Taint analysis plays a crucial role in fuzzing by identifying input bytes that significantly influence program behavior. However, existing taint analysis approaches either require heavy- weight instrumentation or incur substantial runtime overhead. In this paper, we propose HFuzz, a novel fuzzing approach that leverages the havoc mutation mode - a fundamental component in modern fuzzers - to perform lightweight taint inference. Our approach operates in two phases: first identifying ”hot bytes” through havoc-based sampling, then using this information to guide subsequent mutations. By utilizing existing fuzzing components rather than adding extra execution, HFuzz achieves efficient taint inference while maintaining the simplicity and scalability of conventional fuzzers.
Tue 29 AprDisplayed time zone: Eastern Time (US & Canada) change
16:00 - 17:30 | Tool Competitions 2 and Award CeremonySBFT at 104 Chair(s): Addison Crump CISPA Helmholtz Center for Information Security, Matteo Biagiola Università della Svizzera italiana, Alessio Gambi Austrian Institute of Technology (AIT), Vincenzo Riccio University of Udine | ||
16:00 15mPaper | SBFT Tool Competition 2025 - Java Test Case Generation Track SBFT Fitsum Kifetew Fondazione Bruno Kessler, Yun Lin Shanghai Jiao Tong University, Davide Prandi Fondazione Bruno Kessler | ||
16:15 15mPaper | EvoFuzz at the SBFT 2025 Java Tool Competition SBFT Seokhyeon Moon , Jinwoo Choi Technology Research, Samsung SDS, Seoul, Republic of Korea, Yoon-Chan Jhi Technology Research, Samsung SDS, Seoul, South Korea | ||
16:30 15mPaper | SBFT Tool Competition 2025 - Fuzzing Track SBFT Addison Crump CISPA Helmholtz Center for Information Security, Matteo Leonelli CISPA Helmholtz Center for Information Security, Sahil Sihag CISPA Helmholtz Center for Information Security | ||
16:45 15mPaper | KRAKEN-FUZZ: Minimizing Corpus During Fuzzing SBFT Jikai Wang Huazhong University of Science and Technology, Yuekang Li UNSW, Kailong Wang Huazhong University of Science and Technology | ||
17:00 15mPaper | HFuzz: Havoc Mode Guided Fuzzing SBFT Yuchong Xie Hong Kong University of Science and Technology, Dongdong She HKUST (The Hong Kong University of Science and Technology) |