TriFuzz: Probabilistic Distance-Guided Hybrid Directed Fuzzing with Selective Symbolic Instrumentation
Abstract
1. Introduction
- TriFuzz framework. We propose a hybrid directed fuzzing framework [30,32] along three complementary dimensions, including fine-grained probabilistic distance calculation, selective symbolic instrumentation, and hybrid coordination. These components are designed to work together to improve the efficiency of directed exploration.
- Implementation. We implement TriFuzz as a practical directed hybrid fuzzer by extending AFLGo [1] and SymCC [18]. The system integrates the proposed techniques into a unified framework for efficient directed fuzzing. To facilitate reproducibility and further research, the full implementation of TriFuzz has been made publicly available at https://github.com/HandsomeBoyBiu/trifuzz (accessed on 15 April 2026).
2. Background
2.1. Directed Greybox Fuzzing
2.2. Symbolic Execution
2.3. Hybrid Fuzzing
3. Methodology
3.1. Framework Overview
3.1.1. Fine-Grained Probability-Based Distance Calculation
3.1.2. Selective Symbolic Instrumentation
3.1.3. Hybrid Fuzzing Coordination
3.2. Fine-Grained Probability-Based Distance Calculation
- Unreachable-block elimination: all basic blocks that cannot reach the target are pruned from the control-flow graph (CFG), avoiding misleading distance values.
- Loop-aware distance modeling: cyclic structures are explicitly modeled, ensuring that distance calculation within loops is semantically consistent and fine-grained.
3.2.1. Conflict Basic Block Probability Calculation
3.2.2. Recursive Distance Propagation
| Algorithm 1 Probability-based distance calculation |
| Require: with target function set , constant probability map Ensure: : probability map over all basic blocks |
| 1: function Func_level_probability() |
| 2: initialize for all basic blocks b in |
| 3: |
| 4: for each function F in do |
| 5: |
| 6: end for |
| 7: while do |
| 8: |
| 9: BB_level_probability() |
| 10: for each caller function G of F do |
| 11: if G has not been processed then |
| 12: |
| 13: end if |
| 14: end for |
| 15: end while |
| 16: return |
| 17: end function |
| 18: |
| 19: function BB_level_probability() |
| 20: Resolve_conflict() |
| 21: ComputeBBProb() |
| 22: end function |
| 23: |
| 24: function ComputeBBProb() |
| 25: if is Predef or Conflict then |
| 26: return |
| 27: end if |
| 28: |
| 29: for each successor of do |
| 30: ComputeBBProb() |
| 31: |
| 32: end for |
| 33: |
| 34: return |
| 35: end function |
| Algorithm 2 Resolve_conflict: conflict basic block probability calculation |
| Require: Function F, constant probability map |
| Ensure: : probability map over basic blocks in F |
| 1: function Resolve_conflict() |
| 2: |
| 3: |
| 4: |
| ▹Stage 1: construct the conflict forest |
| 5: for each basic block x in F do |
| 6: if such that then |
| 7: |
| 8: end if |
| 9: end for |
| 10: for each conflict basic block do |
| 11: BuildConflictTree() |
| 12: |
| 13: end for |
| ▹Stage 2: construct and solve the linear system |
| 14: enumerate as |
| 15: initialize with zeros |
| 16: initialize with zeros |
| 17: for each conflict tree do |
| 18: |
| 19: initialize for each conflict basic block x in |
| 20: for each layer in do |
| 21: least common multiple of successor counts of blocks in |
| 22: end for |
| 23: |
| 24: for each leaf node of do |
| 25: |
| 26: |
| 27: |
| 28: if then |
| 29: |
| 30: else if then |
| 31: |
| 32: end if |
| 33: end for |
| 34: |
| 35: |
| 36: for each layer in do |
| 37: |
| 38: end for |
| 39: |
| 40: for each conflict basic block x with do |
| 41: |
| 42: |
| 43: |
| 44: end for |
| 45: |
| 46: end for |
| 47: |
| 48: LinearSolve() |
| 49: for to m do |
| 50: |
| 51: end for |
| 52: for each basic block do |
| 53: |
| 54: end for |
| 55: return |
| 56: end function |
3.2.3. Input Distance
3.2.4. Distance-Calculation Example
- Block A inherits the probability of its successor B;
- Block B branches to E and C, giving ;
- Block C branches to F and D; since contributes probability 0, this reduces to ;
- Block D returns to B, completing the cycle.
