EDBT 2026 Demo / reviewers in the wild / expert
Stefan Nagy
dblp:168/9038
· DBLP profile ↗
14ranked-venue papers
3as first author
10since 2021 · last 2025
0000-0003-0220-1706ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 6 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | TeTRIS: General-purpose Fuzzing for Translation Bugs in Source-to-Source Code TranspilersabstractAmid the rise of heterogeneous computing and concerns over systems and application security, developers are increasingly embracing transpilers: a growing class of tools for converting code from one programming language into another. As languages differ greatly in constructs, syntactic sugar, security mitigations, and more, transpilers face difficulties in faithfully translating software between source and target languages—sometimes causing outright failures, or worse, subtle-yet-incorrect execution behavior. Proactively testing transpilers' correctness is thus critical to the success of code-translation-oriented development tasks, but unfortunately, no effective techniques currently exist. Although fuzz-testing appears a natural fit, current general-purpose fuzzing tools mostly generate invalid, junk code that fails to engage transpilers' core translation logic; while dedicated compiler fuzzers cannot keep pace with the ever-expanding set of languages targeted by existing and emergent transpilers. Thoroughly vetting transpilers' correctness thus demands a fuzzing approach combining the reach of general-purpose fuzzing—with the precision of dedicated compiler fuzzers. This paper presents TeTRIS: a general-purpose fuzzer for testing source-to-source code transpilers. At its core, TeTRIS bridges the flexibility of general-purpose fuzzing, abstracting away language-level differences into a unified interface for fine-grained code mutations, with the precision of compiler fuzzers by rigorously enforcing syntactic and semantic correctness. Relying solely on minimal language specifications, TeTRIS supports fuzzing of any transpiler—irrespective of input or output language—producing high-quality programs that extensively probe its underlying translation logic. In an evaluation against four state-of-the-art fuzzers across seven popular transpilers for C, Go, and Haxe, TeTRIS is the only solution to uphold both high language validity and high transpiler code coverage—whilst supporting the broadest range of transpilers. Moreover, TeTRIS reveals the most code translation bugs—all 12 of which were previously unknown—underscoring its effectiveness in vetting today's diverse transpiler ecosystem. Yeaseen Arafat, Stefan Nagy |
ACSAC | 2 |
| 2025 | A Little Goes a Long Way: Tuning Configuration Selection for Continuous Kernel FuzzingabstractThe Linux kernel is actively-developed and widely-used. It supports billions of devices of all classes, from high-performance computing to the Internet-of-Things, in part because of its sophisticated configuration system, which automatically tailors the source code according to thousands of user-provided configuration options. Fuzzing has been highly successful at finding kernel bugs, being among the top bug reporters. Since the kernel receives 100s of patches per day, fuzzers run continuously, stopping regularly to rebuild the kernel with the latest changes before restarting fuzzing. But kernel fuzzers currently use predefined configuration settings that, as we show, exclude the majority of new patches from the kernel binary, nullifying the benefits of continuous fuzzing. Unfortunately, state-of-the-art configuration testing techniques are generally ill-suited to the needs of continuous fuzzing, excluding necessary options or requiring too many configuration files to be tractable. We distill down the needs of continuous testing into six properties with the most impact, systematically analyze the space of configuration selection strategies, and provide actionable recommendations. Through our analysis, we discover that continuous fuzzers can improve configuration variety without sacrificing performance. We empirically evaluate our discovery by modifying the configuration selection strategy for syzkaller, the most popular Linux kernel fuzzer, which subsequently found more than twice as many new bugs (35 vs. 13) than with the original configuration file and 12x more (24 vs. 2) when considering only unique bugs-with one security vulnerability being assigned a CVE. Sanan Hasanov, Stefan Nagy, Paul Gazzillo |
ICSE | 2 |
| 2025 | No Harness, No Problem: Oracle-guided Harnessing for Auto-generating C API Fuzzing HarnessesabstractLibrary APIs are used by virtually every modern application and system, making them among today's most security-critical software. In recent years, library bug-finding efforts have overwhelmingly adopted the powerful testing strategy of coverage-guided fuzzing. At its core, API fuzzing operates on harnesses: wrapper programs that initialize an API before feeding random inputs to its functions. Successful fuzzing demands correct and thorough harnesses, making manual harnessing challenging without sufficient domain expertise. To overcome this, recent strategies propose “learning” libraries' intended usage to automatically generate their fuzzing harnesses. Yet, despite their high code coverage, resulting harnesses frequently miss key API semantics-bringing with them invalid, unrealistic, or otherwise-impossible data and call sequences-derailing fuzzing with false-positive crashes. Thus, without a precise, semantically-correct harnessing, many critical APIs will remain beyond fuzzing's reach-leaving their hidden