Baike.dev
All toolsAI codingTrendingOpen sourceNewsSubmit
Log in
< Back to tools
P

paper_collection

> 开发工具
Open source

Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to read or have already read

1.4K stars0 likes0 views
WebsiteGitHub

About

Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to read or have already read

Note

The sole purpose of this repository is to help me organize recent academic papers related to fuzzing, binary analysis, IoT security, and general exploitation. This is a non-exhausting list, even though I'll try to keep it updated... Feel free to suggest decent papers via a PR.

Table of Contents

  • Note
    • Table of Contents
    • Read & Tagged
    • Unread
      • General fuzzing implementations
      • AI/LLM
      • IoT fuzzing
      • Firmware Emulation
      • Network fuzzing
      • Kernel fuzzing
      • Format specific fuzzing
      • Exploitation
      • Static Binary Analysis
      • Misc
      • Surveys, SoKs, and Studies

Read & Tagged

  • 2023 - Dissecting American Fuzzy Lop A FuzzBench Evaluation ✓
    • Tags:: AFL, collisions, hitcounts, timeout, novelty search, corpus culling, score calculation, corpus scheduling, splicing
  • 2022 - DARWIN: Survival of the Fittest Fuzzing Mutators ✓
    • Tags: mutation scheduling, evolution strategy, AFL, AFL-MOpT, fuzzbench, magma, ecofuzz
  • 2022 - Removing Uninteresting Bytes in Software Fuzzing ✓
    • Tags: seed optimization, seed minimization, diar, coverage-guided
  • 2021 - An Empirical Study of OSS-Fuzz Bugs ✓
    • Tags: flaky bugs, clusterfuzz, sanitizer, bug detection, bug classification, time-to-fix, time-to-detect
  • 2020 - Corpus Distillation for Effective Fuzzing ✓
    • Tags: corpus minimization, afl-cmin, google fuzzer test suite, FTS, minset, AFL
  • 2020 - Symbolic execution with SymCC: Don't interpret, compile! ✓
    • Tags: KLEE, QSYM, LLVM, C, C++, compiler, symbolic execution, concolic execution, source code level, IR, angr, Z3, DARPA corpus, AFL
  • 2020 - WEIZZ: Automatic Grey-Box Fuzzing for Structured Binary Formats ✓
    • Tags: REDQUEEN, chunk-based formats, AFLSmart, I2S, checksums, magix bytes, QEMU, Eclipser, short fuzzing runs,
  • 2020 - Efficient Binary-Level Coverage Analysis ✓
    • Tags: bcov, detour + trampoline, basic block coverage, sliced microexecution, superblocks, strongly connected components, dominator graph, BAP, angr, IDA, DynamoRIO, Intel PI, BAP, angr, IDA, DynamoRIO, Intel PIN
  • 2020 - Test-Case Reduction via Test-Case Generation: Insights From the Hypothesis Reducer ✓
    • Tags: Test case reducer, property based testing, CSmith, test case generation, hierachical delta debugging
  • 2020 - AFL++: Combining Incremental Steps of Fuzzing Research ✗
    • Tags: AFL++, AFL, MOpt, LAF-Intel, Fuzzbench, Ngram, RedQueen, Unicorn, QBDI, CmpLog, AFLFast
  • 2020 - FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal Firmware ✓
    • Tags: Ghdira, static analysis, sound disassembly, base address finder, BLE, vulnerability discovery
  • 2020 - P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface Modeling ✓
    • Tags: HALucinator, emulation, firmware, QEMU, AFL, requires source, MCU, peripheral abstraction
  • 2020 - What Exactly Determines the Type? Inferring Types with Context ✓
    • Tags: context assisted type inference, stripped binaries, variable and type reconstruction, IDA Pro, Word2Vec, CNN,
  • 2020 - Causal Testing: Understanding Defects’ Root Causes ✓
    • Tags: Defects4J, causal relationships, Eclipse plugin, unit test mutation, program trace diffing, static value diffing, user study
  • 2020 - AURORA: Statistical Crash Analysis for Automated Root Cause Explanation ⚠
    • Tags: RCA, program traces, input diversification, Intel PIN, Rust, CFG,
  • 2020 - ParmeSan: Sanitizer-guided Greybox Fuzzing ✓
    • Tags: interprocedural CFG, data flow analysis, directed fuzzing (DGF), disregarding 'hot paths', LAVA-M based primitives, LLVM, Angora, AFLGo, ASAP, santizer dependent
  • 2020 - Magma: A Ground-Truth Fuzzing Benchmark ✓
    • Tags: best practices, fuzzer benchmarking, ground truth, Lava-M
  • 2020 - Fitness Guided Vulnerability Detection with Greybox Fuzzing ✓
    • Tags: AFL, vuln specific fitness metric (headroom), buffer/integer overflow detection, AFLGo, pointer analysis, CIL, bad benchmarking
  • 2020 - GREYONE: Data Flow Sensitive Fuzzing ✓
    • Tags: data-flow fuzzing, taint-guided mutation, input prioritization, constraint conformance, REDQUEEN, good evaluation, VUzzer
  • 2020 - FairFuzz-TC: a fuzzer targeting rare branches ✓
    • Tags: AFL, required seeding, branch mask
  • 2020 - Fitness Guided Vulnerability Detection with Greybox Fuzzing ✓
    • Tags: AFL, vuln specific fitness metric (headroom), buffer/integer overflow detection, AFLGo, pointer analysis, CIL, bad evaluation
  • 2020 - TOFU: Target-Oriented FUzzer ✓