3.3. Selective Symbolic Instrumentation
3.4. Hybrid Fuzzing Coordination
4. Implementation
- Distance Calculation
- Hybrid Fuzzing Coordination
- Indirect Call
5. Evaluation
- RQ1: How efficiently can TriFuzz reach the designated target locations?
- RQ2: How effectively can TriFuzz expose target vulnerabilities?
- RQ3: What advantages does selective symbolic instrumentation provide over full instrumentation?
- RQ4: Does our probability-based fine-grained distance metric outperform traditional distance metrics in guiding fuzzing toward the target?
5.1. Evaluation Setup
5.1.1. Evaluation Criteria
5.1.2. Evaluation Benchmarks
5.1.3. Experimental Settings
5.2. Reaching Target Sites
5.3. Exposing Target Vulnerabilities
5.4. Impact of Selective Instrumentation
5.5. Effectiveness of the Fine-Grained Probabilistic Distance Metric
5.6. Distance-Calculation Overhead Optimization
5.7. Vulnerability Triggering Diversity Analysis
6. Discussion
6.1. Limitations
6.2. Future Work
7. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Böhme, M.; Pham, V.-T.; Nguyen, M.-D.; Roychoudhury, A. Directed Greybox Fuzzing. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA, 30 October–3 November 2017; pp. 2329–2344. [Google Scholar] [CrossRef]
- Canakci, S.; Matyunin, N.; Graffi, K.; Joshi, A.; Egele, M. Targetfuzz: Using darts to guide directed greybox fuzzers. In Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, Nagasaki, Japan, 30 May–3 June 2022; pp. 561–573. [Google Scholar] [CrossRef]
- Tan, X.; Zhang, Y.; Lu, J.; Xiong, X.; Liu, Z.; Yang, M. Syzdirect: Directed greybox fuzzing for linux kernel. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Copenhagen, Denmark, 26–30 November 2023; pp. 1630–1644. [Google Scholar] [CrossRef]
- Wang, P.; Zhou, X.; Yue, T.; Lin, P.; Liu, Y.; Lu, K. The progress, challenges, and perspectives of directed greybox fuzzing. Softw. Test. Verif. Reliab. 2024, 34, e1869. [Google Scholar] [CrossRef]
- Geretto, E.; Jemmett, A.; Giuffrida, C.; Bos, H. LibAFLGo: Evaluating and Advancing Directed Greybox Fuzzing. In Proceedings of the 2025 IEEE 10th European Symposium on Security and Privacy (EuroS&P), Venice, Italy, 30 June–4 July 2025; pp. 355–373. [Google Scholar] [CrossRef]
- Kim, T.; Choi, J.; Heo, K.; Cha, S. DAFL: Directed Grey-box Fuzzing guided by Data Dependency. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA, 9–11 August 2023; pp. 4931–4948. [Google Scholar]
- Cao, S.; He, B.; Sun, X.; Ouyang, Y.; Zhang, C.; Wu, X.; Su, T.; Bo, L.; Li, B.; Ma, C.; et al. Oddfuzz: Discovering java deserialization vulnerabilities via structure-aware directed greybox fuzzing. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 22–26 May 2023; pp. 2726–2743. [Google Scholar] [CrossRef]
- Bao, A.; Zhao, W.; Wang, Y.; Cheng, Y.; McCamant, S.; Yew, P. From Alarms to Real Bugs: Multi-target Multi-step Directed Greybox Fuzzing for Static Analysis Result Verification. In Proceedings of the 34th USENIX Security Symposium (USENIX Security 25), Seattle, WA, USA, 13–15 August 2025; pp. 6977–6997. [Google Scholar]
