{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:16:11Z","timestamp":1782846971980,"version":"3.54.5"},"reference-count":52,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Ensuring data privacy during computation is a critical challenge in many security systems. Fully Homomorphic  \nEncryption (FHE) addresses this gap by enabling multiple operations on encrypted data without decryption,  \nthus ensuring privacy is preserved throughout computation. However, existing cryptographic testing tools  \nare unable to test the core functionality of FHE, which is the execution of computations on encrypted data.  \nThey are expertly designed to generate structured data for testing cryptographic algorithms. This structural  \nmismatch, combined with a lack of awareness of FHE-specific noise management, leads them to generate  \ninvalid test inputs that fail to probe FHE libraries\u2019 core logic.  \nTo address this gap, we propose Eidolon, a noise-aware fuzzer. It directs mutations toward arithmetic  \nexpressions that explore the computational space defined by the noise budget. As its test oracle, Eidolon  \nleverages Equivalence Expression Transformation, which transforms a standard arithmetic expression into  \ntwo mathematically identical but structurally different forms (e.g., Factored, Horner) to detect inconsistencies  \nin their outputs. We evaluated Eidolon on SEAL, OpenFHE, HElib, and TFHE. Compared with existing  \ncryptographic and grammar-based fuzzers, Eidolon achieves 28.7%, 45.5%, 75.6%, and 37.6% higher final code  \ncoverage than CLFuzz, Cryptofuzz, CDF, and Peach, respectively. In total, Eidolon uncovered 20 previously  \nunknown bugs, 13 of which have been fixed and 12 assigned CVEs.<\/jats:p>","DOI":"10.1145\/3808109","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"2282-2303","source":"Crossref","is-referenced-by-count":0,"title":["Eidolon: Perform Noise-Aware Fuzzing on FHE Libraries via Equivalence Expression Transformation"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-3117-8196","authenticated-orcid":false,"given":"Zhensheng","family":"Xian","sequence":"first","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9904-7734","authenticated-orcid":false,"given":"Zhen","family":"Yan","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2701-4296","authenticated-orcid":false,"given":"Yuanliang","family":"Chen","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2227-9896","authenticated-orcid":false,"given":"Xuelian","family":"Cao","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1360-9814","authenticated-orcid":false,"given":"Fuchen","family":"Ma","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5379-2100","authenticated-orcid":false,"given":"Dalong","family":"Shi","sequence":"additional","affiliation":[{"name":"Aviation Industry Corporation of China, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0955-503X","authenticated-orcid":false,"given":"Yu","family":"Jiang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Jonathan Anastasia and Derek Ho. 2024. Stepping through the looking glass of privacy-enhancing technologies. Mastercard. https:\/\/www.mastercard.com\/news\/perspectives\/2024\/stepping-through-the-looking-glass-of-privacyenhancing-technologies\/"},{"key":"e_1_2_1_2_1","unstructured":"Apple. 2024. Combining Machine Learning and Homomorphic Encryption in the Apple Ecosystem. https: \/\/machinelearning.apple.com\/research\/homomorphic-encryption"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1985795"},{"key":"e_1_2_1_4_1","first-page":"2017","article-title":"Automated testing of crypto software using differential fuzzing","volume":"7","author":"Aumasson Jean-Philippe","year":"2017","unstructured":"Jean-Philippe Aumasson and Yolan Romailler. 2017. Automated testing of crypto software using differential fuzzing. Black Hat USA 7 (2017), 2017.","journal-title":"Black Hat USA"},{"key":"e_1_2_1_5_1","unstructured":"Ahmad Al Badawi Andreea Alexandru Jack Bates Flavio Bergamaschi David Bruce Cousins Saroja Erabelli Nicholas Genise Shai Halevi Hamish Hunt Andrey Kim Yongwoo Lee Zeyu Liu Daniele Micciancio Carlo Pascoe Yuriy Polyakov Ian Quah Saraswathy R.V. Kurt Rohloff Jonathan Saylor Dmitriy Suponitsky Matthew Triplett Vinod Vaikuntanathan and Vincent Zucca. 2022. OpenFHE: Open-Source Fully Homomorphic Encryption Library. Cryptology ePrint Archive Paper 2022\/915. https:\/\/eprint.iacr.org\/2022\/915 https:\/\/eprint.iacr.org\/2022\/915."