    • Tags: DGF, structured mutations, staged fuzzing/learning of cli args, target fitness, structure aware, Dijkstra for priority, AFLGo, Superion
  • 2020 - FuZZan: Efficient Sanitizer Metadata Design for Fuzzing ✓
    • Tags:: sanitizer metadata, optimization, ASAN, MSan, AFL
  • 2020 - Boosting Fuzzer Efficiency: An Information Theoretic Perspective ✓
    • Tags:: Shannon entropy, seed power schedule, libfuzzer, active SLAM, DGF, fuzzer efficiency
  • 2020 - Learning Input Tokens for Effective Fuzzing ✓
    • Tags: dynamic taint tracking, parser checks, magic bytes, creation of dict inputs for fuzzers
  • 2020 - A Review of Memory Errors Exploitation in x86-64 ✓
    • Tags: NX, canaries, ASLR, new mitigations, mitigation evaluation, recap on memory issues
  • 2020 - SoK: The Progress, Challenges, and Perspectives of Directed Greybox Fuzzing ✓
    • Tags: SoK, directed grey box fuzzing, AFL, AFL mutation operators, DGF vs CGF
  • 2020 - MemLock: Memory Usage Guided Fuzzing ✓
    • Tags: memory consumption, AFL, memory leak, uncontrolled-recursion, uncontrolled-memory-allocation, static analysis
  • 2019 - Matryoshka: Fuzzing Deeply Nested Branches ✓
    • Tags: AFL, QSYM, Angora, path constraints, nested conditionals, (post) dominator trees, gradient descent, REDQUEEN, LAVA-M
  • 2019 - Building Fast Fuzzers ✓
    • Tags: grammar based fuzzing, optimization, bold claims, comparison to badly/non-optimized fuzzers, python, lots of micro-optimizations, nice protocolling of failures, bad ASM optimization
  • 2019 - Not All Bugs Are the Same: Understanding, Characterizing, and Classifying the Root Cause of Bugs ✓
    • Tags: RCA via bug reports, classification model, F score,
  • 2019 - AntiFuzz: Impeding Fuzzing Audits of Binary Executables ✓
    • Tags: anti fuzzing, prevent crashes, delay executions, obscure coverage information, overload symbolic execution
  • 2019 - MOpt: Optimized Mutation Scheduling for Fuzzers ✓
    • Tags: mutation scheduling, particle swarm optimization (PSO), AFL, AFL mutation operators, VUzzer,
  • 2019 - FuzzFactory: Domain-Specific Fuzzing with Waypoints ✓
    • Tags: domain-specific fuzzing, AFL, LLVM, solve hard constraints like cmp, find dynamic memory allocations, binary-based
  • 2019 - Fuzzing File Systems via Two-Dimensional Input Space Exploration ✓
    • Tags: Ubuntu, file systems, library OS, ext4, brtfs, meta block mutations, edge cases
  • 2019 - REDQUEEN: Fuzzing with Input-to-State Correspondence ⚠
    • Tags: feedback-driven, AFL, magic-bytes, nested contraints, input-to-state correspondence, I2S
  • 2019 - PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary ✓
    • Tags: kernel, android, userland, embedded, hardware, Linux, device driver, WiFi
  • 2019 - FirmFuzz: Automated IoT Firmware Introspection and Analysis ✓
    • Tags: emulation, firmadyne, BOF, XSS, CI, NPD, semi-automatic
  • 2019 - Firm-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process Emulation ✓
    • Tags: emulation, qemu, afl, full vs user mode, syscall redirect, "augmented process emulation", firmadyne
  • 2018 - A Survey of Automated Root Cause Analysisof Software Vulnerability ✓
    • Tags: Exploit mitigations, fuzzing basics, symbolic execution basics, fault localization, high level
  • 2018 - PhASAR: An Inter-procedural Static Analysis Framework for C/C++ ✓
    • Tags: LLVM, (inter-procedural) data-flow analysis, call-graph, points-to, class hierachy, CFG, IR
  • 2018 - INSTRIM: Lightweight Instrumentation for Coverage-guided Fuzzing ✓
    • Tags: LLVM, instrumentation optimization, graph algorithms, selective instrumentation, coverage calculation
  • 2018 - What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded Devices ✓
    • Tags: embedded, challenges, heuristics, emulation, crash classification, fault detection
  • 2018 - Evaluating Fuzz Testing ✓
    • Tags: fuzzing evaluation, good practices, bad practices
  • 2017 - Root Cause Analysis of Software Bugs using Machine Learning Techniques ✓
    • Tags: ML, RC prediction for filed bug reports, unsupervised + supervised combination, RC categorisation, F score
  • 2017 - kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels ✓
    • Tags: intel PT, kernel, AFL, file systems, Windows, NTFS, Linux, ext, macOS, APFS, driver, feedback-driven
  • 2016 - Driller: Argumenting Fuzzing Through Selective Symbolic Execution ✓
    • Tags: DARPA, CGC, conco

GitHub Issues· 0 open

View all on GitHub

No open issues yet, or sync has not completed.

Highlights

  • •Table of Contents
  • •Read &amp; Tagged
  • •General fuzzing implementations
  • •IoT fuzzing
  • •Firmware Emulation
  • •Network fuzzing
  • •Kernel fuzzing
  • •Format specific fuzzing
  • •Exploitation
  • •Static Binary Analysis

> Tags

Pythondirected-fuzzingembeddedexploitationfuzzing

No comments yet. Be the first to share.

> Details

PublishedAug 1, 2026
UpdatedSep 17, 2026
Category开发工具
PricingOpen source

> Related tools

V
VS Code
流行的开源代码编辑器
G
Git
分布式版本控制系统
V
Vite
下一代前端构建工具