- Lin, Z.; Zhang, Y.; Dai, J.; Huang, X.; Xiang, B.; Yang, G.; Yuan, L.; Zhang, L.; Chen, T.; Yang, M. Effective directed fuzzing with hierarchical scheduling for web vulnerability detection. In Proceedings of the 34th USENIX Security Symposium (USENIX Security 25), Seattle, WA, USA, 13–15 August 2025; pp. 8349–8366. [Google Scholar]
- Deng, P.; Zhang, L.; Meng, Y.; Yang, Z.; Zhang, Y. ChainFuzz: Exploiting Upstream Vulnerabilities in Open-Source Supply Chains. In Proceedings of the 34th USENIX Security Symposium (USENIX Security 25), Seattle, WA, USA, 13–15 August 2025; pp. 6199–6218. [Google Scholar]
- Liang, H.; Yu, X.; Cheng, X.; Liu, J.; Li, J. Multiple targets directed greybox fuzzing. IEEE Trans. Dependable Secur. Comput. 2024, 21, 325–339. [Google Scholar] [CrossRef]
- Xiang, Y.; Zhang, X.; Liu, P.; Ji, S.; Liang, H.; Xu, J.; Wang, W. Critical code guided directed greybox fuzzing for commits. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24), Philadelphia, PA, USA, 14–16 August 2024; pp. 2459–2474. [Google Scholar]
- Österlund, S.; Razavi, K.; Bos, H.; Giuffrida, C. ParmeSan: Sanitizer-guided greybox fuzzing. In Proceedings of the 29th USENIX Security Symposium (USENIX Security 20), Boston, MA, USA, 12–14 August 2020; pp. 2289–2306. [Google Scholar]
- Fang, H.; Zhang, K.; Yu, D.; Zhang, Y. DDGF: Dynamic Directed Greybox Fuzzing with Path Profiling. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, Vienna, Austria, 16–20 September 2024; pp. 832–843. [Google Scholar] [CrossRef]
- Li, R.; Liang, H.; Liu, L.; Ma, X.; Qu, R.; Yan, J.; Zhang, J. GTFuzz: Guard token directed grey-box fuzzing. In Proceedings of the 2020 IEEE 25th Pacific Rim International Symposium on Dependable Computing (PRDC), Perth, Australia, 1–4 December 2020; pp. 160–170. [Google Scholar] [CrossRef]
- Zalewski, M. American Fuzzy Lop (AFL) Fuzzer. 2015, p. 33. Available online: http://lcamtuf.coredump.cx/afl/ (accessed on 5 December 2024).
- Fioraldi, A.; Maier, D.; Eißfeldt, H.; Heuse, M. AFL++: Combining incremental steps of fuzzing research. In Proceedings of the 14th USENIX Workshop on Offensive Technologies (WOOT 20), Virtual Event, 11 August 2020. [Google Scholar]
- Poeplau, S.; Francillon, A. Symbolic execution with SymCC: Don’t interpret, compile! In Proceedings of the 29th USENIX Security Symposium (USENIX Security 20), Boston, MA, USA, 12–14 August 2020; pp. 181–198. [Google Scholar]
- Cadar, C.; Dunbar, D.; Engler, D. KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs. In Proceedings of the 8th USENIX Conference on Operating Systems Design and Implementation (OSDI’08), San Diego, CA, USA, 8–10 December 2008; pp. 209–224. [Google Scholar]
- Chipounov, V.; Georgescu, V.; Zamfir, C.; Candea, G. Selective symbolic execution. In Proceedings of the 5th Workshop on Hot Topics in System Dependability, Lisbon, Portugal, 29 June 2009. [Google Scholar]
- Yun, I.; Lee, S.; Xu, M.; Jang, Y.; Kim, T. QSYM: A practical concolic execution engine tailored for hybrid fuzzing. In Proceedings of the 27th USENIX Security Symposium (USENIX Security 18), Baltimore, MD, USA, 15–17 August 2018; pp. 745–761. [Google Scholar]