vulnerabilities ripe for attackers. This paper introduces Oracle-guided Harnessing: a technique for fully-automatic, semantics-aware API fuzzing har-ness synthesis. At a high level, Oracle-guided Harnessing mimics the trial-and-error process of manual harness creation-yet au-tomates it via fuzzing. Specifically, we leverage information from API headers to mutationally stitch-together candidate harnesses; and evaluate their validity via a set of Correctness Oracles: compilation, execution, and changes in coverage. By keeping-and further mutating-only correct candidates, our approach produces a diverse set of semantically-correct harnesses for complex, real-world libraries in as little as one hour. We integrate Oracle-guided Harnessing as a prototype, OG HARN; and evaluate it alongside today's leading fully-automatic harnessing approach, Hopper, and a plethora of developer-written harnesses from OSS-Fuzz. Across 20 real-world APIs, OGHARN outperforms developer-written harnesses by a median 14% code coverage, while uncovering 31 and 30 more vulnerabilities than both Hopper and developer-written harnesses, respectively-with zero false-positive crashes. Of the 41 new vulnerabilities found by OGHARN, all 41 are confirmed by developers-40 of which are since fixed-with many found in APIs that, until now, lacked harnesses whatsoever. Gabriel Sherman, Stefan Nagy |
ICSE | 2 |
| 2025 | GUIFuzz++: Unleashing Grey-box Fuzzing on Desktop Graphical User Interfacing ApplicationsabstractDesktop applications represent one of today’s largest software ecosystems, accounting for over 96% of workplace computing and supporting essential operations across critical sectors such as healthcare, commerce, industry, and government. Though modern software is increasingly being vetted through fuzzing—an automated testing technique for large-scale bug discovery—a major component of desktop applications remains universally under-vetted: the Graphical User Interface (GUI). Existing desktop-based fuzzers like AFL++ and libFuzzer are limited to non-GUI interfaces (e.g., file- or buffer-based inputs), rendering them wholly incompatible with GUIs. Conversely, mobile app GUI fuzzers like Android’s Monkey and iOS’s XCMonkey rely on platform-specific SDKs and event-handling, rendering them fundamentally unportable to the broader, more complex landscape of desktop software. For these reasons, desktop GUI code remains largely under-tested, burdening users with numerous GUI-induced errors that should, in principle, be just as discoverable as any other well-fuzzed class of software bugs.This paper introduces GUIFuzz++: the first general-purpose fuzzer for desktop GUI software. Unlike desktop fuzzers that randomly mutate file- or buffer-based inputs, GUIFuzz++ exclusively targets GUI interactions—clicks, scrolls, key presses, window navigation, and more—to uncover complex event sequences triggering GUI-induced program errors. Central to our approach is a novel GUI Interaction Interpreter: a middle-layer translating fuzzer-generated random inputs into distinct GUI operations, enabling successful non-GUI fuzzers like AFL++ to be easily ported to testing GUIs. Beyond supporting today’s most popular GUI development frameworks like QT, GTK, and Xorg, we introduce a suite of enhancements capitalizing on ubiquitous Software Accessibility Technologies, significantly boosting GUI fuzzing precision as well as GUI bug-finding effectiveness.We integrate GUIFuzz++ as a prototype atop state-of-the-art GUI-agnostic fuzzer AFL++, and perform a large-scale ablation study of its fundamental components and enhancements. In an evaluation across 12 popular, real-world GUI applications, GUI-FUZZ++ uncovers 23 previously-unknown GUI-induced bugs— with 14 thus far confirmed or fixed by developers. Dillon Otto, Tanner Rowlett, Stefan Nagy |
ASE | 3 |
| 2025 | Bin2Wrong: a Unified Fuzzing Framework for Uncovering Semantic Errors in Binary-to-C Decompilers
Zao Yang, Stefan Nagy |
USENIX ATC | 2 |
| 2023 | Profile-guided System Optimizations for Accelerated Greybox FuzzingabstractGreybox fuzzing is a highly popular option for security testing, incentivizing tremendous efforts to improve its performance. Prior research has brought many algorithmic advancements, leading to substantial performance growth. However, less attention has been paid to the system-level designs of greybox fuzzing tools, despite the high impacts of such designs on fuzzing throughput. Yunhang Zhang, Chengbin Pang, Stefan Nagy, Jun Xu 0024 |
CCS | 3 |
| 2023 | No Linux, No Problem: Fast and Correct Windows Binary Fuzzing via Target-embedded Snapshotting
Leo Stone, Rishi Ranjan, Stefan Nagy, Matthew Hicks |
USENIX Security Symposium | 3 |
| 2022 | One Fuzz Doesn't Fit All: Optimizing Directed Fuzzing via Target-tailored Program State RestrictionabstractFuzzing is the de-facto default technique to discover software flaws, randomly testing programs to discover crashing test cases. Yet, a particular scenario may only care about specific code regions (for, e.g., bug reproduction, patch or regression testing)—spurring the adoption of directed fuzzing. Given a set of pre-determined target locations, directed fuzzers drive exploration toward them through distance minimization strategies that (1) isolate the closest-reaching test cases and (2) mutate them stochastically. However, these strategies are applied onto every explored test case—irrespective of whether they ever reach the targets—stalling progress on the paths where targets are unreachable. Accelerating directed fuzzing requires prioritizing target-reachable paths. Prashast Srivastava, Stefan Nagy, Matthew Hicks, Antonio Bianchi, Mathias Payer |
