Peihong Lin

dblp:352/4369 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
8since 2021 · last 2026
0009-0000-6880-9509ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 first-author · 4 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PortRush: Detect Write Port Contention Side-Channel Vulnerabilities via Hardware Fuzzing
Peihong Lin, Gen Zhang, Zhiyuan Jiang, Kai Lu 0001
NDSS1
2026 Not All Paths Are Equal: Multi-path Optimization for Directed Hybrid Fuzzing
abstract
Directed Grey-Box Fuzzing (DGF) can improve bug exposure efficiency by stressing bug-prone areas. Recent studies have modeled DGF as the problem of finding and optimizing paths to reach target sites. However, they still face the “ multi-path ” challenge. When a target site is reachable by multiple paths, it is crucial to comprehensively evaluate and effectively select these paths, as this affects the fuzzer’s choice between reaching target sites via optimal paths and enhancing path diversity toward targets to expose hidden bugs in non-optimal paths. In this article, we propose MultiGo, a directed hybrid fuzzer designed for multi-path optimization. First, we propose a new fitness metric called path difficulty to comprehensively evaluate the promising paths. This metric uses the Poisson distribution to estimate the probability of exploring basic blocks along execution paths based on statistical block frequency, distinguishing between optimal and challenging paths. With path difficulty as a key factor, a customized Contextual Multi-Armed Bandit (CMAB) model is employed to efficiently optimize path scheduling by comprehensively considering the impact of testing conditions on path scheduling. We introduce the concept of the fuzzing context to represent and evaluate testing conditions, which encompass factors such as path characteristics (e.g., path difficulty), the testing agent (e.g., fuzzing or symbolic execution), and the testing goal (e.g., path exploitation or exploration). Then, the CMAB model predicts the expected rewards for scheduling paths under different testing agents and goals, thereby optimizing path scheduling. By leveraging the CMAB model, MultiGo enhances DGF’s capability to explore easier paths and symbolic execution’s capacity to handle more complex ones, enabling efficient target reaching through optimal paths while ensuring sufficient coverage of non-optimal paths. MultiGo is evaluated on 136 target sites of 41 real-world programs from 3 benchmarks. The experimental results show that MultiGo outperforms the state-of-the-art directed fuzzers (AFLGo, SelectFuzz, Beacon, WindRanger, and DAFL) and hybrid fuzzers (SymCC and SymGo) in reaching target sites and exposing known vulnerabilities. Moreover, MultiGo also discovered 14 undisclosed vulnerabilities.
Peihong Lin, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Gen Zhang, Kai Lu 0001
ACM Trans. Softw. Eng. Methodol.1
2025 Learning from the Packet Sequences: Diffusion Model-Based Protocol Greybox Fuzzing
abstract
Network protocol fuzzing is crucial for ensuring the security and stability of protocols. Traditional specification-based methods face severe challenges to generate test cases in scenarios where protocols are complex and specifications are unavailable. Furthermore, the statefulness of protocol implementations requires input packets to satisfy sequential dependencies, further complicates fuzzing. To address these challenges, we developed SPIREFuzz, a novel fuzzer that automatically learns protocol formats and temporal relationships directly from real traffic. SPIREFuzz uses reverse engineering to build a session pattern dataset and employs a Discrete Denoising Diffusion Probabilistic Model (D3PM) to generate packet sequences. Leveraging the model's strengths in stable training and mitigating mode collapse, the method achieves an optimal balance between the accuracy and diversity of generated sequences, which is crucial for generating high-fidelity and state-compliant patterns and simultaneously ensures enhanced state space exploration. Experimental results indicate that on 10 protocols SPIREFuzz's key field identification capability is superior to NetPlier. In fuzzing targeting 8 protocol implementations, compared to AFLNet, NSFuzz, and GANFuzz, its average state coverage, average state transitions, average bitmap coverage, and average unique crashes achieved improvements of up to$\text{78.57 \%}, \text{73.91 \%}, \text{3.94 \%}$, and 216.67 % respectively.