- Shoshitaishvili, Y.; Wang, R.; Salls, C.; Stephens, N.; Polino, M.; Dutcher, A.; Grosen, J.; Feng, S.; Hauser, C.; Kruegel, C.; et al. SoK: (State of) The Art of War: Offensive Techniques in Binary Analysis. In Proceedings of the 2016 IEEE Symposium on Security and Privacy, San Jose, CA, USA, 22–26 May 2016; pp. 138–157. [Google Scholar] [CrossRef]
- Baldoni, R.; Coppa, E.; D’elia, D.; Demetrescu, C.; Finocchi, I. A survey of symbolic execution techniques. ACM Comput. Surv. (CSUR) 2018, 51, 1–39. [Google Scholar] [CrossRef]
- Sen, K. Concolic testing. In Proceedings of the 22nd IEEE/ACM International Conference on Automated Software Engineering, Atlanta, GA, USA, 5–9 November 2007; pp. 571–572. [Google Scholar] [CrossRef]
- Chen, J.; Han, W.; Yin, M.; Zeng, H.; Song, C.; Lee, B.; Yin, H.; Shin, I. SYMSAN: Time and space efficient concolic execution via dynamic data-flow analysis. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22), Boston, MA, USA, 10–12 August 2022; pp. 2531–2548. [Google Scholar]
- Stephens, N.; Grosen, J.; Salls, C.; Dutcher, A.; Wang, R.; Corbetta, J.; Shoshitaishvili, Y.; Kruegel, C.; Vigna, G. Driller: Augmenting fuzzing through selective symbolic execution. In Proceedings of the NDSS, San Diego, CA, USA, 21–24 February 2016; Volume 16, pp. 1–16. [Google Scholar] [CrossRef]
- Zhao, L.; Duan, Y.; Xuan, J. Send hardest problems my way: Probabilistic path prioritization for hybrid fuzzing. In Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 24–27 February 2019. [Google Scholar] [CrossRef]
- Kim, K.; Jeong, D.; Kim, C.; Jang, Y.; Shin, I.; Lee, B. HFL: Hybrid Fuzzing on the Linux Kernel. In Proceedings of the NDSS, San Diego, CA, USA, 23–26 February 2020. [Google Scholar]
- Li, J.; Shen, J.; Su, Y.; Lyu, M. ColorGo: Directed Concolic Execution. arXiv 2025, arXiv:2505.21130. [Google Scholar] [CrossRef]
- Lin, P.; Wang, P.; Zhou, X.; Xie, W.; Lu, K.; Zhang, G. HyperGo: Probability-based directed hybrid fuzzing. Comput. Secur. 2024, 142, 103851. [Google Scholar] [CrossRef]
- Yang, Y.; Yao, S.; Chen, J.; Lee, W. Hybrid Language Processor Fuzzing via LLM-Based Constraint Solving. In Proceedings of the 34th USENIX Security Symposium (USENIX Security 25), Seattle, WA, USA, 13–15 August 2025; pp. 6299–6318. [Google Scholar]
- Liang, H.; Jiang, L.; Ai, L.; Wei, J. Sequence directed hybrid fuzzing. In Proceedings of the 2020 IEEE 27th International Conference on Software Analysis, Evolution and Reengineering (SANER), London, ON, Canada, 18–21 February 2020; pp. 127–137. [Google Scholar] [CrossRef]
- Luo, C.; Meng, W.; Li, P. Selectfuzz: Efficient directed fuzzing with selective path exploration. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 22–26 May 2023; pp. 2693–2707. [Google Scholar] [CrossRef]
- Li, Y.; Ji, S.; Chen, Y.; Liang, S.; Lee, W.; Chen, Y.; Lyu, C.; Wu, C.; Beyah, R.; Cheng, P.; et al. UNIFUZZ: A holistic and pragmatic Metrics-Driven platform for evaluating fuzzers. In Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Vancouver, BC, Canada, 11–13 August 2021; pp. 2777–2794. [Google Scholar]
