Fault-detection value of semantic input coverage

Evaluate whether guidance by input semantic coverage metrics meaningfully improves fault coverage compared with syntactic coverage metrics or traditional mutational code-coverage-guided fuzzers alone, particularly for highly constrained inputs.

Background

The paper reviews semantic coverage metrics, including metrics developed for compiler testing, and observes that these metrics have generally not been evaluated against syntactic coverage or traditional mutational code-coverage-guided fuzzing in terms of fault detection. Establishing whether semantic coverage provides a practical fault-finding advantage remains an unresolved empirical question, especially in settings where generated inputs are highly constrained.

References

So far, we could not find any work that has evaluated whether guidance by input semantic coverage metrics meaningfully improve fault coverage over syntactic coverage metrics or traditional mutational code coverage-guided fuzzers alone. These questions remain open for future works which generate highly constrained inputs.

An analysis of the relationship of input metrics  (2609.11824 - Crump, 10 Sep 2026) in Section 6, “Related Work,” subsection “Other input metrics”