Peihong Lin, Xu Zhou 0004, Wei Xie 0007
IPCCC3
2025 SimFuzz: Conflict-Aware Parallel Fuzzing via Incremental Path Similarity Clustering
abstract
Parallel fuzzing boosts throughput by distributing testcase generation across multiple fuzzing instances. However, this architecture often suffers from task conflict—redundant exploration of similar execution paths—due to the lack of path-level awareness in seed scheduling. These conflicts waste computation and limit overall effectiveness.We present SIMFUZZ, a conflict-aware scheduling framework that mitigates redundancy by integrating path similarity into the fuzzing workflow. SIMFUZZ encodes seeds as branch-level coverage bitmaps and incrementally clusters them based on execution path overlap. It then applies a two-stage scheduling policy that assigns similar seeds to the same instance, while preserving global prioritization for high-potential inputs.We evaluate SIMFUZZ on 19 real-world programs and benchmark targets. Compared to a state-of-the-art baseline, it achieves a 6.7% average increase in branch coverage and reduces task conflict by 3.9%. In several cases, it also discovers substantially more unique crashes. Additionally, SIMFUZZ has uncovered 15 previously unknown vulnerabilities in widely used software projects, all of which have been assigned CVE identifiers.
Xuan Meng, Danjun Liu, Xu Zhou 0004, Peihong Lin, Chenyifan Liu, Lei Zhou 0023, Wei Xie 0007
ISSRE4
2025 When Control Flows Deviate: Directed Grey-box Fuzzing with Probabilistic Reachability Analysis
abstract
Directed grey-box fuzzing (DGF) steers testing toward high-value targets, but developing effective DGF for commercial off-the-shelf (COTS) binaries is challenging due to the lack of accurate structural information (e.g., control-flow graphs and call graphs), which can cause control flows to deviate and misguide DGF’s reachability analysis. In this paper, we introduce BinGo, a tailored binary-level directed grey-box fuzzer, which can accommodate the flawed control-flow graphs (CFGs) of COTS binaries and enable accurate and efficient reachability analysis. First, to quantify the inevitable inaccuracies of uncovered indirect edges and analyze their impact on the reachability of basic blocks, we propose a Bayesian-based method. This method combines prior knowledge from static analysis with dynamic observations from fuzzing to estimate the confidence in correctly recovering indirect edges. Then, we present a new concept called a region, which redefines granularity for efficient reachability analysis by transforming the CFG into a region graph. Using the Bayesian results and region graph, we propose a custom fitness metric for binary-level DGF, termed probabilistic reachability. This metric, based on a dynamically updated region graph and reachability scores, is adaptive, lightweight, and accommodates inaccurate binary-level CFGs. We implemented a prototype tool, BinGo, and evaluated it on the CGC dataset, CVE-Benchmark, and UniBench benchmark. Experimental results show that BinGo surpasses baseline fuzzers (AFL++, AFLGo, PDGF, UAFuzz, and 1dVul) in reaching target locations and exposing known vulnerabilities. Additionally, BinGo discovered three new vulnerabilities in the real-world application cscope-15.9.
Peihong Lin, Xu Zhou 0004, Wei Xie 0007, Kai Lu 0001
ASE1
2024 DeepGo: Predictive Directed Greybox Fuzzing
Peihong Lin, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Gen Zhang, Kai Lu 0001
NDSS1
2024 HyperGo: Probability-based directed hybrid fuzzing
Peihong Lin, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Kai Lu 0001, Gen Zhang
Comput. Secur.1
2024 The progress, challenges, and perspectives of directed greybox fuzzing
abstract
Summary Greybox fuzzing is a scalable and practical approach for software testing. Most greybox fuzzing tools are coverage‐guided as reaching high code coverage is more likely to find bugs. However, since most covered codes may not contain bugs, blindly extending code coverage is less efficient, especially for corner cases. Unlike coverage‐guided greybox fuzzing which increases code coverage in an undirected manner, directed greybox fuzzing (DGF) spends most of its time allocation on reaching specific targets (e.g. the bug‐prone zone) without wasting resources stressing unrelated parts. Thus, DGF is particularly suitable for scenarios such as patch testing, bug reproduction, and special bug detection. For now, DGF has become an active research area. However, DGF has general limitations and challenges that are worth further studying. Based on the investigation of 42 state‐of‐the‐art fuzzers that are closely related to DGF, we conducted the first in‐depth study to summarize the empirical evidence on the research progress of DGF. This paper studies DGF from a broader view, which takes into account not only the location‐directed type that targets specific code parts but also the behavior‐directed type that aims to expose abnormal program behaviors. By analyzing the benefits and limitations of DGF research, we try to identify gaps in current research, meanwhile, reveal new research opportunities and suggest areas for further investigation.
Pengfei Wang 0010, Xu Zhou 0004, Tai Yue, Peihong Lin, Kai Lu 0001
Softw. Test. Verification Reliab.4