Automating Fuzzing Workflows with LLM Agents •

Automating Fuzzing Workflows with LLM Agents •
1 / 1
Automating Fuzzing Workflows with LLM Agents Fuzzing is a cornerstone of software security testingyet crafting and tuning a full workflow from instrumentation to crash triage demands expert effort and time. Recent advances in large

Related Topics

Download this presentation From Below

"Automating Fuzzing Workflows with LLM Agents •" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

01
Automating Fuzzing Workflows with LLM Agents • Fuzzing is a cornerstone of software security testing—yet crafting and tuning a full workflow from instrumentation to crash triage demands expert effort and time. • Recent advances in large language models (LLMs) suggest they can act as intelligent agents, handling complex developer tasks via natural-language prompts and tool integration. • We introduce the Auto Fuzzing Challenge, in which a suite of LLM-based agents collectively automates: – Source-code instrumentation & build configuration – Dynamic harness generation for APIs & binaries – Seed corpus and dictionary creation – Parallelized execution, scheduling, and monitoring of fuzzers – Automated crash deduplication and root-cause analysis • A central Manager Agent coordinates agent workflows, feedback loops, and optimization, dramatically reducing manual overhead and accelerating bug discovery. Method for Automated Fuzzing
Agent-oriented Architecture • Define clear I/O for each agent: receive input message from manager agent and returns summary of actions. • Use a Manager Agent to dispatch tasks, collect outputs, handle retries and error propagation.
Agents to be coded:
Build and Instrumentation: Builder Agent: Automates compilation of the target with fuzzing instrumentation and optional sanitizers.
Harness Generation Harness Generator Agent: Generates a test harness that feeds inputs into the target’s APIs or entry points.
Seed & Dictionary Generation Seed Generator Agent: Collects and synthesizes diverse input seeds to maximize code coverage. Dictionary Generator Agent: Extracts and updates token dictionaries relevant to the target’s input formats.
Execution Fuzzer Executor Agent: Launches, monitors, and dynamically tunes multiple fuzzers in parallel using performance feedback.
Crash Analysis Crash Analyzer Agent: Deduplicates, triages, and produces detailed reports on unique crashes and their root causes.
Orchestration & Feedback Loops • Manager Agent coordinates agent lifecycle: triggers Harness → Seed/Dict → Build → Execute → Analyze. • Incorporate feedback: e.g. if coverage plateaus, ask Seed Agent for new inputs or reconfigure fuzzers. • Log everything for reproducibility and future training data. Introduction References:
Google Fuzzing Tutorial: https://github.com/google/fuzzing
Lyu, Y., Xie, Y., Chen, P., and Chen, H. Prompt Fuzzing for Fuzz Driver Generation. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, December 2024, 3793-3807. doi:10.1145/3658644.367039.
Zhang, C., Zheng, Y., Bai, M., Li, Y., Ma, W., Xie, X., Li, Y., Sun, L., and Liu, Y. How effective are they? Exploring large language model based fuzz driver generation. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, September 2024, 1223-1235. doi:10.1145/3650212.3680355 Automated Fuzzing Workflow Results All agents successfully automated the full fuzzing pipeline—from code instrumentation and harness generation to execution scheduling and crash analysis—without human intervention. This end-to-end automation uncovered multiple unique crashes and demonstrated the effectiveness of an LLM-driven fuzzing workflow.
A successful result is shown in the screenshot of the log below: Conclusion We demonstrate that a coordinated suite of LLM-based agents can fully automate an end-to-end fuzzing workflow, from source-code instrumentation to crash root-cause analysis. This agent-driven approach:
Eliminates manual scripting and specialized expertise in build configuration, harness creation, and crash triage.
Accelerates bug discovery by dynamically adapting fuzzing parameters, seed sets, and dictionaries.
Provides modularity and extensibility—new agents or fuzzers can be added with minimal reconfiguration.
Future work will integrate reinforcement-learning-driven scheduling for smarter fuzzer allocation, extend support to additional build systems and target languages, and evaluate long-term learning effects as agents accumulate domain knowledge.<br>