- Du, Z.; Li, Y.; Liu, Y.; Mao, B. Windranger: A directed greybox fuzzer driven by deviation basic blocks. In Proceedings of the 44th International Conference on Software Engineering, Pittsburgh, PA, USA, 25–27 May 2022; pp. 2440–2451. [Google Scholar] [CrossRef]
- Huang, H.; Guo, Y.; Shi, Q.; Yao, P.; Wu, R.; Zhang, C. Beacon: Directed grey-box fuzzing with provable path pruning. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 22–26 May 2022; pp. 36–50. [Google Scholar] [CrossRef]
- Shah, A.; She, D.; Sadhu, S.; Singal, K.; Coffman, P.; Jana, S. Mc2: Rigorous and efficient directed greybox fuzzing. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, Los Angeles, CA, USA, 7–11 November 2022; pp. 2595–2609. [Google Scholar] [CrossRef]
- Zheng, H.; Zhang, J.; Huang, Y.; Ren, Z.; Wang, H.; Cao, C.; Zhang, Y.; Toffalini, F.; Payer, M. FISHFUZZ: Catch deeper bugs by throwing larger nets. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA, 9–11 August 2023; pp. 1343–1360. [Google Scholar]
- Lin, P.; Wang, P.; Zhou, X.; Xie, W.; Zhang, G.; Lu, K. Deepgo: Predictive directed greybox fuzzing. arXiv 2025, arXiv:2507.21952. [Google Scholar] [CrossRef]
- Chen, Y.; Zhang, C.; Wang, L.; Zhu, W.; Luo, C.; Gui, N.; Ma, Z.; Zhang, X.; Su, B. IDFuzz: Intelligent Directed Grey-box Fuzzing. In Proceedings of the 34th USENIX Security Symposium (USENIX Security 25), Seattle, WA, USA, 13–15 August 2025; pp. 6219–6238. [Google Scholar]
- Lattner, C.; Adve, V. LLVM: A compilation framework for lifelong program analysis & transformation. In Proceedings of the International Symposium on Code Generation and Optimization, 2004 (CGO 2004), San Jose, CA, USA, 20–24 March 2004; pp. 75–86. [Google Scholar] [CrossRef]
- Chen, J.; Wang, J.; Song, C.; Yin, H. Jigsaw: Efficient and scalable path constraints fuzzing. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 22–26 May 2022; pp. 18–35. [Google Scholar] [CrossRef]
- Peng, J.; Li, F.; Liu, B.; Xu, L.; Liu, B.; Chen, K.; Huo, W. 1dvul: Discovering 1-day vulnerabilities through binary patches. In Proceedings of the 2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), Portland, OR, USA, 24–27 June 2019; pp. 605–616. [Google Scholar] [CrossRef]
- Sui, Y.; Xue, J. SVF: Interprocedural static value-flow analysis in LLVM. In Proceedings of the 25th International Conference on Compiler Construction, Barcelona, Spain, 12–18 March 2016; pp. 265–266. [Google Scholar] [CrossRef]
- Vargha, A.; Delaney, H. A critique and improvement of the CL common language effect size statistics of McGraw and Wong. J. Educ. Behav. Stat. 2000, 25, 101–132. [Google Scholar] [PubMed]
- Stallman, R.; Pesch, R.; Shebs, S. Debugging with GDB; Free Software Foundation: Boston, MA, USA, 1988; 675p. [Google Scholar]
- Avgerinos, T.; Cha, S.; Rebert, A.; Schwartz, E.; Woo, M.; Brumley, D. Automatic exploit generation. Commun. ACM 2014, 57, 74–84. [Google Scholar] [CrossRef]
- Wu, Y.; Li, Y.; Zhu, H.; Zhang, Y. SAEG: Stateful Automatic Exploit Generation. In Proceedings of the European Symposium on Research in Computer Security, Bydgoszcz, Poland, 16–20 September 2024; pp. 127–145. [Google Scholar] [CrossRef]
