FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
Wed 8 Jul 2026 11:10 - 11:30 at MB 3.430 - Fuzzing 1 Chair(s): Chengyu Zhang

Smart contracts underpin a wide range of decentralized applications—from financial services to supply-chain management—but their immutability and direct control of assets magnify the impact of any security bugs. Although many fuzz approaches have been proposed and have demonstrated their effectiveness in uncovering vulnerabilities, existing methods often rely on unguided random mutation scheduling, generate redundant inputs, and fail to adapt to smart contract-specific characteristics. To overcome these challenges, we present FuzzMaster, a feedback-driven fuzzing framework that combines deep reinforcement learning (DRL) with lightweight probabilistic scheduling to steer mutation selection at runtime intelligently. By continuously analyzing execution feedback—code coverage, function-call sequences, and vulnerability signals—FuzzMaster’s DRL agent and probabilistic tables prioritize high-impact mutations and avoid wasted effort on redundant seeds. On standard VeriSmart and SmartBugs benchmarks, FuzzMaster achieves a 66.2% detection rate with 100% precision (versus 46.9% for ItyFuzz and 43.1% for Confuzzius) and uncovers most bugs within the first second of execution. Meanwhile, in real-world Ethereum contracts, FuzzMaster identified 97 vulnerabilities in 6 categories. These results demonstrate that dynamic, vulnerability-aware mutation scheduling can dramatically improve both the efficiency and effectiveness of smart contract fuzz testing.

Wed 8 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
Fuzzing 1Journal-First Paper / Research Papers at MB 3.430
Chair(s): Chengyu Zhang Loughborough University
10:30
20m
Talk
Fuzzing-based mutation testing of C/C++ software in cyber-physical systems
Journal-First Paper
Jaekwon Lee Kangwon National University, South Korea, Fabrizio Pastore University of Luxembourg, Lionel Briand University of Ottawa, Canada; Lero centre, University of Limerick, Ireland
Link to publication DOI Pre-print
10:50
20m
Talk
ChainDelta: Automatic Patch-based Exploit Generation for Ethereum with Fuzzing Agents
Research Papers
Mingxi Ye Sun Yat-sen University, Yuhong Nan Sun Yat-sen University, Zhijie Zhong School of Software Engineering, Sun Yat-sen University, Jianzhong Su Sun Yat-sen University, Xingwei Lin Zhejiang University, Peilin Zheng Sun Yat-sen University, Zibin Zheng Sun Yat-sen University
11:10
20m
Talk
Adaptive Mutation Scheduling with Deep Reinforcement Learning for Smart Contract Fuzzing
Research Papers
Qianqian Pang zhejang university, Xin Yin Zhejiang University, Tingting Bi The University of Melbourne, Lingfeng Bao Zhejiang University, Chao Ni Zhejiang University, Xiaohu Yang Zhejiang University
11:30
20m
Talk
OCPPuzz: Specification-driven Fuzzing of Charging Station Management Systems with Large Language Model
Research Papers
Jongchan Hong Sungkyunkwan University, Jaewon Kim Sungkyunkwan University, Sungjae Hwang Sungkyunkwan University
DOI Pre-print
11:50
20m
Talk
PROGnosticator: Testing Source-to-Source Code Translators via Construct-oriented Fuzzing
Research Papers
Yeaseen Arafat University of Utah, Stefan Nagy University of Utah
Pre-print