Security 17. 167-182.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_80_1","volume-title":"Proceedings of EuroSys.","author":"Schumilo Sergej","year":"2022","unstructured":"Sergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi, and Thorsten Holz. 2022. Nyx-net: network fuzzing with incremental snapshots. In Proceedings of EuroSys."},{"key":"e_1_3_2_1_81_1","first-page":"309","article-title":"AddressSanitizer: A fast address sanity checker","volume":"12","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In USENIX ATC 12. 309-318.","journal-title":"USENIX ATC"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"crossref","unstructured":"Parshin Shojaee Iman Mirzadeh Keivan Alizadeh Maxwell Horton Samy Bengio and Mehrdad Farajtabar. 2025. The Illusion of Thinking: Understanding the Strengths and Limitations of Reasoning Models via the Lens of Problem Complexity. https:\/\/ml-site.cdn-apple.com\/papers\/the-illusion-of-thinking.pdf","DOI":"10.70777\/si.v2i6.15919"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"crossref","unstructured":"Dokyung Song Felicitas Hetzelt Dipanjan Das Chad Spensky Yeoul Na Stijn Volckaert Giovanni Vigna Christopher Kruegel Jean-Pierre Seifert and Michael Franz. 2019. PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary. In NDSS.","DOI":"10.14722\/ndss.2019.23176"},{"key":"e_1_3_2_1_84_1","first-page":"46","article-title":"MemorySanitizer: fast detector of uninitialized memory use in C++","author":"Stepanov Evgeniy","year":"2015","unstructured":"Evgeniy Stepanov and Konstantin Serebryany. 2015. MemorySanitizer: fast detector of uninitialized memory use in C++. In CGO. IEEE, 46-55.","journal-title":"CGO. IEEE"},{"key":"e_1_3_2_1_85_1","first-page":"351","article-title":"KSG: Augmenting kernel fuzzing with system call specification generation","volume":"22","author":"Sun Hao","year":"2022","unstructured":"Hao Sun, Yuheng Shen, Jianzhong Liu, Yiru Xu, and Yu Jiang. 2022. KSG: Augmenting kernel fuzzing with system call specification generation. In USENIX ATC 22. 351-366.","journal-title":"USENIX ATC"},{"key":"e_1_3_2_1_86_1","volume-title":"Healer: Relation learning guided kernel fuzzing. In SOSP.","author":"Sun Hao","year":"2021","unstructured":"Hao Sun, Yuheng Shen, Cong Wang, Jianzhong Liu, Yu Jiang, Ting Chen, and Aiguo Cui. 2021. Healer: Relation learning guided kernel fuzzing. In SOSP."},{"key":"e_1_3_2_1_87_1","first-page":"1288","article-title":"SMT solver validation empowered by large pre-trained language models","author":"Sun Maolin","year":"2023","unstructured":"Maolin Sun, Yibiao Yang, Yang Wang, Ming Wen, Haoxiang Jia, and Yuming Zhou. 2023. SMT solver validation empowered by large pre-trained language models. In ASE. IEEE, 1288-1300.","journal-title":"ASE. IEEE"},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"crossref","unstructured":"Xin Tan Yuan Zhang Jiadong Lu Xin Xiong Zhuang Liu and Min Yang. 2023. SyzDirect: Directed Greybox Fuzzing for Linux Kernel. In CCS.","DOI":"10.1145\/3576915.3623146"},{"key":"e_1_3_2_1_89_1","unstructured":"The kernel community. 2025. Introduction to Netlink. https:\/\/docs.kernel.org\/userspace-api\/netlink\/intro.html."},{"key":"e_1_3_2_1_90_1","first-page":"2741","article-title":"SyzVegas: Beating kernel fuzzing odds with reinforcement learning","volume":"21","author":"Wang Daimeng","year":"2021","unstructured":"Daimeng Wang, Zheng Zhang, Hang Zhang, Zhiyun Qian, Srikanth V Krishnamurthy, and Nael Abu-Ghazaleh. 