VLDB 2026 Research / reviewers in the wild / expert
Jonathan Metzman
dblp:299/8771
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2022
0000-0002-7042-0444ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | On the Reliability of Coverage-Based Fuzzer BenchmarkingabstractGiven a program where none of our fuzzers finds any bugs, how do we know which fuzzer is better? In practice, we often look to code coverage as a proxy measure of fuzzer effectiveness and consider the fuzzer which achieves more coverage as the better one. Marcel Böhme, Laszlo Szekeres, Jonathan Metzman |
ICSE | 3 |
| 2022 | Comparing Fuzzers on a Level Playing Field with FuzzBenchabstractFuzzing is a testing approach commonly used in industry to discover bugs in a given software under test (SUT). It consists of running a SUT iteratively with randomly generated (or mutated) inputs, in order to find as many as possible inputs that make the SUT crash. Many fuzzers have been proposed to date, however no consensus has been reached on how to properly evaluate and compare fuzzers. In this work we evaluate and compare nine prominent fuzzers by carrying out a thorough empirical study based on an open-source framework developed by Google, namely FuzzBench, and a manually curated benchmark suite of 12 real-world software systems. The results show that honggfuzz and AFL++ are, in that order, the best choices in terms of general purpose fuzzing effectiveness. The results also show that none of the fuzzers outperforms the others in terms of efficiency across all considered metrics, that no particular bug affinity is found for any fuzzer, and that the correlation found between coverage and number of bugs depends more on the SUT rather than on the fuzzer used. Dario Asprone, Jonathan Metzman, Abhishek Arya, Giovani Guizzo, Federica Sarro |
ICST | 2 |
| 2021 | FuzzBench: an open fuzzer benchmarking platform and serviceabstractFuzzing is a key tool used to reduce bugs in production software. At Google, fuzzing has uncovered tens of thousands of bugs. Fuzzing is also a popular subject of academic research. In 2020 alone, over 120 papers were published on the topic of improving, developing, and evaluating fuzzers and fuzzing techniques. Yet, proper evaluation of fuzzing techniques remains elusive. The community has struggled to converge on methodology and standard tools for fuzzer evaluation. Jonathan Metzman, Laszlo Szekeres, Laurent Simon 0001, Read Sprabery, Abhishek Arya |
ESEC/SIGSOFT FSE | 1 |