{"id":"https://openalex.org/W2963298680","doi":"https://doi.org/10.1145/3338906.3340456","title":"FUDGE: fuzz driver generation at scale","display_name":"FUDGE: fuzz driver generation at scale","publication_year":2019,"publication_date":"2019-08-09","ids":{"openalex":"https://openalex.org/W2963298680","doi":"https://doi.org/10.1145/3338906.3340456","mag":"2963298680"},"language":"en","primary_location":{"id":"doi:10.1145/3338906.3340456","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3338906.3340456","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5000765311","display_name":"Domagoj Babi\u0107","orcid":null},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Domagoj Babi\u0107","raw_affiliation_strings":["Google, USA"],"affiliations":[{"raw_affiliation_string":"Google, USA","institution_ids":["https://openalex.org/I1291425158"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041340593","display_name":"Stefan Bucur","orcid":null},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Stefan Bucur","raw_affiliation_strings":["Google, USA"],"affiliations":[{"raw_affiliation_string":"Google, USA","institution_ids":["https://openalex.org/I1291425158"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101663791","display_name":"Yaohui Chen","orcid":"https://orcid.org/0009-0005-6258-4472"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yaohui Chen","raw_affiliation_strings":["Northeastern University, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020028377","display_name":"Franjo Ivan\u010di\u0107","orcid":null},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Franjo Ivan\u010di\u0107","raw_affiliation_strings":["Google, USA"],"affiliations":[{"raw_affiliation_string":"Google, USA","institution_ids":["https://openalex.org/I1291425158"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086801190","display_name":"Tim L. King","orcid":null},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tim King","raw_affiliation_strings":["Google, USA"],"affiliations":[{"raw_affiliation_string":"Google, USA","institution_ids":["https://openalex.org/I1291425158"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015928385","display_name":"Markus Kusano","orcid":null},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Markus Kusano","raw_affiliation_strings":["Google, USA"],"affiliations":[{"raw_affiliation_string":"Google, USA","institution_ids":["https://openalex.org/I1291425158"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069023395","display_name":"Caroline Lemieux","orcid":"https://orcid.org/0000-0002-9610-8520"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Caroline Lemieux","raw_affiliation_strings":["University of California at Berkeley, USA"],"affiliations":[{"raw_affiliation_string":"University of California at Berkeley, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060664067","display_name":"L\u00e1szl\u00f3 Szekeres","orcid":"https://orcid.org/0000-0002-9808-6484"},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"L\u00e1szl\u00f3 Szekeres","raw_affiliation_strings":["Google, USA"],"affiliations":[{"raw_affiliation_string":"Google, USA","institution_ids":["https://openalex.org/I1291425158"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100777576","display_name":"Wei Wang","orcid":"https://orcid.org/0000-0002-5974-1589"},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wei Wang","raw_affiliation_strings":["Google, USA"],"affiliations":[{"raw_affiliation_string":"Google, USA","institution_ids":["https://openalex.org/I1291425158"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5000765311"],"corresponding_institution_ids":["https://openalex.org/I1291425158"],"apc_list":null,"apc_paid":null,"fwci":7.2012,"has_fulltext":false,"cited_by_count":108,"citation_normalized_percentile":{"value":0.9782038,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"975","last_page":"985"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.9926588535308838},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6396087408065796},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6168283224105835},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5932936072349548},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.19356846809387207},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.13073158264160156}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.9926588535308838},