{"id":"https://openalex.org/W7162122494","doi":"https://doi.org/10.48550/arxiv.2605.21779","title":"FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction","display_name":"FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction","publication_year":2026,"publication_date":"2026-05-20","ids":{"openalex":"https://openalex.org/W7162122494","doi":"https://doi.org/10.48550/arxiv.2605.21779"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.21779","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.21779","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.21779","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5136769004","display_name":"Ze Sheng","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sheng, Ze","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046300025","display_name":"Z.G. Chen","orcid":"https://orcid.org/0000-0001-8214-4128"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Zhicheng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136788383","display_name":"Qingxiao Xu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xu, Qingxiao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136776441","display_name":"Kewen Zhu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhu, Kewen","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5136762512","display_name":"Jeff Huang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Huang, Jeff","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.39250001311302185,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.39250001311302185,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.2003999948501587,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.15809999406337738,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.8258000016212463},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.8007000088691711},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.6776999831199646},{"id":"https://openalex.org/keywords/vulnerability-assessment","display_name":"Vulnerability assessment","score":0.633899986743927},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.6251999735832214},{"id":"https://openalex.org/keywords/abstraction","display_name":"Abstraction","score":0.5228000283241272},{"id":"https://openalex.org/keywords/function","display_name":"Function (biology)","score":0.49230000376701355}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.8258000016212463},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.8007000088691711},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7378000020980835},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.6776999831199646},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.633899986743927},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.6251999735832214},{"id":"https://openalex.org/C124304363","wikidata":"https://www.wikidata.org/wiki/Q673661","display_name":"Abstraction","level":2,"score":0.5228000283241272},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5217999815940857},{"id":"https://openalex.org/C14036430","wikidata":"https://www.wikidata.org/wiki/Q3736076","display_name":"Function (biology)","level":2,"score":0.49230000376701355},{"id":"https://openalex.org/C22680326","wikidata":"https://www.wikidata.org/wiki/Q7444867","display_name":"Secure coding","level":5,"score":0.48579999804496765},{"id":"https://openalex.org/C97686452","wikidata":"https://www.wikidata.org/wiki/Q7604153","display_name":"Static analysis","level":2,"score":0.47620001435279846},{"id":"https://openalex.org/C172776598","wikidata":"https://www.wikidata.org/wiki/Q7943570","display_name":"Vulnerability management","level":4,"score":0.46619999408721924},{"id":"https://openalex.org/C206345919","wikidata":"https://www.wikidata.org/wiki/Q20380951","display_name":"Resource (disambiguation)","level":2,"score":0.4406000077724457},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.415800005197525},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.3228999972343445},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.320499986410141},{"id":"https://openalex.org/C38369872","wikidata":"https://www.wikidata.org/wiki/Q7445009","display_name":"Security analysis","level":2,"score":0.28610000014305115},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.27900001406669617},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.25189998745918274},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.25119999051094055}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.21779","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.21779","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.21779","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.21779","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Software":[0],"vulnerabilities":[1,73,108,180],"pose":[2],"critical":[3],"security":[4],"threats,":[5],"with":[6,74,131,147,191],"nearly":[7],"50,000":[8],"CVEs":[9],"reported":[10,107],"in":[11],"2025.":[12],"While":[13],"Large":[14],"Language":[15],"Models":[16],"(LLMs)":[17],"show":[18],"promise":[19],"for":[20,49,118],"automated":[21,98],"vulnerability":[22,30,50,99,120,152],"detection,":[23],"three":[24],"key":[25,94],"challenges":[26],"remain.":[27],"First,":[28],"LLM-generated":[29],"reports":[31],"suffer":[32],"from":[33],"high":[34],"false":[35],"positive":[36],"rates":[37],"and":[38,78,143,187],"lack":[39],"reproducible":[40],"verification.":[41],"Second,":[42],"existing":[43,67],"LLM-based":[44],"approaches":[45,68],"use":[46],"suboptimal":[47],"granularities":[48],"localization:":[51],"function-level":[52],"analysis":[53,62,100,130,145],"overlooks":[54],"bugs":[55],"when":[56],"context":[57,148],"becomes":[58],"extensive,":[59],"while":[60],"line-level":[61],"lacks":[63],"sufficient":[64],"context.":[65],"Third,":[66],"have":[69],"difficulty":[70],"reasoning":[71],"about":[72],"complex":[75,151],"cross-function":[76],"dependencies":[77],"triggering":[79],"conditions.":[80],"We":[81],"present":[82],"FuzzingBrain":[83,162,175],"V2,":[84],"a":[85,114],"multi-agent":[86],"system":[87],"that":[88],"addresses":[89],"these":[90],"gaps":[91],"through":[92],"four":[93],"contributions:":[95],"(1)":[96],"fully":[97],"built":[101],"on":[102],"Google's":[103],"OSS-Fuzz,":[104],"ensuring":[105],"all":[106,185],"are":[109],"fuzzer-reproducible;":[110],"(2)":[111],"Suspicious":[112],"Point,":[113],"novel":[115],"control-flow-based":[116],"abstraction":[117],"precise":[119],"localization":[121],"at":[122],"the":[123,155],"optimal":[124],"granularity;":[125],"(3)":[126],"logic-driven":[127],"hierarchical":[128],"function":[129,135],"dual-layer":[132],"fuzzing":[133],"enhancing":[134,150],"coverage":[136],"under":[137],"resource":[138],"constraints;":[139],"(4)":[140],"MCP-based":[141],"static":[142],"dynamic":[144],"tools":[146],"engineering":[149],"reasoning.":[153],"On":[154],"AIxCC":[156],"2025":[157],"Final":[158],"Competition":[159],"C/C++":[160],"dataset,":[161],"V2":[163,176],"achieved":[164],"90%":[165],"detection":[166],"rate":[167],"(36":[168],"of":[169],"40":[170],"vulnerabilities).":[171],"In":[172],"real-world":[173],"deployment,":[174],"discovered":[177],"29":[178],"zero-day":[179],"across":[181],"12":[182],"open-source":[183],"projects,":[184],"confirmed":[186],"fixed":[188],"by":[189],"maintainers,":[190],"2":[192],"assigned":[193],"CVE":[194],"IDs.":[195]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-23T00:00:00"}
