[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118028-en":3,"doc-seo-118028-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118028,549758252649,"Ivy","https://ap-avatar.wpscdn.com/avatar/8000253669c5317157?_k=1778319167496531819",8,"Research & Report","Vulnerability detection through machine learning-based fuzzing - A systematic review","Modern software and networks power digital society, yet rapidly emerging vulnerabilities threaten cyber security. Large-scale, proactive identification and mitigation require automated approaches delivered within practical timeframes. Fuzzing offers a preventive testing mechanism, but traditional methods struggle with deep bug identification, expensive analysis, input quality, seed scheduling, and related issues. This systematic review surveys machine learning and optimisation strategies, including TML, DL, RL, and DRL models such as LSTM, GAN, Seq2Seq, and GRU, highlighting benefits and category-specific challenges.","Computers & Security 143 (2024) 103903  \n| Vulnerability detection through machine learning-based fuzzing: A systematic review\u003Cbr>Sadegh Bamohabbat Chafjiri ∗, Phil Legg, Jun Hong, Michail-Antisthenis Tsompanas University of the West of England, Coldharbour Lane, Bristol, BS16 1QY, UK |  |  |\n| --- | --- | --- |\n| A R T I C L E I N F O\u003Cbr>Keywords: ML fuzzing TML fuzzing\u003Cbr>DNN fuzzing RL fuzzing DRL fuzzing | A B S T R A C T\u003Cbr>Modern software and networks underpin our digital society, yet the rapid growth of vulnerabilities that are uncovered within these threaten our cyber security posture. Addressing these issues at scale requires automated proactive approaches that can identify and mitigate these vulnerabilities in a suitable time frame. Fuzzing techniques have emerged as crucial methods to preemptively tackle these risks. However, traditional fuzzing methods encounter various challenges, such as a lack of strategy for deep bug identification, time-intensive bug analysis, quality of inputs, seed scheduling and others. To overcome these challenges, diverse Machine Learning (ML) models and optimisation techniques have been employed, including advanced feature engineering, optimised seed selection, refined predictive/fitness models, and Gradient-based optimisation. Furthermore, the use of ML architectures such as Long Short-Term Memory (LSTM), Generative Adversarial Network (GAN), Sequence-to-Sequence (Seq2Seq), and Generative Randomised Unit (GRU), have demonstrated greater effectiveness within ML-based fuzzing. In this paper, we delve into this paradigm shift, aiming to address fundamental challenges across different ML categories. We survey popular ML categories such as Traditional Machine Learning (TML), Deep Learning (DL), Reinforcement Learning (RL), and Deep Reinforcement Learning (DRL), to investigate their potential for enhancing traditional fuzzing approaches. We explore the respective advantages in each category of ML-based fuzzing, while also analysing the challenges unique to each category. Our work provides a comprehensive survey across the fuzzing domain and how machine learning techniques have been utilised, that we believe will be of use to future researchers in this domain. |  |\n\n1. Introduction  \nFuzzing is the process of automated software testing to assess how a given system, whether it be an application or a network tool, handles various forms of input, including unexpected and random data inputs generated automatically.  \nThe process of software testing is both part of the established development lifecycle and a key component of software security testing to uncover potential vulnerabilities caused by bugs that could be further exploited by an adversary. Software vulnerabilities such as Heartbleed (Carvalho et al., 2014), Shellshock (Anon, 2014), and log4j (Anon, 2021) are good examples of these vulnerabilities that have been widely reported and are known to have had devastating impact on many organisations. Hence, the identification of software vulnerabilities using fuzzing analysis is vital for maintaining a strong cyber security posture. The traditional concept of fuzzing was introduced by Miller back in 1988 and also through his work in the early 1990s (Miller et al., 1990, 1995). Fuzzing methods have since evolved to cover a range of white-box (Molnar et al., 2008), grey-box (Böhme et al., 2017)  \n∗ Corresponding author.  \nand black-box (Abdelnur et al., 2007) methods, giving full, partial and zero access to software details respectively. A variety of fuzzing techniques have since been proposed (Takanen, 2009; Miller and Peterson, 2007; Felderer et al., 2016) including generation-based fuzzing, mutation-based fuzzing and evolution-based fuzzing, including Genetic Algorithms (She et al., 2020) and the popular American Fuzzing Lop (AFL) (Zalewski, 2020). Most recently, and as the motivation for this systematic review, Traditional Machine Learning (TML), Deep Learning (DL), Reinforcement Learning (RL)","cbCaigElbs9s73Fe","https://ap.wps.com/l/cbCaigElbs9s73Fe","pdf",2313947,1,24,"English","en",105,"# Introduction\n## Bug Identification and Prioritisation\n## Time-Consuming Bug Analysis\n## Seed Scheduling\n## Data Flow Interpretation","[{\"question\":\"What role does fuzzing play in vulnerability detection and cyber security?\",\"answer\":\"Fuzzing performs automated software testing by feeding unexpected and random inputs to applications or network tools. It helps uncover vulnerabilities that bugs could allow adversaries to exploit.\"},{\"question\":\"Why do traditional fuzzing methods face challenges?\",\"answer\":\"Traditional fuzzing can struggle with deep bug identification, time-intensive bug analysis, ensuring good input quality, and effective seed scheduling. These limitations make large-scale vulnerability prioritisation difficult.\"},{\"question\":\"Which machine learning categories and model types are surveyed in this review?\",\"answer\":\"The review surveys Traditional Machine Learning (TML), Deep Learning (DL), Reinforcement Learning (RL), and Deep Reinforcement Learning (DRL). It also discusses ML architectures such as LSTM, GAN, Seq2Seq, and GRU for ML-based fuzzing effectiveness.\"}]","Vulnerability detection through machine learning-based fuzzing - A systematic review | PDF",1785680832,60,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"vulnerability-detection-through-machine-learning-based-fuzzing-a-systematic-review","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/vulnerability-detection-through-machine-learning-based-fuzzing-a-systematic-review/118028/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What role does fuzzing play in vulnerability detection and cyber security?","Question",{"text":75,"@type":76},"Fuzzing performs automated software testing by feeding unexpected and random inputs to applications or network tools. It helps uncover vulnerabilities that bugs could allow adversaries to exploit.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why do traditional fuzzing methods face challenges?",{"text":80,"@type":76},"Traditional fuzzing can struggle with deep bug identification, time-intensive bug analysis, ensuring good input quality, and effective seed scheduling. These limitations make large-scale vulnerability prioritisation difficult.",{"name":82,"@type":73,"acceptedAnswer":83},"Which machine learning categories and model types are surveyed in this review?",{"text":84,"@type":76},"The review surveys Traditional Machine Learning (TML), Deep Learning (DL), Reinforcement Learning (RL), and Deep Reinforcement Learning (DRL). It also discusses ML architectures such as LSTM, GAN, Seq2Seq, and GRU for ML-based fuzzing effectiveness.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":29,"slug":108},5,"Comic","comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]