EDBT 2026 Demo / reviewers in the wild / expert
Nico Schiller
dblp:342/3697
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2026
0009-0004-6401-5989ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: A Systematic Review of Integration and Reproducibility of Fuzzing Research into AFL++
Nico Schiller, Nils Bars, Moritz Schloegel, Thorsten Holz |
EuroS&P | 1 |
| 2025 | VMIGEN: Utilizing Virtual Machine Introspection for Fuzzing Complex Closed-Source TargetsabstractModern fuzzing is a highly successful testing method, but it still struggles with stateful software that expects complex, context-rich inputs. Instead of further tuning the fuzzing process itself, we introduce VMIGEN, a new approach that captures interactions by implicitly recording both complex inputs and the corresponding system states needed for effective testing. By using Virtual Machine Introspection (VMI), a technique for observing the state and behavior of a VM from the outside, we can monitor actual runtime events for a given system. This way, we can extract concrete inputs and snapshot the whole system at relevant interactions to preserve the full system state, thereby enabling effective fuzzing. At the same time, our approach does not require access to source code, allowing us to test closed-source software on Windows. To demonstrate VMIGEN's effectiveness, we use it to test kernel drivers, including those of anti-virus engines, and Remote Procedure Call (RPC) interfaces. Our comprehensive evaluation shows that our VMI-based method enables an existing fuzzer to achieve up to 6.6x more code coverage. In total, VMIGEN allowed us to discover 33 previously unknown bugs, which we disclosed in a coordinated way to the affected vendors. Florian Schweins, Moritz Schloegel, Moritz Bley, Nico Schiller, Thorsten Holz |
ACSAC | 4 |
| 2025 | Novelty Not Found: Exploring Input Shadowing in Fuzzing through Adaptive Fuzzer RestartsabstractGreybox fuzzing enhances software security through unprecedented effectiveness in automated fault detection. Its success lies in the coverage feedback extracted from the system under test, guiding the fuzzer to explore different program parts. The most prominent way to use this feedback is novelty search , where the fuzzer keeps only new inputs exercising a new program edge. However, this approach—by design—ignores input shadowing , in which interesting inputs are discarded if they do not contribute to new coverage. This limits the accepted input space and may overlook bugs that shadowed inputs could trigger with mutations. In this work, we present a comprehensive analysis of input shadowing and demonstrate that multiple fuzzing runs of the same target exhibit a different basic block hit frequency distribution despite overlapping code coverage. We propose fuzzer restarts to effectively redistribute basic block hit frequencies and show that this increases the overall achieved coverage on 15 evaluated targets on average by \(9.5\%\) and up to \(25.0\%\) . Furthermore, restarts help to find more bugs and trigger them more reliably. Overall, our results highlight the importance of considering input shadowing in the fuzzers’ design and the potential benefits of a restart-based strategy to enhance the performance of complex fuzzing methods. Nico Schiller, Lukas Bernhard, Nils Bars, Moritz Schloegel, Thorsten Holz |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2025 | Novelty Not Found: Exploring Input Shadowing in Fuzzing through Adaptive Fuzzer Restarts - RCR ReportabstractThis is the Replicated Computational Results (RCR) Report for our ACM TOSEM paper, “Novelty Not Found: Exploring Input Shadowing in Fuzzing through Adaptive Fuzzer Restarts”. In this paper, we demonstrate how input shadowing can impact the fuzzing process and propose a mitigation strategy: restarting the fuzzing process when progress stagnates. As part of this RCR, we provide a replication package to facilitate the reproduction of our results. Nico Schiller, Lukas Bernhard, Nils Bars, Moritz Schloegel, Thorsten Holz |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2024 | No Peer, no Cry: Network Application Fuzzing via Fault InjectionabstractNetwork-facing applications are commonly exposed to all kinds of attacks, especially when connected to the internet. As a result, web servers like Nginx or client applications such as curl make every effort to secure and harden their code to rule out memory safety violations. One would expect this to include regular fuzz testing, as fuzzing has proven to be one of the most successful approaches to uncovering bugs in software. Yet, surprisingly little research has focused on fuzzing network applications. When studying the underlying reasons, we find that the interactive nature of communication, its statefulness, and the protection of exchanged messages (e.g., via encryption or cryptographic signatures) render typical fuzzers ineffective. Attempts to replay recorded messages or modify them on the fly only work for specific targets and often lead to early termination of communication. Nils Bars, Moritz Schloegel, Nico Schiller, Lukas Bernhard, Thorsten Holz |