ACSAC | 2 |
| 2021 | Same Coverage, Less Bloat: Accelerating Binary-only Fuzzing with Coverage-preserving Coverage-guided TracingabstractCoverage-guided fuzzing's aggressive, high-volume testing has helped reveal tens of thousands of software security flaws. While executing billions of test cases mandates fast code coverage tracing, the nature of binary-only targets leads to reduced tracing performance. A recent advancement in binary fuzzing performance is Coverage-guided Tracing (CGT), which brings orders-of-magnitude gains in throughput by restricting the expense of coverage tracing to only when new coverage is guaranteed. Unfortunately, CGT suits only a basic block coverage granularity---yet most fuzzers require finer-grain coverage metrics: edge coverage and hit counts. It is this limitation which prohibits nearly all of today's state-of-the-art fuzzers from attaining the performance benefits of CGT. Stefan Nagy, Anh Nguyen-Tuong, Jason Hiser, Jack W. Davidson, Matthew Hicks |
CCS | 1 |
| 2021 | Breaking Through Binaries: Compiler-quality Instrumentation for Better Binary-only Fuzzing
Stefan Nagy, Anh Nguyen-Tuong, Jason Hiser, Jack W. Davidson, Matthew Hicks |
USENIX Security Symposium | 1 |
| 2019 | A Case Study on a Sustainable Framework for Ethically Aware Predictive ModelingabstractLarge volumes of data allow for modern application of statistical and mathematical models to practical social issues. Many applications of predictive models like criminal activity heat mapping, recidivism estimation, and child safety scoring rely on data that may be incomplete, incorrect, or biased. Many sensitive social and historical issues can unintentionally be incorporated into predictions causing ethical mistreatment. This work proposes a mechanism for continuously mitigating model bias by using algorithms that produce predictions from reasonably small subsets of data, allowing a human-in-the-loop approach to model application. The benefits offered by this framework are twofold: (1) bias can be identified either statistically or by human users on a per-prediction basis; (2) data can be cleaned for bias on a per-prediction basis. A modeling and data management methodology similar to that presented here could strengthen the ethical application of data science and make the process of cleaning and validating data manageable in the long term. Thomas Lux, Stefan Nagy, Mohammed Almanaa, Sirui Yao, Reid Bixler |
ISTAS | 2 |
| 2019 | Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingabstractCoverage-guided fuzzing is one of the most successful approaches for discovering software bugs and security vulnerabilities. Of its three main components: (1) test case generation, (2) code coverage tracing, and (3) crash triage, code coverage tracing is a dominant source of overhead. Coverage-guided fuzzers trace every test case's code coverage through either static or dynamic binary instrumentation, or more recently, using hardware support. Unfortunately, tracing all test cases incurs significant performance penalties--even when the overwhelming majority of test cases and their coverage information are discarded because they do not increase code coverage. To eliminate needless tracing by coverage-guided fuzzers, we introduce the notion of coverage-guided tracing. Coverage-guided tracing leverages two observations: (1) only a fraction of generated test cases increase coverage, and thus require tracing; and (2) coverage-increasing test cases become less frequent over time. Coverage-guided tracing encodes the current frontier of coverage in the target binary so that it self-reports when a test case produces new coverage--without tracing. This acts as a filter for tracing; restricting the expense of tracing to only coverage-increasing test cases. Thus, coverage-guided tracing trades increased time handling coverage-increasing test cases for decreased time handling non-coverage-increasing test cases. To show the potential of coverage-guided tracing, we create an implementation based on the static binary instrumentor Dyninst called UnTracer. We evaluate UnTracer using eight real-world binaries commonly used by the fuzzing community. Experiments show that after only an hour of fuzzing, UnTracer's average overhead is below 1%, and after 24-hours of fuzzing, UnTracer approaches 0% overhead, while tracing every test case with popular white- and black-box-binary tracers AFL-Clang, AFL-QEMU, and AFL-Dyninst incurs overheads of 36%, 612%, and 518%, respectively. We further integrate UnTracer with the state-of-the-art hybrid fuzzer QSYM and show that in 24-hours of fuzzing, QSYM-UnTracer executes 79% and 616% more test cases than QSYM-Clang and QSYM-QEMU, respectively. Stefan Nagy, Matthew Hicks |
IEEE Symposium on Security and Privacy | 1 |
| 2018 | Secure coding practices in Java: challenges and vulnerabilitiesabstractThe Java platform and its third-party libraries provide useful features to facilitate secure coding. However, misusing them can cost developers time and effort, as well as introduce security vulnerabilities in software. We conducted an empirical study on StackOverflow posts, aiming to understand developers' concerns on Java secure coding, their programming obstacles, and insecure coding practices. Na Meng 0001, Stefan Nagy, Danfeng Yao, Wenjie Zhuang, Gustavo A. Arango-Argoty |
ICSE | 2 |
| 2015 | Digital Forensics Education: A Multidisciplinary Curriculum Model
Imani Palmer, Elaine Wood, Stefan Nagy, Gabriela García, Masooda N. Bashir, Roy H. Campbell |
ICDF2C | 3 |