FunFuzz: An LLM-Powered Evolutionary Fuzzing Framework
About
Modern fuzzers increasingly use Large Language Models (LLMs) to generate structured inputs, but LLM-driven fuzzing is sensitive to prompt initialization and sampling variance, which can reduce exploration efficiency and lead to redundant inputs. We present FunFuzz, a multi-island evolutionary fuzzing framework that runs several isolated searches in parallel and periodically migrates high-value candidates to maintain diversity. FunFuzz derives initial generation prompts from documentation and initializes islands with topic-specific instructions, then continuously adapts prompts using feedback-guided selection. During fuzzing, candidates are prioritized by incremental compiler coverage, while compiler-internal failure signals are used to identify crash-inducing inputs. We evaluate FunFuzz on compiler fuzzing, where inputs are source programs and success is measured by compiler coverage and unique compiler-internal failures. Across repeated 24-hour campaigns on GCC and Clang, FunFuzz achieves higher compiler coverage than previous LLM-driven baselines and discovers more unique failure-triggering inputs.
Related benchmarks
| Task | Dataset | Result | Rank | |
|---|---|---|---|---|
| Compiler Fuzzing | Clang++ | Program Count2.38e+5 | 9 | |
| Compiler Fuzzing | G++ | Programs Generated225 | 6 | |
| Compiler Fuzzing | GCC 24 hours | Generated Programs4.80e+5 | 6 | |
| Compiler Fuzzing | LLVM/Clang 24 hours | Generated Programs4.80e+5 | 6 | |
| Bug Discovery | GCC C frontend 16.0 | Unique Bugs Found34 | 4 | |
| Bug Discovery | Clang C frontend 23 (trunk snapshots) | Unique Bugs Found52 | 4 | |
| Compiler Fuzzing | GCC | Program Count2.38e+5 | 3 | |
| Bug Discovery | G++ (three independent 24-hour runs) | Unique Findings24 | 2 | |
| Bug Discovery | Clang++ C++ frontend 23 | Unique Bugs Found64 | 2 |