FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
Wed 8 Jul 2026 14:00 - 14:10 at MB 2.435 - Fuzzing 2 Chair(s): Roland H. C. Yap

Fuzz testing is widely used in industry and open-source ecosystems, but its effectiveness depends on the quality of fuzz drivers that translate raw fuzzer input into valid function arguments. Automated fuzz driver generation reduces manual effort, but in practice often produces false positive crashes, especially for complex functions. We introduce OSS-Fuzz-Gen, an experimental system for agent-based fuzz driver generation. This paper reports our experience mitigating its false positives using two complementary strategies: constraint-based fuzz driver generation and context-aware crash validation against realistic program entry points. In our evaluation on 1,500 benchmark functions from OSS-Fuzz, these strategies filtered out more than half of crashes initially classified as program errors, at modest additional cost. We distill lessons for deploying LLM-based agents in large-scale fuzzing pipelines.

Wed 8 Jul

Displayed time zone: Eastern Time (US & Canada) change

14:00 - 15:30
Fuzzing 2Research Papers / Industry Papers at MB 2.435
Chair(s): Roland H. C. Yap National University of Singapore
14:00
10m
Talk
Lessons from Mitigating False Positives in Google's OSS-Fuzz-Gen
Industry Papers
Paschal Amusuo Purdue University, Dongge Liu , Ricardo Andres Calvo Mendez Purdue University, Jonathan Metzman Google, Oliver Chang Google, James C. Davis Purdue University
14:10
20m
Talk
Binvariants: Enhancing Fuzzing of Closed-source Binary Executables via Register-level Likely Invariants
Research Papers
Zao Yang University of Utah, Stefan Nagy University of Utah
Pre-print
14:30
20m
Talk
In Bugs We Trust? On Measuring the Randomness of a Fuzzer Benchmarking Outcome
Research Papers
Ardi Madadi Max Planck Institute for Security and Privacy, Seongmin Lee UCLA, Cornelius Aschermann Ruhr-University Bochum, Marcel Böhme MPI for Security and Privacy
Pre-print
14:50
20m
Talk
An Empirical Study of Fuzz Harness Degradation
Research Papers
Philipp Görz Ruhr-University Bochum, Joschua Schilling CISPA Helmholtz Center for Information Security, Nicolai Bissantz Ruhr-University Bochum, Thorsten Holz Max Planck Institute for Security and Privacy
Pre-print
15:10
20m
Talk
SnakeCharmer: Automatic Fuzzing Harness Generation for Pure and Hybrid Python Libraries
Research Papers
Gabriel Sherman University of Utah, Stefan Nagy University of Utah
Pre-print