Ilmu Komputer & AI editorial
State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation
The core problem
Innovation
StateLens was evaluated against state-of-the-art fuzzers on real-world JavaScript engines. The experiments show that StateLens significantly outperforms existing fuzzers in terms of both code coverage and bug discovery. Notably, StateLens uncovered 68 new bugs, many of which are deep and security-critical. The bugs include type confusion, out-of-bounds access, and use-after-free vulnerabilities. The dual-feedback mechanism proved essential: without state coverage, the fuzzer quickly plateaued and missed deep bugs. The LLM-guided instrumentation was also efficient, with the agent pipeline selecting a small fraction of states (less than 1% of all possible states) that accounted for the majority of new coverage. The table below summarizes the bug discovery results:
| Fuzzer | Bugs Found |
|--------|------------|
| StateLens | 68 |
| Baseline 1 | 23 |
| Baseline 2 | 17 |
| Baseline 3 | 12 |
These results demonstrate the effectiveness of state-aware fuzzing and the value of LLM-guided instrumentation.
Why it matters
Who should read this
Opening member contentโฆ