EDBT 2026 Demo / reviewers in the wild / expert
Zhenkai Weng
dblp:368/3329
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Software testing · 100% |
Topics — the 3 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software testing
compiler testing |
0.9 | 1 | 2025 | IRFuzzer: Specialized Fuzzing for LLVM Backend Code Generation · ICSE 2025 |
Software testing
fuzzing |
0.9 | 1 | 2025 | IRFuzzer: Specialized Fuzzing for LLVM Backend Code Generation · ICSE 2025 |
Software testing › test coverage
coverage-based testing |
0.3 | 1 | 2025 | IRFuzzer: Specialized Fuzzing for LLVM Backend Code Generation · ICSE 2025 |
Methods — techniques the papers use, named apart from their topics
coverage instrumentation · 0.9constrained mutation · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | IRFuzzer: Specialized Fuzzing for LLVM Backend Code GenerationabstractModern compilers, such as LLVM, are complex. Due to their complexity, manual testing is unlikely to suffice, yet formal verification is difficult to scale. End-to-end fuzzing can be used, but it has difficulties in discovering LLVM backend problems for two reasons. First, frontend preprocessing and middle optimization shield the backend from seeing diverse inputs. Second, branch coverage cannot provide effective feedback as LLVM backend contains much reusable code. In this paper, we implement IRFuzzer to investigate the need of specialized fuzzing of the LLVM compiler backend. We focus on two approaches to improve the fuzzer: guaranteed input validity using constrained mutations to improve input diversity and new metrics to improve feedback quality. The mutator in IRFuzzer can generate a wide range of LLVM IR inputs, including structured control flow, vector types, and function definitions. The system instruments coding patterns in the compiler to monitor the execution status of instruction selection. The instrumentation not only provides new coverage feedback on the matcher table but also guides the mutator on architecture-specific intrinsics. We ran IRFuzzer on 29 mature LLVM backend targets. IRFuzzer discovered 78 new, confirmed bugs in LLVM upstream, none of which existing fuzzers could discover. This demonstrates that IRFuzzer is far more effective than existing fuzzers. Upon receiving our bug report, the developers have fixed 57 bugs and back-ported five fixes to LLVM 15, which shows that specialized fuzzing provides actionable insights to LLVM developers. Yuyang Rong, Zhanghan Yu, Zhenkai Weng, Stephen Neuendorffer, Hao Chen 0003 |
ICSE | 3 |