FitFuzz: Depth-Oriented Coverage-Guided Fuzzing via Fitness-Based Seed Scheduling
Year: 2025, Pages: 315-318
DOI Bookmark: 10.1109/ICCD65941.2025.00051
Authors
Venkat Nitin Patnala, George Mason University, Fairfax, Virginia, USA
Sai Manoj Pudukotai Dinakarrao, George Mason University, Fairfax, Virginia, USA
Abstract
Coverage-guided greybox fuzzing (CGF) has emerged as a powerful technique for identifying software vulnerabilities by leveraging lightweight code coverage feedback. However, existing fuzzers often treat seeds independently, overlooking the structural and evolutionary relationships among inputs. This lack of relational insight can limit the fuzzer's ability to prioritize inputs collectively capable of revealing deeper or more complex program behaviors. We present FitFuzz, a novel fuzzing framework that improves seed scheduling through a fitness-guided strategy. It constructs a mutation-aware seed relation tree and assigns each node a dynamic fitness score based on execution performance, structural depth, and complexity. By integrating fitness-aware seed generation and selection, FitFuzz achieves more effective path exploration while maintaining efficient resource usage. On the UniFuzz benchmark suite, FitFuzz triggered 221 crashes in tiffsplit and 490 in infotocap, while also achieving leading results in seed scheduling efficiency, with top performance in edge discovery for 6 of 11 benchmarks and favored path efficiency in 7 of 11. These results demonstrate that FitFuzz consistently outperforms state-of-the-art fuzzers in crash discovery, particularly by uncovering deeper and less frequently explored execution paths.