Comparison: Vulnerability Function Coverage Stopping Criterion.
As shown in the Figure 1, the proposed fuzzing termination criterion terminates 1.4–7.2 hours earlier than the vulnerability function coverage-based approach for Jasper, Libtiff, objdump, and size, while missing only 0.25 bugs on average. For nm and Libxml2, our method slightly outperforms the coverage-based strategy. In the case of Libpcap, although the proposed criterion extends fuzzing duration by 0.9 hours, it detects additional bugs, demonstrating its effectiveness.
Figure 2 illustrates that the majority of campaigns (86.5%) achieved complete bug detection, while those that missed bugs demonstrated an average reduction in runtime of 2.1 hours (equivalent to 8%). Instances where two or more bugs were missed accounted for only 5.1%, underscoring the robustness of the proposed criterion. This demonstrates that the method effectively balances efficiency and accuracy, enabling significant time savings while ensuring the majority of vulnerabilities are uncovered.