- Bui, Q.; Iannone, E.; Camporese, M.; Hinrichs, T.; Tony, C.; Tóth, L.; Palomba, F.; Hegedűs, P.; Massacci, F.; Scandariato, R. A Systematic Literature Review on Automated Exploit and Security Test Generation. arXiv 2025, arXiv:2502.04953. [Google Scholar] [CrossRef]
- Dixit, S.; Geethna, T.; Jayaraman, S.; Pavithran, V. Angerza: Automated exploit generation. In Proceedings of the 2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT), Kharagpur, India, 6–8 July 2021; pp. 1–6. [Google Scholar] [CrossRef]
- Jin, L.; Cao, Y.; Chen, Y.; Zhang, D.; Campanoni, S. Exgen: Cross-platform, automated exploit generation for smart contract vulnerabilities. IEEE Trans. Dependable Secur. Comput. 2023, 20, 650–664. [Google Scholar] [CrossRef]
- Alhuzali, A.; Eshete, B.; Gjomemo, R.; Venkatakrishnan, V. Chainsaw: Chained automated workflow-based exploit generation. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria, 24–28 October 2016; pp. 641–652. [Google Scholar] [CrossRef]
- Clause, J.; Li, W.; Orso, A. Dytan: A generic dynamic taint analysis framework. In Proceedings of the 2007 International Symposium on Software Testing and Analysis, London, UK, 9–12 July 2007; pp. 196–206. [Google Scholar] [CrossRef]
- Newsome, J.; Song, D. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In Proceedings of the NDSS, San Diego, CA, USA, 3–4 February 2005; Volume 5, pp. 3–4. [Google Scholar]








| Notation | Description |
|---|---|
| x | A basic block in the program. |
| The set of n-hop successor basic blocks of basic block x. | |
| The set of conflict basic blocks. | |
| . The set of predefined basic blocks whose probabilities are assigned before distance calculation, such as target blocks, exit blocks, and call-site blocks. | |
| . The set of leaf basic blocks, including all predefined basic blocks and conflict basic blocks. | |
| The conflict tree rooted at basic block t. | |
| The conflict forest, i.e., the set of all conflict trees in a control-flow graph. | |
| The leaf-coefficient vector of basic block x in conflict tree , used to construct the linear equation system. | |
| The matrix composed of the leaf-coefficient vectors in conflict tree . | |
| The static target-reachability probability of basic block x. | |
| The distance value derived from and used by the fuzzer. | |
| The distance value of an input. | |
| The set of functions executed by the program on input . |
| Project | Program | Type | Seed Type | LoC | Version | CVE/Issue | CWE |
|---|---|---|---|---|---|---|---|
| jasper | jasper | Image | - | 45,554 | 1.900.1 | CVE-2015-5221 | CWE-416 |
| mjs | mjs-bin | Text/JSE | - | 44,233 | 1.25 | issues-57/issues-78 | CWE-190/CWE-416 |
| LMS | LMS | Text/DARPA | - | 9440 | - | - | - |
| Palindrome | Palindrome | Text/DARPA | - | 250 | - | - | - |
| jhead | jhead | Image | jpg | 5649 | 3.00 | CVE-2018-6612 | CWE-125, CWE-191 |
| xpdf | pdftotext | Text | 28,958 | 4.00 | CVE-2018-7175 | CWE-476 | |
| Bento4 | mp42aac | Video | mp4 | 89,693 | 1.5.1-628 | CVE-2020-19721 | CWE-787 |
| mp3gain | mp3gain | Audio | mp3 | 12,140 | 1.5.2 | CVE-2017-14409 | CWE-787 |
| Benchmark | TriFuzz | TriFuzz-Full | TriFuzz-nSE | AFLGo | QSYM | SelectFuzz | BEACON | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TTR | TTR | (TriFuzz) | TTR | (AFLGo) | TTR | TTR | TTR | TTR | |||||
