CWGAN-GP: Fuzzing Testcase Generation Method based on Conditional Generative Adversarial Network
Zhongyuan Qin, Jiarong Fan, Zeru Li, Xujian Liu, Xin Sun · 2023
Fuzzing is widely used in vulnerability mining because of its simplicity and efficiency. The fuzzing tool generates numerous testcases according to the mutation of the initial seed and inputs them into the program to be tested. At the same time, it monitors exceptions of the running program to find possible software bugs. In order to improve the performance of fuzzing, many researchers are committed to generating various initial testcases. However, at present, fuzzing testcase generation does not make full use of the information of testcases, the generation process is uncontrollable, and the generation effect is general. In view of the problems mentioned above, this paper proposes a testcase generation method based on conditional generative adversarial networks. The CWGAN-GP (Conditional Wasserstein Generic Adversarial Network-Gradient Penalty) learns the format features of testcases, and generates testcases covering corresponding branches according to the input branch information. This paper conducted experiments on 6 common programs, and the experiments showed that compared to the initial training set, testcases generated by (C)WGAN-GP can extend the exploration of the program, and thus find more vulnerabilities. The CWGAN-GP model uses the branch vector in the training set as the condition to generate testcases, which can find more crashes and hangs, and improve the final fuzzing performance.