{"id":"https://openalex.org/W2967191362","doi":"https://doi.org/10.1145/3338906.3338975","title":"Cerebro: context-aware adaptive fuzzing for effective vulnerability detection","display_name":"Cerebro: context-aware adaptive fuzzing for effective vulnerability detection","publication_year":2019,"publication_date":"2019-08-09","ids":{"openalex":"https://openalex.org/W2967191362","doi":"https://doi.org/10.1145/3338906.3338975","mag":"2967191362"},"language":"en","primary_location":{"id":"doi:10.1145/3338906.3338975","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3338906.3338975","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://ink.library.smu.edu.sg/cgi/viewcontent.cgi?article=8075&amp;amp;context=sis_research","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5068561556","display_name":"Yuekang Li","orcid":"https://orcid.org/0000-0003-4382-0757"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]},{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN","SG"],"is_corresponding":true,"raw_author_name":"Yuekang Li","raw_affiliation_strings":["University of Science and Technology of China, China / Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology of China, China / Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005","https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083669929","display_name":"Yinxing Xue","orcid":"https://orcid.org/0000-0002-2979-7151"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yinxing Xue","raw_affiliation_strings":["University of Science and Technology of China, China"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology of China, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107243315","display_name":"Hongxu Chen","orcid":"https://orcid.org/0000-0001-7983-2544"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Hongxu Chen","raw_affiliation_strings":["Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085270691","display_name":"Xiuheng Wu","orcid":"https://orcid.org/0000-0003-4464-0782"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Xiuheng Wu","raw_affiliation_strings":["Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044463543","display_name":"Cen Zhang","orcid":"https://orcid.org/0000-0001-9833-6327"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Cen Zhang","raw_affiliation_strings":["Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084396416","display_name":"Xiaofei Xie","orcid":"https://orcid.org/0000-0002-1288-6502"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Xiaofei Xie","raw_affiliation_strings":["Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100419375","display_name":"Haijun Wang","orcid":"https://orcid.org/0009-0001-3509-3919"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Haijun Wang","raw_affiliation_strings":["Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100355692","display_name":"Yang Liu","orcid":"https://orcid.org/0000-0001-7300-9215"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]},{"id":"https://openalex.org/I1328775524","display_name":"Zhejiang Sci-Tech University","ror":"https://ror.org/03893we55","country_code":"CN","type":"education","lineage":["https://openalex.org/I1328775524"]}],"countries":["CN","SG"],"is_corresponding":false,"raw_author_name":"Yang Liu","raw_affiliation_strings":["Nanyang Technological University, Singapore / Zhejiang Sci-Tech University, China"],"affiliations":[{"raw_affiliation_string":"Nanyang Technological University, Singapore / Zhejiang Sci-Tech University, China","institution_ids":["https://openalex.org/I172675005","https://openalex.org/I1328775524"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5068561556"],"corresponding_institution_ids":["https://openalex.org/I126520041","https://openalex.org/I172675005"],"apc_list":null,"apc_paid":null,"fwci":15.1551,"has_fulltext":false,"cited_by_count":92,"citation_normalized_percentile":{"value":0.99159664,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"533","last_page":"544"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.9839634895324707},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.9130231738090515},{"id":"https://openalex.org/keywords/prioritization","display_name":"Prioritization","score":0.5600696206092834},{"id":"https://openalex.org/keywords/code-coverage","display_name":"Code coverage","score":0.5152568817138672},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.5073496699333191},{"id":"https://openalex.org/keywords/software-bug","display_name":"Software