| jasper | 6.3 | 6.55 | 0.385 | 17.29 | 0.320 | 18.55 | 0.0024 | 10.5 | 0.032 | 11.2 | 0.043 | 12.5 | 0.0396 |
| mjs-issues-78 | 4.1 | 4.3 | 0.445 | 4.4 | 0.471 | 4.9 | 0.385 | 4.3 | 0.429 | 5.3 | 0.338 | 4.2 | 0.395 |
| mjs-issues-57 | 12,387.8 | 14,127.3 | 0.068 | 37,091.2 | 0.332 | 38,709.3 | 0.00085 | 6377.2 | 0.0035 | 23,934.6 | 0.00032 | 25,718.3 | 0.00076 |
| LMS | 301.6 | 317.9 | 0.222 | 292.9 | 0.442 | 334.5 | 0.423 | 244.6 | 0.049 | 359.2 | 0.060 | 304.7 | 0.450 |
| Palindrome | 1.26 | 1.21 | 0.329 | 1.12 | 0.417 | 1.15 | 0.448 | 1.23 | 0.526 | 1.13 | 0.379 | 1.22 | 0.476 |
| jhead | 209.42 | 330.58 | 0.007 | 1823.41 | 0.00002 | 33,321.85 | 0.00003 | 1946.2 | 0.0054 | 3395.7 | 0.00012 | 10,923.5 | 0.00001 |
| xpdf (pdftotext) | T.O. | T.O. | - | T.O. | - | T.O. | - | T.O. | - | T.O. | - | T.O. | - |
| Bento4 (mp42aac) | T.O. | T.O. | - | T.O. | - | T.O. | - | T.O. | - | T.O. | - | T.O. | - |
| mp3gain | 60.1 | 370.5 | 0.0002 | 9234.1 | 0.00012 | 24,098.9 | 0.00001 | 119.5 | 0.0034 | 253.7 | 0.00037 | 58.2 | 0.398 |
| Benchmark | TriFuzz | TriFuzz-Full | TriFuzz-nSE | AFLGo | QSYM | SelectFuzz | BEACON | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TTE | TTE | (TriFuzz) | TTE | (AFLGo) | TTE | TTE | TTE | TTE | |||||
| jasper | 10.9 | 13.4 | 0.178 | 46.3 | 0.221 | 53.5 | 0.0011 | 20.1 | 0.028 | 30.1 | 0.017 | 35.7 | 0.015 |
| mjs-issues-78 | 1046.7 | 1210.8 | 0.013 | 5362.5 | 0.0023 | 8718.8 | 0.00005 | 2316.9 | 0.014 | 4427.9 | 0.0032 | 3892.1 | 0.0053 |
| mjs-issues-57 | 4427.1 | 6871.9 | 0.0047 | 12,930.2 | 0.0026 | 28,021.3 | 0.00003 | 3698.1 | 0.024 | 10,596.2 | 0.022 | 8915.5 | 0.015 |
| LMS | 5218.2 | 7293.6 | 0.017 | 7721.5 | 0.225 | 7564.2 | 0.034 | 5940.5 | 0.182 | 9501.4 | 0.025 | 4011.6 | 0.044 |
| Palindrome | 1.60 | 1.87 | 0.353 | 1.82 | 0.547 | 1.75 | 0.651 | 1.10 | 0.173 | 1.65 | 0.479 | 1.78 | 0.514 |
| jhead | 540.7 | 882.3 | 0.012 | 27,891.5 | 0.0003 | 47,612.2 | 0.00001 | 2398.2 | 0.0037 | 5273.5 | 0.0021 | 13,647.8 | 0.0005 |
| xpdf (pdftotext) | 2602 | 2934.25 | 0.151 | 4025.3 | 0.019 | 4893.4 | 0.0076 | 4216.2 | 0.0018 | 602.6 | 0.0066 | 5932.1 | 0.013 |
| Bento4 (mp42aac) | 392.5 | 416.1 | 0.149 | 412.9 | 0.182 | 420.3 | 0.287 | 490.1 | 0.031 | 448.2 | 0.251 | 149.6 | 0.030 |
| mp3gain | 84.45 | 280.7 | 0.0007 | 881.2 | 0.453 | 918.5 | 0.00002 | 190.7 | 0.013 | 523.1 | 0.0008 | 128.9 | 0.039 |
| Metric | Comparison | jasper | mjs-78 | mjs-57 | LMS | Palindrome | jhead | pdftotext | mp42aac | mp3gain | All |
|---|---|---|---|---|---|---|---|---|---|---|---|
| TTR | TriFuzz & TriFuzz-Full | 1.0× | 1.0× | 1.1× | 1.1× | 1.0× | 1.6× | - | - | 6.2× | 1.9× |
| TriFuzz-nSE & AFLGo | 1.1× | 1.1× | 1.0× | 1.1× | 1.0× | 18.3× | - | - | 2.6× | 3.8× | |
| QSYM | 1.7× | 1.0× | 0.5× | 0.8× | 1.0× | 9.3× | - | - | 2.0× | 2.3× | |
| SelectFuzz | 1.8× | 1.3× | 1.9× | 1.2× | 0.9× | 16.2× | - | - | 4.2× | 3.9× | |
| BEACON | 2.0× | 1.0× | 2.1× | 1.0× | 1.0× | 52.2× | - | - | 1.0× | 8.6× | |
| TTE | TriFuzz & TriFuzz-Full | 1.2× | 1.2× | 1.6× | 1.4× | 1.2× | 1.6× | 1.1× | 1.1× | 3.3× | 1.5× |
