Fuzzing the Gleam Compiler
kurz.net
kurz.net
I did not think of applying LLMs on fuzzing at all until I saw llvm-hackme[0] which does both traditional mutation fuzzing as well as LLM-generated targeted regression test cases, where the LLM is pretty effective in understanding the PR and targeting edge cases! It was pretty impressive and I keep getting to think on how we can actually combine LLMs to make fuzzing much more efficient & effective.
// Sorry about the yet-another-LLM-comment. I really love PLs and I'm terribly sorry that I'm contributing yet another LLM-related content (instead of the more interesting stuff!)
I also think your instincts are on a useful path. Perhaps using a very small and stupid LLM to generate plausible-sounding-but-probably-wrong programs might be a path to generating interesting test cases?
At one point it was considered state-of-the-art. As a project it's since been superseded by AFL++ - https://aflplus.plus/ .
The main presentation of the tool lacks any description of its coverage, but from deep inside the documentation[^1] I gather that AFL++ is only relevant for GCC/LLVM languages. Gleam is not one of those.
[^1]: https://github.com/AFLplusplus/AFLplusplus/blob/stable/docs/...
I was under the impression that AFL (I don't know much about AFL++) could instrument arbitrary binaries (with obvious limitations like requiring a known calling convention.)
This is called differential fuzzing and is one of the most powerful methods to find bugs in all kinds of software.