bug","score":0.44503745436668396},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.44214528799057007},{"id":"https://openalex.org/keywords/scheduling","display_name":"Scheduling (production processes)","score":0.4410896301269531},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.42859700322151184},{"id":"https://openalex.org/keywords/power-consumption","display_name":"Power consumption","score":0.4262586236000061},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.4178633987903595},{"id":"https://openalex.org/keywords/power","display_name":"Power (physics)","score":0.2781240940093994},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2681117653846741},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.21165987849235535},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.15714946389198303},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.13867226243019104}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.9839634895324707},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.9130231738090515},{"id":"https://openalex.org/C2777615720","wikidata":"https://www.wikidata.org/wiki/Q11888847","display_name":"Prioritization","level":2,"score":0.5600696206092834},{"id":"https://openalex.org/C53942775","wikidata":"https://www.wikidata.org/wiki/Q1211721","display_name":"Code coverage","level":3,"score":0.5152568817138672},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.5073496699333191},{"id":"https://openalex.org/C1009929","wikidata":"https://www.wikidata.org/wiki/Q179550","display_name":"Software bug","level":3,"score":0.44503745436668396},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.44214528799057007},{"id":"https://openalex.org/C206729178","wikidata":"https://www.wikidata.org/wiki/Q2271896","display_name":"Scheduling (production processes)","level":2,"score":0.4410896301269531},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.42859700322151184},{"id":"https://openalex.org/C2984118289","wikidata":"https://www.wikidata.org/wiki/Q29954","display_name":"Power consumption","level":3,"score":0.4262586236000061},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.4178633987903595},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.2781240940093994},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2681117653846741},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.21165987849235535},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.15714946389198303},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.13867226243019104},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C21547014","wikidata":"https://www.wikidata.org/wiki/Q1423657","display_name":"Operations management","level":1,"score":0.0},{"id":"https://openalex.org/C539667460","wikidata":"https://www.wikidata.org/wiki/Q2414942","display_name":"Management science","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3338906.3338975","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3338906.3338975","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","raw_type":"proceedings-article"},{"id":"pmh:oai:ink.library.smu.edu.sg:sis_research-8075","is_oa":true,"landing_page_url":"https://ink.library.smu.edu.sg/cgi/viewcontent.cgi?article=8075&amp;amp;context=sis_research","pdf_url":null,"source":{"id":"https://openalex.org/S4377196871","display_name":"Institutional Knowledge (InK) - Institutional Knowledge at Singapore Management University (Singapore Management University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79891267","host_organization_name":"Singapore Management University","host_organization_lineage":["https://openalex.org/I79891267"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"https://doi.org/10.1145/3338906.3338975","raw_type":"Conference Proceeding Article"}],"best_oa_location":{"id":"pmh:oai:ink.library.smu.edu.sg:sis_research-8075","is_oa":true,"landing_page_url":"https://ink.library.smu.edu.sg/cgi/viewcontent.cgi?article=8075&amp;amp;context=sis_research","pdf_url":null,"source":{"id":"https://openalex.org/S4377196871","display_name":"Institutional Knowledge (InK) - Institutional Knowledge at Singapore Management University (Singapore Management University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79891267","host_organization_name":"Singapore Management University","host_organization_lineage":["https://openalex.org/I79891267"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"https://doi.org/10.1145/3338906.3338975","raw_type":"Conference Proceeding