arXiv · 2307.14556
Reinforcement learning guided fuzz testing for a browser's HTML rendering engine
Abstract
Generation-based fuzz testing can uncover various bugs and security vulnerabilities. However, compared to mutation-based fuzz testing, it takes much longer to develop a well-balanced generator that produces good test cases and decides where to break the underlying structure to exercise new code paths. We propose a novel approach to combine a trained test case generator deep learning model with a double deep Q-network (DDQN) for the first time. The DDQN guides test case creation based on a code coverage signal. Our approach improves the code coverage performance of the underlying generator model by up to 18.5\% for the Firefox HTML rendering engine compared to the baseline grammar based fuzzer.
Explore related subjects
Keep this discovery
Martin Sablotny, Bjørn Sand Jensen, Jeremy Singer. 2023-07-27. Reinforcement learning guided fuzz testing for a browser's HTML rendering engine. https://arxiv.org/abs/2307.14556
Cite the original work for its findings. Save a collection to share your selection of sources.