},{"key":"e_1_2_1_6_1","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1186\/s12920-020-0719-9","article-title":"Optimized homomorphic encryption solution for secure genome-wide association studies","volume":"13","author":"Blatt Marcelo","year":"2020","unstructured":"Marcelo Blatt, Alexander Gusev, Yuriy Polyakov, Kurt Rohloff, and Vinod Vaikuntanathan. 2020. Optimized homomorphic encryption solution for secure genome-wide association studies. BMC Medical Genomics 13, Suppl 7 (2020), 83.","journal-title":"BMC Medical Genomics"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_50"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2633600"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3143561"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2016.176"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-78381-9_14"},{"key":"e_1_2_1_12_1","volume-title":"International Conference on Selected Areas in Cryptography. Springer, 347-368","author":"Cheon Jung Hee","year":"2018","unstructured":"Jung Hee Cheon, Kyoohyung Han, Andrey Kim, Miran Kim, and Yongsoo Song. 2018. A full RNS variant of approximate homomorphic encryption. In International Conference on Selected Areas in Cryptography. Springer, 347-368."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70694-8_15"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-019-09319-x"},{"key":"e_1_2_1_15_1","unstructured":"Wikipedia contributors. 2025. Horner's method. https:\/\/en.wikipedia.org\/wiki\/Horner%27s_method Accessed: 2025-09-12."},{"key":"e_1_2_1_16_1","volume-title":"Cryptographers' Track at the RSA Conference","author":"Costache Ana","unstructured":"Ana Costache and Nigel P Smart. 2016. Which ring based somewhat homomorphic encryption scheme is best?. In Cryptographers' Track at the RSA Conference. Springer, 325-340."},{"key":"e_1_2_1_17_1","volume-title":"Somewhat practical fully homomorphic encryption. Cryptology ePrint Archive","author":"Fan Junfeng","year":"2012","unstructured":"Junfeng Fan and Frederik Vercauteren. 2012. Somewhat practical fully homomorphic encryption. Cryptology ePrint Archive (2012)."},{"key":"e_1_2_1_18_1","volume-title":"14th USENIX Workshop on Offensive Technologies (WOOT 20)","author":"Fioraldi Andrea","year":"2020","unstructured":"Andrea Fioraldi, Dominik Maier, Heiko Ei\u00dffeldt, and Marc Heuse. 2020. AFL++: Combining Incremental Steps of Fuzzing Research. In 14th USENIX Workshop on Offensive Technologies (WOOT 20). USENIX Association."},{"key":"e_1_2_1_19_1","unstructured":"Craig Gentry. 2009. A fully homomorphic encryption scheme. Stanford university."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1666420.1666444"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_49"},{"key":"e_1_2_1_22_1","volume-title":"Annual cryptology conference","author":"Gentry Craig","unstructured":"Craig Gentry, Amit Sahai, and Brent Waters. 2013. Homomorphic encryption from learning with errors: Conceptuallysimpler, asymptotically-faster, attribute-based. In Annual cryptology conference. Springer, 75-92."},{"key":"e_1_2_1_23_1","unstructured":"Google. 2015. American Fuzzy Lop. https:\/\/github.com\/google\/AFL"},{"key":"e_1_2_1_24_1","unstructured":"Google. 2019. Project Wycheproof. https:\/\/github.com\/google\/wycheproof."},{"key":"e_1_2_1_25_1","unstructured":"Google. 2021. AddressSanitizer. https:\/\/clang.llvm.org\/docs\/AddressSanitizer.html."},{"key":"e_1_2_1_26_1","unstructured":"Google. 2021. UndefinedBehaviorSanitizer. https:\/\/clang.llvm.org\/docs\/UndefinedBehaviorSanitizer.html."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-020-09368-7"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3387940.3392252"},{"key":"e_1_2_1_29_1","unstructured":"HElib. 2023. HElib release v2.3.0. https:\/\/github.com\/homenc\/HElib\/releases\/tag\/v2.3.0"},{"key":"e_1_2_1_30_1","unstructured":"homenc. 2025. HElib. https:\/\/github.com\/homenc\/HElib. Accessed: 2025-08-19"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594334"},{"key":"e_1_2_1_32_1","unstructured":"LLVM. 2025. LibFuzzer. https:\/\/llvm.org\/docs\/LibFuzzer.html Accessed: 2025-09-09."},{"key":"e_1_2_1_33_1","unstructured":"Microsoft. 2025. SymCrypt. https:\/\/github.com\/microsoft\/SymCrypt Accessed: 2025-09-11."