Article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.550000011920929,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":47,"referenced_works":["https://openalex.org/W41412440","https://openalex.org/W614438062","https://openalex.org/W1546956568","https://openalex.org/W1964962870","https://openalex.org/W1965335252","https://openalex.org/W2002934700","https://openalex.org/W2025525377","https://openalex.org/W2035653731","https://openalex.org/W2042033151","https://openalex.org/W2046241805","https://openalex.org/W2049625105","https://openalex.org/W2069205948","https://openalex.org/W2088181608","https://openalex.org/W2105983962","https://openalex.org/W2126105956","https://openalex.org/W2128128820","https://openalex.org/W2153315398","https://openalex.org/W2345196092","https://openalex.org/W2463553622","https://openalex.org/W2484116259","https://openalex.org/W2505544946","https://openalex.org/W2511770387","https://openalex.org/W2517087431","https://openalex.org/W2535617737","https://openalex.org/W2546918856","https://openalex.org/W2574017551","https://openalex.org/W2613534458","https://openalex.org/W2701225458","https://openalex.org/W2741068848","https://openalex.org/W2757104921","https://openalex.org/W2766540688","https://openalex.org/W2766647240","https://openalex.org/W2778319809","https://openalex.org/W2794670092","https://openalex.org/W2888728013","https://openalex.org/W2891235722","https://openalex.org/W2899036588","https://openalex.org/W2963764936","https://openalex.org/W2964097210","https://openalex.org/W2964241064","https://openalex.org/W3104664063","https://openalex.org/W4230648425","https://openalex.org/W4251988601","https://openalex.org/W6619192471","https://openalex.org/W6749470752","https://openalex.org/W6834258854","https://openalex.org/W6929225692"],"related_works":["https://openalex.org/W614438062","https://openalex.org/W4313066017","https://openalex.org/W3173990398","https://openalex.org/W4205454537","https://openalex.org/W4283736421","https://openalex.org/W4385301282","https://openalex.org/W2297949281","https://openalex.org/W1964740600","https://openalex.org/W4381785649","https://openalex.org/W4226494072"],"abstract_inverted_index":{"Existing":[0],"greybox":[1,20],"fuzzers":[2,21,190],"mainly":[3],"utilize":[4],"program":[5],"coverage":[6,187],"as":[7,91,192],"the":[8,12,25,38,56,71,75,100,106,113,131,139,151,155],"goal":[9],"to":[10,23,42,55,69,86,111,123,149],"guide":[11],"fuzzing":[13,154],"process.":[14],"To":[15,98],"maximize":[16],"their":[17],"outputs,":[18],"coverage-based":[19],"need":[22],"evaluate":[24],"quality":[26],"of":[27,108,115,153],"seeds":[28],"properly,":[29],"which":[30,36],"involves":[31],"making":[32],"two":[33],"decisions:":[34],"1)":[35],"is":[37,147],"most":[39],"promising":[40],"seed":[41,58,76],"fuzz":[43],"next":[44],"(seed":[45],"prioritization),":[46],"and":[47,118,184,194],"2)":[48],"how":[49],"many":[50],"efforts":[51],"should":[52],"be":[53],"made":[54],"current":[57],"(power":[59],"scheduling).":[60],"In":[61],"this":[62],"paper,":[63],"we":[64,79,104],"present":[65],"our":[66],"fuzzer,":[67],"Cerebro,":[68],"address":[70,99],"above":[72],"challenges.":[73],"For":[74],"prioritization":[77],"problem,":[78,103],"propose":[80,119],"an":[81,134],"online":[82],"multi-objective":[83],"based":[84,137],"algorithm":[85,122],"balance":[87],"various":[88],"metrics":[89],"such":[90,191],"code":[92,117],"complexity,":[93],"coverage,":[94],"execution":[95,140],"time,":[96],"etc.":[97],"power":[101],"scheduling":[102],"introduce":[105],"concept":[107],"input":[109,135,156,161],"potential":[110],"measure":[112],"complexity":[114],"uncovered":[116],"a":[120,165],"cost-effective":[121],"update":[124],"it":[125,143],"dynamically.":[126],"Unlike":[127],"previous":[128],"approaches":[129],"where":[130],"fuzzer":[132],"evaluates":[133],"solely":[136],"on":[138,170],"traces":[141],"that":[142,178],"has":[144],"covered,":[145],"Cerebro":[146,169,179],"able":[148],"foresee":[150],"benefits":[152],"by":[157],"adaptively":[158],"evaluating":[159],"its":[160],"potential.":[162],"We":[163],"perform":[164],"thorough":[166],"evaluation":[167],"for":[168],"8":[171],"different":[172],"real-world":[173],"programs.":[174],"The":[175],"experiments":[176],"show":[177],"can":[180],"find":[181],"more":[182],"vulnerabilities":[183],"achieve":[185],"better":[186],"than":[188],"state-of-the-art":[189],"AFL":[193],"AFLFast.":[195]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":19},{"year":2023,"cited_by_count":13},{"year":2022,"cited_by_count":18},{"year":2021,"cited_by_count":15},{"year":2020,"cited_by_count":8},{"year":2019,"cited_by_count":5}],"updated_date":"2026-04-11T08:14:18.477133","created_date":"2025-10-10T00:00:00"}
