OptFuzz: Rethinking LLM-Assisted Fuzzing from Stateless Generation to Closed-Loop Semantic Optimization
Abstract
Large Language Models (LLMs) can generate syntactically valid test cases, but existing LLM-assisted fuzzers mostly treat them as stateless, single-shot generators. For critical infrastructure systems with deep semantic constraints—such as compilers, runtimes, and bytecode interpreters—this design lacks global search memory, architectural state tracking, and iterative error recovery, leaving exploration perpetually stuck on coverage plateaus. In this paper, we propose OptFuzz, a novel hybrid fuzzing framework that reframes LLM-assisted fuzzing into hierarchical closed-loop semantic optimization. OptFuzz preserves the high throughput of coverage-guided fuzzing (CGF) while selectively invoking the LLM when coverage stagnation is detected. We devise two collaborative optimization engines: the Breadth Optimizer estimates dynamic region values combining static potential metrics and historical solving feedback to steer global state-space exploration toward under-covered logic; the Depth Optimizer models hard bottleneck branch penetration as a contextual multi-armed bandit (LinUCB) sequential decision process over multimodal structural features, iteratively repairing and approximating branch constraints via compilation diagnostics and execution traces. Evaluated across 8 industrial-grade language processors (including Clang, Flang, Hermes, ChakraCore, and Lua), OptFuzz improves edge coverage by up to 115.9% over state-of-the-art fuzzers and discovers 74 real-world vulnerabilities (57 confirmed by upstream maintainers), proving the immense security value of closed-loop semantic optimization. Our code and artifacts are publicly available at https://osf.io/5g2ez/overview?view_only=9a341081ce104a60ad8b3102a7ebb430.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.