{"id":"https://openalex.org/W4400120919","doi":"https://doi.org/10.1145/3634737.3637650","title":"Fuzzing API Error Handling Behaviors using Coverage Guided Fault Injection","display_name":"Fuzzing API Error Handling Behaviors using Coverage Guided Fault Injection","publication_year":2024,"publication_date":"2024-06-28","ids":{"openalex":"https://openalex.org/W4400120919","doi":"https://doi.org/10.1145/3634737.3637650"},"language":"en","primary_location":{"id":"doi:10.1145/3634737.3637650","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3637650","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637650?download=true","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637650?download=true","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101461763","display_name":"Shashank Sharma","orcid":"https://orcid.org/0009-0005-4149-884X"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shashank Sharma","raw_affiliation_strings":["Purdue University, West Lafayette, Indiana, USA"],"raw_orcid":"https://orcid.org/0009-0005-4149-884X","affiliations":[{"raw_affiliation_string":"Purdue University, West Lafayette, Indiana, USA","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5092624335","display_name":"Sai Ritvik Tanksalkar","orcid":"https://orcid.org/0009-0008-6428-0511"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sai Ritvik Tanksalkar","raw_affiliation_strings":["Purdue University, West Lafayette, USA"],"raw_orcid":"https://orcid.org/0009-0008-6428-0511","affiliations":[{"raw_affiliation_string":"Purdue University, West Lafayette, USA","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5094208287","display_name":"Sourag Cherupattamoolayil","orcid":"https://orcid.org/0009-0002-7199-1879"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sourag Cherupattamoolayil","raw_affiliation_strings":["Purdue University, West Lafayette, USA"],"raw_orcid":"https://orcid.org/0009-0002-7199-1879","affiliations":[{"raw_affiliation_string":"Purdue University, West Lafayette, USA","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5071486684","display_name":"Aravind Machiry","orcid":"https://orcid.org/0000-0001-5124-6818"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Aravind Machiry","raw_affiliation_strings":["Purdue University, West Lafayette, United States of America"],"raw_orcid":"https://orcid.org/0000-0001-5124-6818","affiliations":[{"raw_affiliation_string":"Purdue University, West Lafayette, United States of America","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.7246,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.85755634,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1495","last_page":"1509"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.9814146757125854},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8001381754875183},{"id":"https://openalex.org/keywords/fault-injection","display_name":"Fault injection","score":0.5252522826194763},{"id":"https://openalex.org/keywords/fault","display_name":"Fault (geology)","score":0.4332345724105835},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.350544273853302},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.3244333267211914},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.24520820379257202},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.12295746803283691}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.9814146757125854},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8001381754875183},{"id":"https://openalex.org/C2775928411","wikidata":"https://www.wikidata.org/wiki/Q2041312","display_name":"Fault injection","level":3,"score":0.5252522826194763},{"id":"https://openalex.org/C175551986","wikidata":"https://www.wikidata.org/wiki/Q47089","display_name":"Fault (geology)","level":2,"score":0.4332345724105835},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.350544273853302},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3244333267211914},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.24520820379257202},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.12295746803283691},{"id":"https://openalex.org/C165205528","wikidata":"https://www.wikidata.org/wiki/Q83371","display_name":"Seismology","level":1,"score":0.0},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3634737.3637650","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3637650","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637650?download=true","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3634737.3637650","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3637650","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3634737.3637650?download=true","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/13","display_name":"Climate