2021. SyzVegas: Beating kernel fuzzing odds with reinforcement learning. In USENIX Security 21. 2741-2758.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_91_1","first-page":"724","article-title":"Superion: Grammaraware greybox fuzzing","author":"Wang Junjie","year":"2019","unstructured":"Junjie Wang, Bihuan Chen, Lei Wei, and Yang Liu. 2019. Superion: Grammaraware greybox fuzzing. In ICSE. 724-735.","journal-title":"ICSE."},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"crossref","unstructured":"Mingzhe Wang Jie Liang Yuanliang Chen Yu Jiang Xun Jiao Han Liu Xibin Zhao and Jiaguang Sun. 2018. SAFL: increasing and accelerating testing coverage with symbolic execution and guided fuzzing. In ICSE.","DOI":"10.1145\/3183440.3183494"},{"key":"e_1_3_2_1_93_1","volume-title":"Selfdefend: Llms can defend themselves against jailbreaking in a practical manner. arXiv preprint arXiv:2406.05498","author":"Wang Xunguang","year":"2024","unstructured":"Xunguang Wang, Daoyuan Wu, Zhenlan Ji, Zongjie Li, Pingchuan Ma, Shuai Wang, Yingjiu Li, Yang Liu, Ning Liu, and Juergen Rahmel. 2024. Selfdefend: Llms can defend themselves against jailbreaking in a practical manner. arXiv preprint arXiv:2406.05498 (2024)."},{"key":"e_1_3_2_1_94_1","volume-title":"Michael Pradel, and Lingming Zhang.","author":"Xia Chunqiu Steven","year":"2023","unstructured":"Chunqiu Steven Xia, Matteo Paltenghi, Jia Le Tian, Michael Pradel, and Lingming Zhang. 2023. Universal fuzzing via large language models. arXiv preprint arXiv:2308.04748 (2023)."},{"key":"e_1_3_2_1_95_1","volume-title":"Demystifying OS Kernel Fuzzing with a Novel Taxonomy. arXiv:2501.16165","author":"Xu Jiacheng","year":"2025","unstructured":"Jiacheng Xu, He Sun, Shihao Jiang, Qinying Wang, Mingming Zhang, Xiang Li, Kaiwen Shen, Peng Cheng, Jiming Chen, and Charles Zhang. 2025. Demystifying OS Kernel Fuzzing with a Novel Taxonomy. arXiv:2501.16165 (2025)."},{"key":"e_1_3_2_1_96_1","unstructured":"Jiacheng Xu Xuhong Zhang Shouling Ji Yuan Tian Binbin Zhao Qinying Wang Peng Cheng and Jiming Chen. 2024. Mock: optimizing kernel fuzzing mutation with context-aware dependency. In NDSS."},{"key":"e_1_3_2_1_97_1","volume-title":"White-box compiler fuzzing empowered by large language models. CoRR abs\/2310.15991","author":"Yang Chenyuan","year":"2023","unstructured":"Chenyuan Yang, Yinlin Deng, Runyu Lu, Jiayi Yao, Jiawei Liu, Reyhaneh Jabbarvand, and Lingming Zhang. 2023. White-box compiler fuzzing empowered by large language models. CoRR abs\/2310.15991 (2023)."},{"key":"e_1_3_2_1_98_1","first-page":"560","article-title":"Kernelgpt: Enhanced kernel fuzzing via large language models","author":"Yang Chenyuan","year":"2025","unstructured":"Chenyuan Yang, Zijie Zhao, and Lingming Zhang. 2025. Kernelgpt: Enhanced kernel fuzzing via large language models. In ASPLOS. 560-573.","journal-title":"ASPLOS."},{"key":"e_1_3_2_1_99_1","first-page":"283","article-title":"Finding and understanding bugs in C compilers","author":"Yang Xuejun","year":"2011","unstructured":"Xuejun Yang, Yang Chen, Eric Eide, and John Regehr. 2011. Finding and understanding bugs in C compilers. In PLDI. 283-294.","journal-title":"PLDI."},{"key":"e_1_3_2_1_100_1","volume-title":"Songfang Huang, Dingyi Fang, Xiaoyang Sun, Lizhong Bian, Haibo Wang, and Zheng Wang.","author":"Ye Guixin","year":"2021","unstructured":"Guixin Ye, Zhanyong Tang, Shin Hwei Tan, Songfang Huang, Dingyi Fang, Xiaoyang Sun, Lizhong Bian, Haibo Wang, and Zheng Wang. 2021. Automated conformance testing for JavaScript engines via deep compiler fuzzing. In PLDI."