Skip to content
Conference

Graph-Driven LLM-Augmented Stateful API Fuzzing for OWASP API Top 10

Aug 2026 · International Conference on Multimedia Analysis and Pattern Recognition · pp. 406-411 · 0 citations · 29 references

Abstract

Security testing of REST APIs remains difficult because real-world OpenAPI specifications are often incomplete, many flaws are inherently stateful, and prevailing stateful fuzzers optimize for structural exploration rather than OWASP-aligned risk. This paper presents APIGFUZZ, a graph-driven, OWASP-aware black-box REST API fuzzing framework that builds an operation-level parameter-flow graph from OpenAPI specifications and lightweight semantic field classification. The graph recovers producer-consumer dependencies between operations, including low-confidence create-then-access relations when response schemas are weak, and drives deterministic generation of short stateful request sequences. On top of it, the framework applies OWASP-aligned test templates and a multi-oracle panel combining status-code anomalies, authorization and sequence invariants, schema deviations, and dedicated checks for categories invisible to 5xx-only baselines such as rate limiting and injection. Large language models are used only outside the hot loop: for offline rule inference and as an optional fallback classifier for ambiguous parameters, preserving determinism and reproducibility. On vAPI 1.3 and c{api}tal, APIGFUZZ finds 33 unique bugs on vAPI under a 30-minute budget (21 oracle-only beyond 5xx detection), covers 8 of 10 OWASP API Top-10 categories, and surfaces a rate-limiting flaw on the hardened c{api}tal backend that the baselines miss.

View source

Similar papers

Book Open access Sep 2026

State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation

The security of the modern web depends on the correctness of JavaScript (JS) engines, yet these complex systems remain vulnerable to high-impact bugs. A critical limitation of state-of-the-art fuzzers is the coverage plateau: once a fuzzer saturates the control-flow graph, edge coverage loses its ability to guide disco...

Wai-Kin Wong, Dong-Wei Xiao, Anthony Cheuk Tung Lai et al. · 0 citations
Open access Oct 2026

CAST: A Compiler-Based Framework for Systematically Testing LLM Compositional Safety

Large language models (LLMs) are increasingly used in software pipelines, raising concerns about harmful behaviors in security-critical domains. Existing safety evaluations predominantly probe models with single prompts or short interactions, and therefore do not capture how safety behaves under multi-step workflows wh...

Lu Yan, Zhuo Zhang, Xiang-Zhe Xu et al. · 0 citations
Sep 2026

SE4SC-LLM: an LLM-Augmented symbolic execution framework for smart contracts

SE4SC-LLM, an LLM-augmented symbolic execution framework for smart contracts that achieves 95.1% average CFG coverage, a 6.5 percentage point improvement over the strongest baseline, and detects 11.2% more vulnerabilities.

Tian-Huan Miao, Yang Liu · 0 citations
Open access Sep 2026

A framework for efficient and secure LLM agency: a case for the GraphQL paradigm

It is argued that GraphQL constitutes a principled, testable alternative to function calling for agentic systems, combining lower cost, stronger safety, and improved cognitive robustness.

Viktor Zhakhalov · 0 citations
Book Open access Apr 2026

DBcover: A White-box SQL Test Generation Framework for Coverage Improvement

DBcover is proposed, an LLM-driven database test generation framework that performs white-box, code-aware SQL test generation through contextual reasoning, and substantially outperforms existing fuzzers.

Yan-Kai Rong, Shuang Liu, Jin-Hao Dong et al. · 0 citations
Conference Open access Sep 2026

QiMeng-VPID: Verification-Grounded Port-Level Iterative Decomposition for Complex Verilog Generation

This work proposes VPID, a multi-agent framework for generating complex Verilog that achieves monotonic functional improvement and introduces an experience-guided refinement strategy that distills historical waveform mismatches into constraints, guiding the targeted debugging for the unverified ports.

Hong-Guang Wang, Jiaming Guo, Rui Zhang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.