Conjecture on inefficiency of coverage-guided and heuristic fuzzing for JavaScript engines
Determine whether traditional coverage-guided fuzzing and heuristic-based mitigation approaches for JavaScript engines disproportionately mutate irrelevant code, thereby wasting computational resources.
Sponsor
References
This paper addresses the inefficiencies involved with fuzzing JS engines which involves the failure to prioritize high-risk paths in traditional coverage guided and limited mitigations from manual rules and observations in the literature. We conjecture that such methods spend a lot of effort mutating irrelevant codes, thereby wasting resources.
— From Coverage to Causes: Data-Centric Fuzzing for JavaScript Engines
(2512.18102 - Ganguly et al., 19 Dec 2025) in Section 8 Conclusion