| TriFuzz-nSE & AFLGo | 1.2× | 1.6× | 2.2× | 1.0× | 1.0× | 1.7× | 1.2× | 1.0× | 1.0× | 1.3× | |
| QSYM | 1.8× | 2.2× | 0.8× | 1.1× | 0.7× | 4.4× | 1.6× | 1.2× | 2.3× | 1.8× | |
| SelectFuzz | 2.8× | 4.2× | 2.4× | 1.8× | 1.0× | 9.8× | 0.2× | 1.1× | 6.2× | 3.3× | |
| BEACON | 3.3× | 3.7× | 2.0× | 0.8× | 1.1× | 25.2× | 2.3× | 0.4× | 1.5× | 4.5× |
| Prog. | RTV | TTE | TTR | |||||
|---|---|---|---|---|---|---|---|---|
| TriFuzz | TriFuzz-Full | TriFuzz-nSE | AFLGo | (TF, AFLGo) | (TF, TFfull) | (TF, AFLGo) | (TF, TFfull) | |
| jasper | 59.8 | 87.8 | 412.3 | 405.9 | 0.973 | 0.637 | 0.853 | 0.530 |
| mjs-issues-78 | 0.958 | 0.461 | 0.534 | 0.512 | ||||
| mjs-issues-57 | 0.897 | 0.640 | 0.922 | 0.569 | ||||
| LMS | 0.360 | 0.632 | 0.651 | 0.511 | ||||
| Palindrome | 1.07 | 1.03 | 1.07 | 1.05 | 0.524 | 0.581 | 0.493 | 0.493 |
| jhead | 0.990 | 0.789 | 0.995 | 0.860 | ||||
| xpdf (pdftotext) | 0.910 | 0.649 | - | - | ||||
| Bento4 (mp42aac) | 0.564 | 0.555 | - | - | ||||
| mp3gain | 235.9 | 0.988 | 0.482 | 0.814 | 0.975 | |||
| Prog. | Time (s) | Max RSS (KB) | ||||||
|---|---|---|---|---|---|---|---|---|
| TriFuzz | TriFuzz (Optimized) | AFLGo | AFLGo (Fast) | TriFuzz | TriFuzz (Optimized) | AFLGo | AFLGo (Fast) | |
| jasper | 0.44 | 0.41 | 107.875 | 2.105 | 78,408 | 79,064 | 112,588 | 112,964 |
| mjs-issues-78 | 4.74 | 4.85 | 40.728 | 1.053 | 45,004 | 45,604 | 100,932 | 101,116 |
| mjs-issues-57 | 4.85 | 5.05 | 40.220 | 1.055 | 45,564 | 45,732 | 101,420 | 101,160 |
| Palindrome | ≈0 | ≈0 | 2.953 | 0.251 | 30,976 | 30,464 | 78,260 | 77,292 |
| jhead | 52.84 | 0.52 | 6.437 | 0.170 | 585,372 | 54,528 | 77,568 | 77,824 |
| Bento4 (mp42aac) | 15.15 | 15.25 | 405.230 | 37.450 | 106,488 | 108,912 | 299,260 | 183,232 |
| mujs | 46.69 | 0.24 | 13.200 | 1.340 | 349,952 | 48,128 | 83,029 | 84,231 |
| cflow | 0.14 | 0.13 | 45.425 | 1.178 | 45,968 | 46,140 | 75,008 | 69,836 |
| xpdf (pdftotext) | T.O. | 91.72 | 546.434 | 156.340 | T.O. | 246,444 | 362,744 | 326,836 |
| objdump | T.O. | 186.98 | 1301.534 | 18.830 | T.O. | 1,625,368 | 2,439,868 | 501,452 |
| SQLite | 113.78 | 124.93 | 389.309 | 7.569 | 147,084 | 207,864 | 302,808 | 289,060 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Li, Y.; Wang, Y.; Feng, R.; Li, J.; Qin, W. TriFuzz: Probabilistic Distance-Guided Hybrid Directed Fuzzing with Selective Symbolic Instrumentation. Electronics 2026, 15, 2049. https://doi.org/10.3390/electronics15102049
Li Y, Wang Y, Feng R, Li J, Qin W. TriFuzz: Probabilistic Distance-Guided Hybrid Directed Fuzzing with Selective Symbolic Instrumentation. Electronics. 2026; 15(10):2049. https://doi.org/10.3390/electronics15102049
Chicago/Turabian StyleLi, Yufeng, Yiwei Wang, Runhan Feng, Jiangtao Li, and Wutao Qin. 2026. "TriFuzz: Probabilistic Distance-Guided Hybrid Directed Fuzzing with Selective Symbolic Instrumentation" Electronics 15, no. 10: 2049. https://doi.org/10.3390/electronics15102049
APA StyleLi, Y., Wang, Y., Feng, R., Li, J., & Qin, W. (2026). TriFuzz: Probabilistic Distance-Guided Hybrid Directed Fuzzing with Selective Symbolic Instrumentation. Electronics, 15(10), 2049. https://doi.org/10.3390/electronics15102049

