EDBT 2026 Demo / reviewers in the wild / expert
Nathan K. Diamond
dblp:420/8165
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Software testing · 100% | |
| Network and information security
1 paper |
Hardware security and side channels · 50% Systems and software security · 50% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software testing › fuzzing
differential fuzzing |
0.9 | 1 | 2025 | Risk Estimation in Differential Fuzzing via Extreme Value Theory · ASE 2025 |
Software testing
fuzzing |
0.9 | 1 | 2025 | Risk Estimation in Differential Fuzzing via Extreme Value Theory · ASE 2025 |
Systems and software security › information flow control
information leak detection |
0.3 | 1 | 2025 | Risk Estimation in Differential Fuzzing via Extreme Value Theory · ASE 2025 |
Hardware security and side channels
side-channel attack |
0.3 | 1 | 2025 | Risk Estimation in Differential Fuzzing via Extreme Value Theory · ASE 2025 |
Methods — techniques the papers use, named apart from their topics
statistical extrapolation · 1.7markov's inequality · 1.7extreme value theory · 1.7chebyshev's inequality · 1.7bayes factor · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Risk Estimation in Differential Fuzzing via Extreme Value TheoryabstractDifferential testing is a highly effective technique for automatically detecting software bugs and vulnerabilities when the specifications involve an analysis over multiple executions simultaneously. Differential fuzzing, in particular, operates as a guided randomized search, aiming to find (similar) inputs that lead to a maximum difference in software outputs or their behaviors. However, fuzzing, as a dynamic analysis, lacks any guarantees on the absence of bugs: from a differential fuzzing campaign that has observed no bugs (or a minimal difference), what is the risk of observing a bug (or a larger difference) if we run the fuzzer for one or more steps?This paper investigates the application of Extreme Value Theory (EVT) to address the risk of missing or underestimating bugs in differential fuzzing. The key observation is that differential fuzzing as a random process resembles the maximum distribution of observed differences. Hence, EVT, a branch of statistics dealing with extreme values, is an ideal framework to analyze the tail of the differential fuzzing campaign to contain the risk. We perform experiments on a set of real-world Java libraries and use differential fuzzing to find information leaks via side channels in these libraries. We first explore the feasibility of EVT for this task and the optimal hyperparameters for EVT distributions. We then compare EVT-based extrapolation against baseline statistical methods like Markov’s as well as Chebyshev’s inequalities, and the Bayes factor. EVT-based extrapolations outperform the baseline techniques in 14.3% of cases and tie with the baseline in 64.2% of cases. Finally, we evaluate the accuracy and performance gains of EVT-enabled differential fuzzing in real-world Java libraries, where we reported an average saving of tens of millions of bytecode executions by an early stop. Rafael Baez, Alejandro Olivas, Nathan K. Diamond, Marcelo F. Frias, Yannic Noller, Saeid Tizpaz-Niari |
ASE | 3 |