SAFuzz: Semantic-Guided Adaptive Fuzzing for LLM-Generated Code

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Yang, Ziyi, Inani, Kalit, Kabra, Keshav, Gupta, Vima, Iyer, Anand Padmanabha
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866917269470183424
author Yang, Ziyi
Inani, Kalit
Kabra, Keshav
Gupta, Vima
Iyer, Anand Padmanabha
author_facet Yang, Ziyi
Inani, Kalit
Kabra, Keshav
Gupta, Vima
Iyer, Anand Padmanabha
contents While AI-coding assistants accelerate software development, current testing frameworks struggle to keep pace with the resulting volume of AI-generated code. Traditional fuzzing techniques often allocate resources uniformly and lack semantic awareness of algorithmic vulnerability patterns, leading to inefficient resource usage and missed vulnerabilities. To address these limitations, we present a hybrid testing framework that leverages LLM-guided adaptive fuzzing to detect algorithmic vulnerabilities efficiently. Our system SAFuzz integrates prompt-based behavioral diversification, harness generation with problem-specific oracles, and an LLM-based predictor to enable adaptive resource allocation and dynamic early stopping. Evaluating SAFuzz on CSES algorithmic problems, we improve vulnerability discrimination precision from 77.9% to 85.7% and achieve a 1.71x reduction in time cost compared to SOTA GreenFuzz while maintaining comparable recall. We further observe that combining our approach with existing unit test generation methods yields complementary gains, increasing the bug detection recall from 67.3% to 79.5%.
format Preprint
id arxiv_https___arxiv_org_abs_2602_11209
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle SAFuzz: Semantic-Guided Adaptive Fuzzing for LLM-Generated Code
Yang, Ziyi
Inani, Kalit
Kabra, Keshav
Gupta, Vima
Iyer, Anand Padmanabha
Software Engineering
Cryptography and Security
While AI-coding assistants accelerate software development, current testing frameworks struggle to keep pace with the resulting volume of AI-generated code. Traditional fuzzing techniques often allocate resources uniformly and lack semantic awareness of algorithmic vulnerability patterns, leading to inefficient resource usage and missed vulnerabilities. To address these limitations, we present a hybrid testing framework that leverages LLM-guided adaptive fuzzing to detect algorithmic vulnerabilities efficiently. Our system SAFuzz integrates prompt-based behavioral diversification, harness generation with problem-specific oracles, and an LLM-based predictor to enable adaptive resource allocation and dynamic early stopping. Evaluating SAFuzz on CSES algorithmic problems, we improve vulnerability discrimination precision from 77.9% to 85.7% and achieve a 1.71x reduction in time cost compared to SOTA GreenFuzz while maintaining comparable recall. We further observe that combining our approach with existing unit test generation methods yields complementary gains, increasing the bug detection recall from 67.3% to 79.5%.
title SAFuzz: Semantic-Guided Adaptive Fuzzing for LLM-Generated Code
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2602.11209