Skip to main navigation Skip to search Skip to main content

An eBPF-Based Scheduler for the AFL++ Fuzzer

  • Ernesto Ortiz
  • , Clemente Izurieta
  • , Ann Marie Reinhold

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Fuzzing is one of the most effective software vulnerability discovery techniques. It consists of repeatedly executing a target program with mutated inputs. Fuzzing campaigns are usually run with multiple fuzzer instances running in parallel to explore the target in different ways simultaneously. This accelerates the bug discovery process. eBPF is a Linux kernel technology that allows user-space programs to be loaded into the kernel to modify kernel behavior at runtime. The Linux SCX framework allows eBPF programs to be attached to scheduling events to implement custom CPU scheduling policies. In this study, we present an approach for prioritizing AFL++ fuzzing processes using eBPF -based scheduling. Our results show that the improvement in crash discovery with process-level scheduling is target-dependent, not universal.

Original languageEnglish
Title of host publication2025 Cyber Awareness and Research Symposium, CARS 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331596286
DOIs
StatePublished - Jan 21 2026
Event2025 Cyber Awareness and Research Symposium, CARS 2025 - Grand Forks, United States
Duration: Oct 27 2025Oct 30 2025

Publication series

Name2025 Cyber Awareness and Research Symposium, CARS 2025

Conference

Conference2025 Cyber Awareness and Research Symposium, CARS 2025
Country/TerritoryUnited States
CityGrand Forks
Period10/27/2510/30/25

Keywords

  • AFL++
  • CPU Scheduling
  • eBPF
  • Fuzzing
  • sched ext

INL Publication Number

  • NA

Fingerprint

Dive into the research topics of 'An eBPF-Based Scheduler for the AFL++ Fuzzer'. Together they form a unique fingerprint.

Cite this