Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

FunFuzz: An LLM-Powered Evolutionary Fuzzing Framework

About

Modern fuzzers increasingly use Large Language Models (LLMs) to generate structured inputs, but LLM-driven fuzzing is sensitive to prompt initialization and sampling variance, which can reduce exploration efficiency and lead to redundant inputs. We present FunFuzz, a multi-island evolutionary fuzzing framework that runs several isolated searches in parallel and periodically migrates high-value candidates to maintain diversity. FunFuzz derives initial generation prompts from documentation and initializes islands with topic-specific instructions, then continuously adapts prompts using feedback-guided selection. During fuzzing, candidates are prioritized by incremental compiler coverage, while compiler-internal failure signals are used to identify crash-inducing inputs. We evaluate FunFuzz on compiler fuzzing, where inputs are source programs and success is measured by compiler coverage and unique compiler-internal failures. Across repeated 24-hour campaigns on GCC and Clang, FunFuzz achieves higher compiler coverage than previous LLM-driven baselines and discovers more unique failure-triggering inputs.

Mario Rodr\'iguez B\'ejar, B. Romera-Paredes, Jose L. Hern\'andez-Ramos• 2026

Related benchmarks

TaskDatasetResultRank
Compiler FuzzingClang++
Program Count2.38e+5
9
Compiler FuzzingG++
Programs Generated225
6
Compiler FuzzingGCC 24 hours
Generated Programs4.80e+5
6
Compiler FuzzingLLVM/Clang 24 hours
Generated Programs4.80e+5
6
Bug DiscoveryGCC C frontend 16.0
Unique Bugs Found34
4
Bug DiscoveryClang C frontend 23 (trunk snapshots)
Unique Bugs Found52
4
Compiler FuzzingGCC
Program Count2.38e+5
3
Bug DiscoveryG++ (three independent 24-hour runs)
Unique Findings24
2
Bug DiscoveryClang++ C++ frontend 23
Unique Bugs Found64
2
Showing 9 of 9 rows

Other info

Follow for update