CCS | 3 |
| 2024 | DarthShader: Fuzzing WebGPU Shader Translators & CompilersabstractA recent trend towards running more demanding web applications, such as video games or client-side LLMs, in the browser has led to the adoption of the WebGPU standard that provides a cross-platform API exposing the GPU to websites. This opens up a new attack surface: Untrusted web content is passed through to the GPU stack, which traditionally has been optimized for performance instead of security. Worsening the problem, most of WebGPU cannot be run in the tightly sandboxed process that manages other web content, which eases the attacker's path to compromising the client machine. Contrasting its importance, WebGPU shader processing has received surprisingly little attention from the automated testing community. Part of the reason is that shader translators expect highly structured and statically typed input, which renders typical fuzzing mutations ineffective. Complicating testing further, shader translation consists of a complex multi-step compilation pipeline, each stage presenting unique requirements and challenges. Lukas Bernhard, Nico Schiller, Moritz Schloegel, Nils Bars, Thorsten Holz |
CCS | 2 |
| 2024 | SoK: Prudent Evaluation Practices for FuzzingabstractFuzzing has proven to be a highly effective approach to uncover software bugs over the past decade. After AFL popularized the groundbreaking concept of lightweight coverage feedback, the field of fuzzing has seen a vast amount of scientific work proposing new techniques, improving methodological aspects of existing strategies, or porting existing methods to new domains. All such work must demonstrate its merit by showing its applicability to a problem, measuring its performance, and often showing its superiority over existing works in a thorough, empirical evaluation. Yet, fuzzing is highly sensitive to its target, environment, and circumstances, e. g., randomness in the testing process. After all, relying on randomness is one of the core principles of fuzzing, governing many aspects of a fuzzer’s behavior. Combined with the often highly difficult to control environment, the reproducibility of experiments is a crucial concern and requires a prudent evaluation setup. To address these threats to validity, several works, most notably Evaluating Fuzz Testing by Klees et al., have outlined how a carefully designed evaluation setup should be implemented, but it remains unknown to what extent their recommendations have been adopted in practice.In this work, we systematically analyze the evaluation of 150 fuzzing papers published at the top venues between 2018 and 2023. We study how existing guidelines are implemented and observe potential shortcomings and pitfalls. We find a surprising disregard of the existing guidelines regarding statistical tests and systematic errors in fuzzing evaluations. For example, when investigating reported bugs, we find that the search for vulnerabilities in real-world software leads to authors requesting and receiving CVEs of questionable quality. Extending our literature analysis to the practical domain, we attempt to reproduce claims of eight fuzzing papers. These case studies allow us to assess the practical reproducibility of fuzzing research and identify archetypal pitfalls in the evaluation design. Unfortunately, our reproduced results reveal several deficiencies in the studied papers, and we are unable to fully support and reproduce the respective claims. To help the field of fuzzing move toward a scientifically reproducible evaluation strategy, we propose updated guidelines for conducting a fuzzing evaluation that future work should follow. Moritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard, Tobias Scharnowski, Addison Crump, Arash Ale Ebrahim, Nicolai Bissantz, Marius Muench, Thorsten Holz |
SP | 3 |
| 2023 | Drone Security and the Mysterious Case of DJI's DroneID
Nico Schiller, Merlin Chlosta, Moritz Schloegel, Nils Bars, Thorsten Eisenhofer, Tobias Scharnowski, Felix Domke, Lea Schönherr, Thorsten Holz |
NDSS | 1 |
| 2023 | Fuzztruction: Using Fault Injection-based Fuzzing to Leverage Implicit Domain Knowledge
Nils Bars, Moritz Schloegel, Tobias Scharnowski, Nico Schiller, Thorsten Holz |
USENIX Security Symposium | 4 |