action","score":0.44999998807907104}],"awards":[{"id":"https://openalex.org/G3821343620","display_name":null,"funder_award_id":"CNS-2247686","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G4173798759","display_name":null,"funder_award_id":"N6600120C4031","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"},{"id":"https://openalex.org/G552446388","display_name":null,"funder_award_id":"N660012224037","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"},{"id":"https://openalex.org/G8099155983","display_name":"Collaborative Research: SaTC: CORE: Medium: Securing Continuous Integration Workflows","funder_award_id":"2247686","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"},{"id":"https://openalex.org/F4320332815","display_name":"Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4400120919.pdf"},"referenced_works_count":46,"referenced_works":["https://openalex.org/W1626778198","https://openalex.org/W1987615754","https://openalex.org/W2001266352","https://openalex.org/W2008626182","https://openalex.org/W2028820179","https://openalex.org/W2056689755","https://openalex.org/W2065948900","https://openalex.org/W2069268700","https://openalex.org/W2078592559","https://openalex.org/W2118477385","https://openalex.org/W2122646361","https://openalex.org/W2142103633","https://openalex.org/W2144344516","https://openalex.org/W2252608406","https://openalex.org/W2273497736","https://openalex.org/W2297774820","https://openalex.org/W2479699657","https://openalex.org/W2514084604","https://openalex.org/W2574017551","https://openalex.org/W2613534458","https://openalex.org/W2701225458","https://openalex.org/W2734941459","https://openalex.org/W2757104921","https://openalex.org/W2791610814","https://openalex.org/W2794670092","https://openalex.org/W2899516694","https://openalex.org/W2914040074","https://openalex.org/W2947182139","https://openalex.org/W2959219726","https://openalex.org/W2964097210","https://openalex.org/W3001307185","https://openalex.org/W3002937678","https://openalex.org/W3004040842","https://openalex.org/W3104664063","https://openalex.org/W3153103063","https://openalex.org/W4210660460","https://openalex.org/W4230167402","https://openalex.org/W4232485878","https://openalex.org/W4238083723","https://openalex.org/W4239312229","https://openalex.org/W4248587618","https://openalex.org/W4254645357","https://openalex.org/W4289038676","https://openalex.org/W4312396353","https://openalex.org/W6737694244","https://openalex.org/W6756301311"],"related_works":["https://openalex.org/W2767601850","https://openalex.org/W2617887951","https://openalex.org/W2120051590","https://openalex.org/W2538450276","https://openalex.org/W1894599085","https://openalex.org/W2112914176","https://openalex.org/W2029915748","https://openalex.org/W2800017701","https://openalex.org/W2059685150","https://openalex.org/W184998578"],"abstract_inverted_index":{"Incorrect":[0],"handling":[1,80,115,166],"of":[2,24,52,167],"Software":[3],"Application":[4],"Programming":[5],"Interfaces":[6],"(APIs)":[7],"errors":[8,31],"results":[9],"in":[10,135],"bugs":[11,81,162],"or":[12],"security":[13],"vulnerabilities":[14],"that":[15,154,175],"are":[16,32,47],"hard":[17],"to":[18,28,39,76,109,144],"trigger":[19],"during":[20],"regular":[21],"testing.":[22],"Most":[23],"the":[25,179],"existing":[26],"techniques":[27,54],"detect":[29,77],"such":[30],"based":[33,82],"on":[34,83],"static":[35],"analysis":[36,74],"and":[37,94,107,141,159],"fail":[38],"identify":[40],"certain":[41],"cases":[42],"where":[43],"API":[44,78,168],"return":[45],"values":[46],"incorrectly":[48],"handled.":[49],"Furthermore,":[50],"most":[51],"these":[53],"suffer":[55],"from":[56,164],"a":[57,72,97,111,171],"very":[58],"high":[59],"false":[60,120],"positive":[61],"rate":[62],"(\u226550%),":[63],"raising":[64],"concerns":[65],"regarding":[66],"their":[67],"practical":[68],"use.":[69],"We":[70,118,131],"propose":[71],"dynamic":[73],"approach":[75],"error":[79,114],"coverage-guided":[84],"software":[85],"fault":[86,102],"injection.":[87],"Specifically,":[88],"we":[89],"inject":[90],"faults":[91],"into":[92],"APIs":[93],"observe":[95],"how":[96],"program":[98],"handles":[99],"them.":[100],"Our":[101,151],"injection":[103],"mechanism":[104],"is":[105],"generic":[106],"targeted":[108],"explore":[110],"given":[112],"program's":[113],"behavior":[116],"effectively.":[117],"avoid":[119],"positives":[121],"by":[122,128],"proactively":[123],"filtering":[124],"out":[125],"crashes":[126],"caused":[127],"infeasible":[129],"faults.":[130],"implemented":[132],"our":[133],"technique":[134],"an":[136],"automated":[137],"pipeline":[138],"called":[139],"FuzzERR":[140,155,176],"applied":[142],"it":[143],"20":[145],"different":[146],"programs":[147],"spanning":[148],"444":[149],"APIs.":[150],"evaluation":[152,173],"shows":[153],"found":[156],"31":[157],"new":[158],"previously":[160],"unknown":[161],"resulting":[163],"incorrect":[165],"errors.":[169],"Moreover,":[170],"comparative":[172],"showed":[174],"significantly":[177],"outperformed":[178],"state-of-the-art":[180],"tools.":[181]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
