Helping Generative Fuzzers Avoid Looking Only Where the Light is Good
https://blog.regehr.org/archives/1700 [blog.regehr.org]
2019-11-05 04:20
Using a generative fuzzer — which creates test cases from scratch, rather than mutating a collection of seed inputs — feels to me a lot like being the drunk guy in the joke: we’re looking for bugs that can be triggered by inputs that the generator is likely to generate, because we don’t have an obviously better option, besides doing some hard work in improving the generator. This problem has bothered me for a long time.