SimiFuzz: Seed–Worker Scheduling for Parallel Fuzzing via Contextual Bandits
Parallel fuzzing is now a standard way to scale vulnerability discovery, yet its efficiency is still limited by ineffective task allocation among workers. Existing approaches mainly aim to reduce conflicts; however, none considers the interaction between seeds and workers: the same seed can yield very different gains on different workers due to their divergent exploration states. As a result, parallel fuzzing can drift toward over-isolation that wastes shared states, or excessive overlap that duplicates effort. To solve this problem, we present SimiFuzz, a context-aware scheduling framework that learns to assign seed–worker pairs online. SimiFuzz encodes each assignment with a compact context vector that jointly models seed characteristics, worker state, and seed–worker interaction. On top of this representation, SimiFuzz employs a LinUCB-based contextual bandit to score candidate pairs, balancing individual worker efficiency against group-level redundancy to maximize collective progress. To handle non-stationary fuzzing dynamics, SimiFuzz adopts a time-slice feedback mechanism that aggregates coverage gains within fixed intervals, combining globally new edges with cross-learning progress to form stable reward signals. We implement SimiFuzz on top of AFL++ and evaluate it on eight real-world targets. In 24-hour campaigns with 10 parallel instances, SimiFuzz improves average edge coverage by 11.76 % over FlexFuzz, the strongest baseline in coverage and unique vulnerability (VUL) count, achieves the highest final coverage on all evaluated targets, and uncovers 16 more unique vulnerabilities and 11 more CVEs than FlexFuzz.
Authors
- Dandan Zhao (ORCID: https://orcid.org/0000-0001-9375-2997)
- Hao Peng (ORCID: https://orcid.org/0000-0003-0586-7132)
- Shouling Ji (ORCID: https://orcid.org/0000-0003-4268-372X)
- Zhiguo Ding
- Ming Jun Zhong (ORCID: https://orcid.org/0000-0002-9132-3782)
- Bo Zhang (ORCID: https://orcid.org/0000-0002-6975-9184)
- Xuhong Zhang (ORCID: https://orcid.org/0000-0002-8571-9780)
- Hong Liang (ORCID: https://orcid.org/0000-0003-1132-840X)
- Yijia Guo (ORCID: https://orcid.org/0009-0007-2413-3173)
Institutions
- Zhejiang Normal University (CN)
- China Electric Power Research Institute
- Zhejiang University (CN)
Publication Details
- Journal
- Proceedings of the ACM on software engineering.
- Published
- 2026-10-01
- DOI
- https://doi.org/10.1145/3832107
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00