SearcharxivSearch

arXiv subjects

Jingchuan Ma

Publications and source records attributed to Jingchuan Ma.

2 recordsLinked to original sources

AdaRare: Telemetry-Guided Joint Profile Control for Greybox Fuzzing

Greybox fuzzers combine interacting queue, mutation, dictionary, energy, and comparison-solving control surfaces, while prior adaptive systems typically optimize other decision objects or control layers. We present AdaRare, an AFL++ extension that coordinates five internal actuation mechanisms as one bounded in-process profile updated every 5,000 ms. Completed-window, action-induced telemetry feeds an arm-local recency-weighted linear scorer and a profile-conditioned controller target. The scorer borrows the algebraic structure of disjoint LinUCB, but serves as a closed-loop profile-ranking mechanism rather than a calibrated contextual-bandit action-value estimator or statistical confidence bound. Across three sequential repeated-trial phases, Main provides broad integrated-system evidence: AdaRare has higher median edge coverage than vanilla AFL++ on all eight targets, with five Holm-significant comparisons. In the strongest matched result, Full AdaRare has higher median edge coverage than CmpLog-matched AFL++ on all five follow-up targets, with four Holm-significant comparisons. Batch A finds higher medians for telemetry-guided selection than fixed-context, random, and round-robin schedules in all 15 target-control comparisons, with 13 Holm-significant comparisons. The experiments do not establish independent No-A6-versus-Shadow or scarcity-bundle effects; A6 evidence is target-dependent and weakens under batch-wide correction. In an unmatched firmware case study, AdaRare-generated inputs exposed five distinct memory-corruption findings, each reproduced in a separate environment and later assigned a CVE identifier. Controller-boundary compute P99 medians are below 6.5 ms for a five-second window; complete-boundary P99 medians including synchronous logging are below 14.7 ms. These measurements characterize boundary latency, not total system overhead.

cs.CR

Rank-Two Frobenius-Linearized Normal Forms and Orthoderivative Dual Coordinates in Quadratic APN Maps

We classify binary-linear two-term Frobenius-linearized operators $L(Y)=AY^\sigma+BY$ on $K^3$, where $K$ is a finite extension of $\mathbb{F}_2$ and $\sigma$ is a fixed nontrivial Frobenius automorphism of $K$ with fixed field $\mathbb{F}_2$. Under a coefficient-rank and binary-kernel condition, if $A$ and $B$ both have $K$-rank two and $L$ has a one-dimensional kernel over $\mathbb{F}_2$, then invertible $K$-linear input and output changes reduce $L$, for this fixed $\sigma$, to the canonical model $(\alpha,\beta,\gamma)\mapsto(\alpha^\sigma+\alpha,\beta^\sigma,\gamma)$. The proof constructs the coordinate frames from the two coefficient-kernel directions and the binary kernel. In these coordinates, the first dual output row is exactly the unique nonzero trace-adjoint normal, with an exact $K$-valued normalization. For pure $\sigma$-quadratic almost perfect nonlinear maps, this identifies the orthoderivative by $\pi_F(X)^T F(X)=1$; in odd extension degree it also yields permutation behavior and a bijection from the projective plane to its dual. The triprojective construction of Gologlu and Kolsch and the cubic norm-twist construction of Li, Zhou, Li, and Qu provide two realizations arising from different algebraic constructions. The triprojective case further admits a determinant factorization and a complete dual frame, whereas the norm-twist realization shows that the pure-map consequences do not follow from the operator theorem alone. A natural Gold representation has coefficient-rank pair $(3,3)$, delimiting the rank-two subclass. The normal form also supplies exact extension-field labels for known component-radical and Walsh-support relations.

cs.CR