arXiv:2503.00795cs.SEcs.AI2025-03被引 2

用大模型提升模糊测试可靠性,破解驱动生成难题

Towards Reliable LLM-Driven Fuzz Testing: Vision and Road Ahead

  • 提出可靠大模型模糊测试的愿景,聚焦驱动与种子生成
  • 指出当前方案存在驱动有效率低、种子质量差等瓶颈
  • 适合安全测试、自动化开发人员关注,推动工业落地

模糊测试是软件安全评估的关键环节,但其效果高度依赖有效的模糊驱动和多样化的初始输入。近年来,大语言模型(LLMs)为自动化模糊测试(LLM4Fuzz)带来变革性潜力,尤其在生成驱动和种子方面。然而,现有LLM4Fuzz方案面临严重可靠性挑战,包括驱动有效率低、种子质量与多样性权衡困难,阻碍实际应用。本文旨在分析LLM驱动模糊测试的可靠性瓶颈,探索潜在研究方向。首先综述LLM在软件工程中的发展现状,强调构建可靠LLM4Fuzz的必要性。随后描绘未来愿景:可靠的LLM4Fuzz将重塑行业软件测试与安全格局,惠及开发者与经济可及性。最后提出未来研究路线,识别关键挑战并给出具体建议,旨在激发领域创新,推动可靠LLM4Fuzz成为现代软件测试的核心组成部分。

原文摘要 · Abstract (English)

Fuzz testing is a crucial component of software security assessment, yet its effectiveness heavily relies on valid fuzz drivers and diverse seed inputs. Recent advancements in Large Language Models (LLMs) offer transformative potential for automating fuzz testing (LLM4Fuzz), particularly in generating drivers and seeds. However, current LLM4Fuzz solutions face critical reliability challenges, including low driver validity rates and seed quality trade-offs, hindering their practical adoption. This paper aims to examine the reliability bottlenecks of LLM-driven fuzzing and explores potential research directions to address these limitations. It begins with an overview of the current development of LLM4SE and emphasizes the necessity for developing reliable LLM4Fuzz solutions. Following this, the paper envisions a vision where reliable LLM4Fuzz transforms the landscape of software testing and security for industry, software development practitioners, and economic accessibility. It then outlines a road ahead for future research, identifying key challenges and offering specific suggestions for the researchers to consider. This work strives to spark innovation in the field, positioning reliable LLM4Fuzz as a fundamental component of modern software testing.

模糊测试大模型软件安全自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。