Constarium
← Search

Table · dataset · 2026

CLADFuzz

Listed in figshare

Description

<p dir="ltr"><b>Description</b></p><p dir="ltr">This deposit contains the complete implementation and test corpus of CLADFuzz, a constraint-guided fuzzing framework for OOXML office documents, corresponding to the research paper on constraint-aware dependency-guided OOXML fuzzing.</p><p dir="ltr"><b>Background</b></p><p dir="ltr">Office documents are OOXML ZIP packages whose interdependent parts determine whether an application opens, repairs, or rejects them.

Fuzzing must balance early rejection of malformed packages against validity-preserving mutations that miss inconsistent-but-parseable states. CLADFuzz com bines a Reference Constraint Graph, dependency-aware rewrit ing, and a seed-captured PackageContract. Before repacking, HardValidity gates mutated package states; TargetViolation isolates one requested new soft violation whenever a target identifier is recorded.

Read the rest (2 more)

A probabilistic destructive path also permits malformed candidates. Across 3,000 native-extension DOCX/XLSX/PPTX samples, HardValidity predicts Office ad mission with 96.3% precision and 99.8% recall. Sole-new violation realization is 99.8% for DOCX, 98.9% for XLSX, and 100% for PPTX under the modeled evaluator.

Across ten independent runs compared over the first 20 hours, CLAD Fuzz’s median post-initial occupied edge-map-slot gain is 3.6× 17.6× that of AFL++/Nyx or OpenXMolar/Nyx (Holm-adjusted p <0.001). A one-year Microsoft 365 Apps campaign produced ten vendor-confirmed, patched CVEs.</p><p dir="ltr"><b>CLADFuzz Design</b></p><p dir="ltr">CLADFuzz models OOXML packages as <b>Reference Constraint Graphs</b> and combines dependency-aware rewriting with a seed-captured <i>PackageContract</i> to maintain structural validity while enabling precise consistency mutations.</p><ul><li><b>HardValidity</b>: A structure-aware gating mechanism that filters out structurally invalid inputs before they are sent to the target application</li><li><b>TargetViolation</b>: A control predicate for targeted consistency mutation, which isolates exactly one requested soft-constraint violation per generated input</li><li>A bounded destructive channel to retain malformed inputs for broader exploration of parser boundary behavio</li></ul><p dir="ltr"><b>Contents of This Deposit</b></p><ol><li>Full source code of the CLADFuzz fuzzing framework</li><li>A curated benchmark corpus of 300 native-extension DOCX, XLSX, and PPTX seed samples</li><li>Experiment configuration files and run scripts for comparative testing with AFL++/Nyx and OpenXMolar/Nyx</li><li>Proof-of-concept samples for the 10 vendor-confirmed CVEs (all vulnerabilities have been patched by Microsoft)</li></ol><p dir="ltr"><b>Citation</b></p><p dir="ltr">Please cite the associated research paper when using this framework or dataset in your work.</p>

Links

Where it is published

Catalogue records · 1

Topics

Provenance · 1 source records, 18 field assertions
SourceKeyLast seenRaw
figshareoai:figshare.com:article/334574534 d agoJSON v1
FieldAssertionExtractorEvidence
access_levelsource · figshare comconnector:figshare_com@1.0.0
concepts[field].anzsrc:field:460406mapping · figshare comvocabulary-mapper@1.0.0keywords['software security']
concepts[field].anzsrc:field:461208mapping · figshare comvocabulary-mapper@1.0.0keywords['Software testing, verification and validation']
concepts[field].local:field:astronomymapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:chemistrymapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:computer-science-aimapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:earth-environmentalmapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:economics-financemapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:engineeringmapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:humanitiesmapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:life-sciencesmapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:medicine-healthmapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:ocean-atmosphericmapping · figshare comconnector:figshare_com@1.0.0
concepts[field].local:field:social-sciencemapping · figshare comconnector:figshare_com@1.0.0
descriptionsource · figshare comconnector:figshare_com@1.0.0/metadata/dc/description
licensesource · figshare comconnector:figshare_com@1.0.0/metadata/dc/rights
publication_datesource · figshare comconnector:figshare_com@1.0.0
titlesource · figshare comconnector:figshare_com@1.0.0/metadata/dc/title