},{"key":"e_1_3_2_1_101_1","unstructured":"Micha\u0142 Zalewski. 2014. American fuzzy lop. https:\/\/lcamtuf.coredump.cx\/afl\/."},{"key":"e_1_3_2_1_102_1","first-page":"1223","article-title":"How effective are they? exploring large language model based fuzz driver generation","author":"Zhang Cen","year":"2024","unstructured":"Cen Zhang, Yaowen Zheng, Mingqiang Bai, Yeting Li, Wei Ma, Xiaofei Xie, Yuekang Li, Limin Sun, and Yang Liu. 2024. How effective are they? exploring large language model based fuzz driver generation. In ISSTA. 1223-1235.","journal-title":"ISSTA."},{"key":"e_1_3_2_1_103_1","volume-title":"ECG: Augmenting Embedded Operating System Fuzzing via LLM-Based Corpus Generation. TCAD","author":"Zhang Qiang","year":"2024","unstructured":"Qiang Zhang, Yuheng Shen, Jianzhong Liu, Yiru Xu, Heyuan Shi, Yu Jiang, and Wanli Chang. 2024. ECG: Augmenting Embedded Operating System Fuzzing via LLM-Based Corpus Generation. TCAD (2024)."},{"key":"e_1_3_2_1_104_1","volume-title":"Jbshield: Defending large language models from jailbreak attacks through activated concept analysis and manipulation. arXiv preprint arXiv:2502.07557","author":"Zhang Shenyi","year":"2025","unstructured":"Shenyi Zhang, Yuchen Zhai, Keyan Guo, Hongxin Hu, Shengnan Guo, Zheng Fang, Lingchen Zhao, Chao Shen, Cong Wang, and Qian Wang. 2025. Jbshield: Defending large language models from jailbreak attacks through activated concept analysis and manipulation. arXiv preprint arXiv:2502.07557 (2025)."},{"key":"e_1_3_2_1_105_1","doi-asserted-by":"crossref","unstructured":"Zhiyu Zhang Longxing Li Ruigang Liang and Kai Chen. 2025. Unlocking Low Frequency Syscalls in Kernel Fuzzing with Dependency-Based RAG. In ISSTA.","DOI":"10.1145\/3728913"},{"key":"e_1_3_2_1_106_1","first-page":"3273","article-title":"StateFuzz: System Call-BasedState-Aware linux driver fuzzing","volume":"22","author":"Zhao Bodong","year":"2022","unstructured":"Bodong Zhao, Zheming Li, Shisong Qin, Zheyu Ma, Ming Yuan, Wenyu Zhu, Zhihong Tian, and Chao Zhang. 2022. StateFuzz: System Call-BasedState-Aware linux driver fuzzing. In USENIX Security 22. 3273-3289.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_107_1","first-page":"489","article-title":"TCP-Fuzz: Detecting memory and semantic bugs in TCP stacks with fuzzing","volume":"21","author":"Zou Yong-Hao","year":"2021","unstructured":"Yong-Hao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan, Chenggang Qin, and Shi-Min Hu. 2021. TCP-Fuzz: Detecting memory and semantic bugs in TCP stacks with fuzzing. In USENIX ATC 21. 489-502.","journal-title":"USENIX ATC"}],"event":{"name":"CODASPY '26: Sixteenth ACM Conference on Data and Application Security and Privacy","location":"Frankfurt am Main Germany","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Sixteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"deposited":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:28:38Z","timestamp":1781281718000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3800506.3803511"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":107,"alternative-id":["10.1145\/3800506.3803511","10.1145\/3800506"],"URL":"https:\/\/doi.org\/10.1145\/3800506.3803511","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}