All You Need Is A Fuzzing Brain: An LLM-Powered System for Automated Vulnerability Detection and Patching

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sheng, Ze, Xu, Qingxiao, Huang, Jianwei, Woodcock, Matthew, Huang, Heqing, Donaldson, Alastair F., Gu, Guofei, Huang, Jeff
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916942029258752
author Sheng, Ze
Xu, Qingxiao
Huang, Jianwei
Woodcock, Matthew
Huang, Heqing
Donaldson, Alastair F.
Gu, Guofei
Huang, Jeff
author_facet Sheng, Ze
Xu, Qingxiao
Huang, Jianwei
Woodcock, Matthew
Huang, Heqing
Donaldson, Alastair F.
Gu, Guofei
Huang, Jeff
contents Our team, All You Need Is A Fuzzing Brain, was one of seven finalists in DARPA's Artificial Intelligence Cyber Challenge (AIxCC), placing fourth in the final round. During the competition, we developed a Cyber Reasoning System (CRS) that autonomously discovered 28 security vulnerabilities - including six previously unknown zero-days - in real-world open-source C and Java projects, and successfully patched 14 of them. The complete CRS is open source at https://github.com/o2lab/afc-crs-all-you-need-is-a-fuzzing-brain. This paper provides a detailed technical description of our CRS, with an emphasis on its LLM-powered components and strategies. Building on AIxCC, we further introduce a public leaderboard for benchmarking state-of-the-art LLMs on vulnerability detection and patching tasks, derived from the AIxCC dataset. The leaderboard is available at https://o2lab.github.io/FuzzingBrain-Leaderboard/.
format Preprint
id arxiv_https___arxiv_org_abs_2509_07225
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle All You Need Is A Fuzzing Brain: An LLM-Powered System for Automated Vulnerability Detection and Patching
Sheng, Ze
Xu, Qingxiao
Huang, Jianwei
Woodcock, Matthew
Huang, Heqing
Donaldson, Alastair F.
Gu, Guofei
Huang, Jeff
Cryptography and Security
Our team, All You Need Is A Fuzzing Brain, was one of seven finalists in DARPA's Artificial Intelligence Cyber Challenge (AIxCC), placing fourth in the final round. During the competition, we developed a Cyber Reasoning System (CRS) that autonomously discovered 28 security vulnerabilities - including six previously unknown zero-days - in real-world open-source C and Java projects, and successfully patched 14 of them. The complete CRS is open source at https://github.com/o2lab/afc-crs-all-you-need-is-a-fuzzing-brain. This paper provides a detailed technical description of our CRS, with an emphasis on its LLM-powered components and strategies. Building on AIxCC, we further introduce a public leaderboard for benchmarking state-of-the-art LLMs on vulnerability detection and patching tasks, derived from the AIxCC dataset. The leaderboard is available at https://o2lab.github.io/FuzzingBrain-Leaderboard/.
title All You Need Is A Fuzzing Brain: An LLM-Powered System for Automated Vulnerability Detection and Patching
topic Cryptography and Security
url https://arxiv.org/abs/2509.07225