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6396087408065796},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6168283224105835},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5932936072349548},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.19356846809387207},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.13073158264160156},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3338906.3340456","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3338906.3340456","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6499999761581421,"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":32,"referenced_works":["https://openalex.org/W90447038","https://openalex.org/W157156687","https://openalex.org/W1575308494","https://openalex.org/W1878544538","https://openalex.org/W1884646655","https://openalex.org/W1978924650","https://openalex.org/W1995650922","https://openalex.org/W2001642682","https://openalex.org/W2006291142","https://openalex.org/W2014097364","https://openalex.org/W2014577207","https://openalex.org/W2029643891","https://openalex.org/W2052657693","https://openalex.org/W2096449544","https://openalex.org/W2107709519","https://openalex.org/W2108234281","https://openalex.org/W2122156963","https://openalex.org/W2122475137","https://openalex.org/W2134829794","https://openalex.org/W2153185479","https://openalex.org/W2155233265","https://openalex.org/W2173213060","https://openalex.org/W2296467253","https://openalex.org/W2469513535","https://openalex.org/W2547212960","https://openalex.org/W2795536361","https://openalex.org/W2913256667","https://openalex.org/W2953777927","https://openalex.org/W3213458668","https://openalex.org/W4237492309","https://openalex.org/W4239249613","https://openalex.org/W4255089469"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W2511770387","https://openalex.org/W3120811337","https://openalex.org/W3203597304","https://openalex.org/W2990186179","https://openalex.org/W4248424560","https://openalex.org/W4385301282","https://openalex.org/W3023977444","https://openalex.org/W2766647240","https://openalex.org/W4210660460"],"abstract_inverted_index":{"At":[0],"Google":[1],"we":[2,59],"have":[3,88,123,136,149],"found":[4],"tens":[5],"of":[6,8,54,94,101,127,145,177],"thousands":[7,93],"security":[9,141,180],"and":[10,16,111,116,135,156],"robustness":[11],"bugs":[12],"by":[13,64],"fuzzing":[14,133,161],"C":[15],"C++":[17],"libraries.":[18,102],"To":[19],"fuzz":[20,27,40,71,77,147,165],"a":[21,23,26,43,47,98,107,112],"library,":[22],"fuzzer":[24],"requires":[25],"driver\u2014which":[28],"exercises":[29],"some":[30],"library":[31],"code\u2014to":[32],"which":[33],"it":[34],"can":[35],"pass":[36],"inputs.":[37],"Unfortunately,":[38],"writing":[39],"drivers":[41,96,130,148,166],"remains":[42],"primarily":[44],"manual":[45],"exercise,":[46],"major":[48,62],"hindrance":[49,63],"to":[50,91,138,152],"the":[51,66,159,175],"widespread":[52],"adoption":[53],"fuzzing.":[55],"In":[56],"this":[57,61],"paper,":[58],"address":[60,139],"introducing":[65],"Fudge":[67,74,90],"system":[68],"for":[69,80,97,120],"automated":[70],"driver":[72,78,105],"generation.":[73],"automatically":[75,118],"generates":[76],"candidates":[79],"libraries":[81],"based":[82],"on":[83],"existing":[84],"client":[85],"code.":[86],"We":[87],"used":[89],"generate":[92],"new":[95],"wide":[99],"variety":[100],"Each":[103],"generated":[104,129],"includes":[106],"synthesized":[108],"C/C++":[109],"program":[110],"corresponding":[113],"build":[114],"script,":[115],"is":[117],"analyzed":[119],"quality.":[121],"Developers":[122],"integrated":[124,157],"over":[125,170],"200":[126],"these":[128,146,164],"into":[131,158],"continuous":[132],"services":[134],"committed":[137],"reported":[140],"bugs.":[142],"Further,":[143],"several":[144],"been":[150],"upstreamed":[151],"open":[153],"source":[154],"projects":[155],"OSS-Fuzz":[160],"infrastructure.":[162],"Running":[163],"has":[167],"resulted":[168],"in":[169],"150":[171],"bug":[172],"fixes,":[173],"including":[174],"elimination":[176],"numerous":[178],"exploitable":[179],"vulnerabilities.":[181]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":22},{"year":2023,"cited_by_count":23},{"year":2022,"cited_by_count":16},{"year":2021,"cited_by_count":19},{"year":2020,"cited_by_count":6},{"year":2019,"cited_by_count":2}],"updated_date":"2026-03-12T08:34:05.389933","created_date":"2025-10-10T00:00:00"}
