RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    RAG 기반 라이브러리 하네스 자동 생성 프레임워크 = RAG-Based Framework for Automatic Library Harness Generation

    한글로보기

    https://www.riss.kr/link?id=A110179217

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Library fuzzing is a powerful technique for vulnerability detection; however, harness generation remains a critical bottleneck because API-centric libraries lack a single entry point. Existing LLM-based harness generation approaches often compose APIs without access to library-specific documentation or code context, leading to hallucinations, API misuse, and incorrect initialization, which result in a large number of non-executable harnesses. To address these limitations, we propose a framework for harness generation based on RAG. Our framework retrieves library resources, including API documentation, header files, and example code. It injects them into the LLM input context, enabling grounded harness generation that respects library-specific initialization rules and API usage constraints. In addition, we employ a compile-time validation and an iterative repair loop to filter and retain only executable harnesses that fuzzers can use directly. Experimental results demonstrate that RAG-based context injection significantly improves harness compilability and executability, and contributes to expanding the set of reachable functions during fuzzing. This work presents a new paradigm for combining RAG and LLMs in harness generation. It serves as a foundational technique for improving the reliability and efficiency of LLM-driven library fuzzing automation.
    번역하기

    Library fuzzing is a powerful technique for vulnerability detection; however, harness generation remains a critical bottleneck because API-centric libraries lack a single entry point. Existing LLM-based harness generation approaches often compose APIs...

    Library fuzzing is a powerful technique for vulnerability detection; however, harness generation remains a critical bottleneck because API-centric libraries lack a single entry point. Existing LLM-based harness generation approaches often compose APIs without access to library-specific documentation or code context, leading to hallucinations, API misuse, and incorrect initialization, which result in a large number of non-executable harnesses. To address these limitations, we propose a framework for harness generation based on RAG. Our framework retrieves library resources, including API documentation, header files, and example code. It injects them into the LLM input context, enabling grounded harness generation that respects library-specific initialization rules and API usage constraints. In addition, we employ a compile-time validation and an iterative repair loop to filter and retain only executable harnesses that fuzzers can use directly. Experimental results demonstrate that RAG-based context injection significantly improves harness compilability and executability, and contributes to expanding the set of reachable functions during fuzzing. This work presents a new paradigm for combining RAG and LLMs in harness generation. It serves as a foundational technique for improving the reliability and efficiency of LLM-driven library fuzzing automation.

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