PILOT: Command-line Interface Fuzzing via Path-Guided, Iterative Large Language Model Prompting

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shiraishi, Momoko, Cao, Yinzhi, Shinagawa, Takahiro
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912965069897728
author Shiraishi, Momoko
Cao, Yinzhi
Shinagawa, Takahiro
author_facet Shiraishi, Momoko
Cao, Yinzhi
Shinagawa, Takahiro
contents Command-line interface (CLI) fuzzing tests programs by mutating both command-line options and input file contents, thus enabling discovery of vulnerabilities that only manifest under specific option-input combinations. Prior works of CLI fuzzing face the challenges of generating semantics-rich option strings and input files, which cannot reach deeply embedded target functions. This often leads to a misdetection of such a deep vulnerability using existing CLI fuzzing techniques. In this paper, we design a novel Path-guided, Iterative LLM-Orchestrated Testing framework, called PILOT, to fuzz CLI applications. The key insight is to provide potential call paths to target functions as context to LLM so that it can better generate CLI option strings and input files. Then, PILOT iteratively repeats the process, and provides reached functions as additional context so that target functions are reached. Our evaluation on real-world CLI applications demonstrates that PILOT achieves higher coverage than state-of-the-art fuzzing approaches and discovers 51 zero-day vulnerabilities. We responsibly disclosed all the vulnerabilities to their developers and so far 41 have been confirmed by their developers with 33 being fixed and three assigned CVE identifiers.
format Preprint
id arxiv_https___arxiv_org_abs_2511_20555
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PILOT: Command-line Interface Fuzzing via Path-Guided, Iterative Large Language Model Prompting
Shiraishi, Momoko
Cao, Yinzhi
Shinagawa, Takahiro
Cryptography and Security
Command-line interface (CLI) fuzzing tests programs by mutating both command-line options and input file contents, thus enabling discovery of vulnerabilities that only manifest under specific option-input combinations. Prior works of CLI fuzzing face the challenges of generating semantics-rich option strings and input files, which cannot reach deeply embedded target functions. This often leads to a misdetection of such a deep vulnerability using existing CLI fuzzing techniques. In this paper, we design a novel Path-guided, Iterative LLM-Orchestrated Testing framework, called PILOT, to fuzz CLI applications. The key insight is to provide potential call paths to target functions as context to LLM so that it can better generate CLI option strings and input files. Then, PILOT iteratively repeats the process, and provides reached functions as additional context so that target functions are reached. Our evaluation on real-world CLI applications demonstrates that PILOT achieves higher coverage than state-of-the-art fuzzing approaches and discovers 51 zero-day vulnerabilities. We responsibly disclosed all the vulnerabilities to their developers and so far 41 have been confirmed by their developers with 33 being fixed and three assigned CVE identifiers.
title PILOT: Command-line Interface Fuzzing via Path-Guided, Iterative Large Language Model Prompting
topic Cryptography and Security
url https://arxiv.org/abs/2511.20555