Adaptive Mutation Scheduling with Deep Reinforcement Learning for Smart Contract Fuzzing
Smart contracts underpin a wide range of decentralized applications—from financial services to supply-chain management—but their immutability and direct control of assets magnify the impact of any security bugs. Although many fuzz approaches have been proposed and have demonstrated their effectiveness in uncovering vulnerabilities, existing methods often rely on unguided random mutation scheduling, generate redundant inputs, and fail to adapt to smart contract-specific characteristics. To overcome these challenges, we present FuzzMaster, a feedback-driven fuzzing framework that combines deep reinforcement learning (DRL) with lightweight probabilistic scheduling to steer mutation selection at runtime intelligently. By continuously analyzing execution feedback—code coverage, function-call sequences, and vulnerability signals—FuzzMaster’s DRL agent and probabilistic tables prioritize high-impact mutations and avoid wasted effort on redundant seeds. On standard VeriSmart and SmartBugs benchmarks, FuzzMaster achieves a 66.2% detection rate with 100% precision (versus 46.9% for ItyFuzz and 43.1% for Confuzzius) and uncovers most bugs within the first second of execution. Meanwhile, in real-world Ethereum contracts, FuzzMaster identified 97 vulnerabilities in 6 categories. These results demonstrate that dynamic, vulnerability-aware mutation scheduling can dramatically improve both the efficiency and effectiveness of smart contract fuzz testing.
Wed 8 JulDisplayed time zone: Eastern Time (US & Canada) change
10:30 - 12:30 | Fuzzing 1Journal-First Paper / Research Papers at MB 3.430 Chair(s): Chengyu Zhang Loughborough University | ||
10:30 20mTalk | Fuzzing-based mutation testing of C/C++ software in cyber-physical systems Journal-First Paper Jaekwon Lee Kangwon National University, South Korea, Fabrizio Pastore University of Luxembourg, Lionel Briand University of Ottawa, Canada; Lero centre, University of Limerick, Ireland Link to publication DOI Pre-print | ||
10:50 20mTalk | ChainDelta: Automatic Patch-based Exploit Generation for Ethereum with Fuzzing Agents Research Papers Mingxi Ye Sun Yat-sen University, Yuhong Nan Sun Yat-sen University, Zhijie Zhong School of Software Engineering, Sun Yat-sen University, Jianzhong Su Sun Yat-sen University, Xingwei Lin Zhejiang University, Peilin Zheng Sun Yat-sen University, Zibin Zheng Sun Yat-sen University | ||
11:10 20mTalk | Adaptive Mutation Scheduling with Deep Reinforcement Learning for Smart Contract Fuzzing Research Papers Qianqian Pang zhejang university, Xin Yin Zhejiang University, Tingting Bi The University of Melbourne, Lingfeng Bao Zhejiang University, Chao Ni Zhejiang University, Xiaohu Yang Zhejiang University | ||
11:30 20mTalk | OCPPuzz: Specification-driven Fuzzing of Charging Station Management Systems with Large Language Model Research Papers Jongchan Hong Sungkyunkwan University, Jaewon Kim Sungkyunkwan University, Sungjae Hwang Sungkyunkwan University DOI Pre-print | ||
11:50 20mTalk | PROGnosticator: Testing Source-to-Source Code Translators via Construct-oriented Fuzzing Research Papers Pre-print | ||