},{"key":"e_1_2_1_34_1","volume-title":"Zachary NJ Peterson, et al","author":"Miller Charlie","year":"2007","unstructured":"Charlie Miller, Zachary NJ Peterson, et al. 2007. Analysis of mutation and generation-based fuzzing. Independent Security Evaluators, Tech. Rep 4 (2007)."},{"key":"e_1_2_1_35_1","unstructured":"Mozilla Security Team. 2025. Peach Fuzzer. https:\/\/github.com\/MozillaSecurity\/peach Accessed: 2025-09-09."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464817"},{"key":"e_1_2_1_37_1","unstructured":"OpenFHE. 2024. OpenFHE release v1.2.1. https:\/\/github.com\/openfheorg\/openfhe-development\/releases\/tag\/v1.2.1"},{"key":"e_1_2_1_38_1","unstructured":"OpenSSL. 2025. OpenSSL. https:\/\/github.com\/openssl\/openssl Accessed: 2025-09-11."},{"key":"e_1_2_1_39_1","first-page":"644","article-title":"Testing and understanding deviation behaviors in fhe-hardened machine learning models","author":"Peng Yiteng","year":"2025","unstructured":"Yiteng Peng, Daoyuan Wu, Zhibo Liu, Dongwei Xiao, Zhenlan Ji, Juergen Rahmel, and Shuai Wang. 2025. Testing and understanding deviation behaviors in fhe-hardened machine learning models. In IEEE Computer Society. 644-644.","journal-title":"IEEE Computer Society."},{"key":"e_1_2_1_40_1","unstructured":"Perforce. 2025. Klocwork. https:\/\/www.perforce.com\/products\/klocwork"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.5555\/3488766.3488804"},{"key":"e_1_2_1_42_1","volume-title":"https:\/\/github.com\/Microsoft\/SEAL. Microsoft Research","author":"SEAL","unstructured":"SEAL 2023. Microsoft SEAL (release 4.1). https:\/\/github.com\/Microsoft\/SEAL. Microsoft Research, Redmond, WA.."},{"key":"e_1_2_1_43_1","unstructured":"SEAL. 2024. SEAL release v4.1.2. https:\/\/github.com\/microsoft\/SEAL\/releases\/tag\/v4.1.2"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1480881.1480915"},{"key":"e_1_2_1_45_1","unstructured":"OpenFHE Development Team. 2025. Addition for CKKS FLEXIBLE* modes at multiplicative depth = 0 returns incorrect results for batch size = 1 or 2. https:\/\/github.com\/openfheorg\/openfhe-development\/issues\/728 Accessed: 2025-08-19."},{"key":"e_1_2_1_46_1","volume-title":"TFHE release v1.0.1. https:\/\/github.com\/tfhe\/tfhe\/releases\/tag\/v1.0.1","author":"TFHE.","year":"2017","unstructured":"TFHE. 2017. TFHE release v1.0.1. https:\/\/github.com\/tfhe\/tfhe\/releases\/tag\/v1.0.1, 2017."},{"key":"e_1_2_1_47_1","first-page":"101","article-title":"A critique and improvement of the CL common language effect size statistics of McGraw and Wong","volume":"25","author":"Vargha Andr\u00e1s","year":"2000","unstructured":"Andr\u00e1s Vargha and Harold D Delaney. 2000. A critique and improvement of the CL common language effect size statistics of McGraw and Wong. Journal of Educational and Behavioral Statistics 25, 2 (2000), 101-132.","journal-title":"Journal of Educational and Behavioral Statistics"},{"key":"e_1_2_1_48_1","volume-title":"International Conference on Financial Cryptography and Data Security. Springer, 213-230","author":"Varia Mayank","year":"2015","unstructured":"Mayank Varia, Sophia Yakoubov, and Yang Yang. 2015. HEtest: A homomorphic encryption testing framework. In International Conference on Financial Cryptography and Data Security. Springer, 213-230."},{"key":"e_1_2_1_49_1","unstructured":"Guido Vranken. 2025. Cryptofuzz. https:\/\/github.com\/guidovranken\/cryptofuzz Accessed: 2025-08-19."},{"key":"e_1_2_1_50_1","unstructured":"Wikipedia contributors. 2025. Homomorphic encryption. https:\/\/en.wikipedia.org\/wiki\/Homomorphic_encryption Accessed: 2025-08-19."},{"key":"e_1_2_1_51_1","first-page":"1309","volume-title":"Proceedings of the ACM on Programming Languages 8, OOPSLA2","author":"Zhou Chijin","year":"2024","unstructured":"Chijin Zhou, Bingzhou Qian, Gwihwan Go, Quan Zhang, Shanshan Li, and Yu Jiang. 2024. Polyjuice: Detecting miscompilation bugs in tensor compilers with equality saturation based rewriting. Proceedings of the ACM on Programming Languages 8, OOPSLA2 (2024), 1309-1335."},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3628160"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3808109","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:37:16Z","timestamp":1782844636000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3808109"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":52,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808109"],"URL":"https:\/\/doi.org\/10.1145\/3808109","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}