
OSS-Fuzz के माध्यम से LLM-संचालित फ़ज़िंग।
# फ़ज़ टार्गेट जनरेशन और मूल्यांकन के लिए एक फ्रेमवर्क यह फ्रेमवर्क विभिन्न लार्ज लैंग्वेज मॉडल (LLM) के साथ वास्तविक दुनिया के `C`/`C++/Java/Python` प्रोजेक्ट्स के लिए फ़ज़ टार्गेट उत्पन्न करता है और [`OSS-Fuzz` प्लेटफ़ॉर्म](https://github.com/google/oss-fuzz) के माध्यम से उनका बेंचमार्क करता है। अधिक विवरण [AI-संचालित फ़ज़िंग: बग हंटिंग बाधा को तोड़ना](https://security.googleblog.com/2023/08/ai-powered-fuzzing-breaking-bug-hunting.html) में उपलब्ध हैं:  वर्तमान में समर्थित मॉडल हैं: - Vertex AI code-bison - Vertex AI code-bison-32k - Gemini Pro - Gemini Ultra - Gemini Experimental - Gemini 1.5 - OpenAI GPT-3.5-turbo - OpenAI GPT-4 - OpenAI GPT-4o - OpenAI GPT-4o-mini - OpenAI GPT-4-turbo - OpenAI GPT-3.5-turbo (Azure) - OpenAI GPT-4 (Azure) - OpenAI GPT-4o (Azure) उत्पन्न फ़ज़ टार्गेट का मूल्यांकन प्रोडक्शन परिवेश के सबसे अद्यतन डेटा के आधार पर चार मेट्रिक्स के साथ किया जाता है: - संकलन-क्षमता - रनटाइम क्रैश - रनटाइम कवरेज - `OSS-Fuzz` में मौजूदा मानव-लिखित फ़ज़ टार्गेट के सापेक्ष रनटाइम लाइन कवरेज अंतर यह 31 जनवरी 2024 का एक नमूना प्रयोग परिणाम है। प्रयोग में 297 ओपन-सोर्स प्रोजेक्ट्स के [1300+ बेंचमार्क](https://github.com/google/oss-fuzz-gen/blob/main/benchmark-sets/all) शामिल थे।  कुल मिलाकर, यह फ्रेमवर्क 160 C/C++ प्रोजेक्ट्स के लिए मान्य फ़ज़ टार्गेट उत्पन्न करने हेतु LLM का सफलतापूर्वक उपयोग करता है (जो गैर-शून्य कवरेज वृद्धि उत्पन्न करते हैं)। मौजूदा मानव-लिखित टार्गेट की तुलना में अधिकतम लाइन कवरेज वृद्धि 29% है। ध्यान दें कि ये रिपोर्ट सार्वजनिक नहीं हैं क्योंकि उनमें अप्रकटित कमजोरियाँ हो सकती हैं। ## उपयोग इस फ्रेमवर्क को चलाने और परिणामों के आधार पर रिपोर्ट तैयार करने के निर्देशों के लिए हमारी विस्तृत [उपयोग मार्गदर्शिका](https://github.com/google/oss-fuzz-gen/blob/main/USAGE.md) देखें। ## स्वतंत्र एजेंट निष्पादन और मूल्यांकन आप पूर्ण प्रयोग चलाए बिना, एकीकृत एजेंट निष्पादन फ्रेमवर्क का उपयोग करके व्यक्तिगत एजेंटों को निष्पादित या मूल्यांकन भी कर सकते हैं। व्यक्तिगत एजेंटों या एजेंटों के अनुक्रम को चलाने के तरीके के विस्तृत निर्देशों के लिए [फ्रेमवर्क का दस्तावेज़ीकरण](https://github.com/google/oss-fuzz-gen/blob/main/agent_tests/readme.md) देखें। ## सहयोग शोध या ओपन-सोर्स समुदाय सहयोग में रुचि रखते हैं? कृपया बेझिझक एक issue बनाएं या हमें ईमेल करें: [email protected]. <img src="https://assets.kitploit.com/production/public/readmes/48725/5b2675733e9bc674402ab5cf1ae7613df5be74fd9e1640c6e59d43f7725e6734.png" width="200" height="200"> ## खोजे गए बग्स अब तक, हम इस फ्रेमवर्क द्वारा निर्मित स्वचालित रूप से उत्पन्न टार्गेट के माध्यम से पाए गए 30 नए बग/कमजोरियों की रिपोर्ट कर चुके हैं: | प्रोजेक्ट | बग | LLM | प्रॉम्प्ट बिल्डर | टार्गेट ओरेकल | | ------- | --------- | --------- | --------------- | ------- | | [`cJSON`](https://github.com/google/oss-fuzz/tree/master/projects/cjson) | [OOB read](https://github.com/DaveGamble/cJSON/issues/800) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | [`libplist`](https://github.com/google/oss-fuzz/tree/master/projects/libplist) | [OOB read](https://github.com/libimobiledevice/libplist/issues/244) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | [`hunspell`](https://github.com/google/oss-fuzz/tree/master/projects/hunspell) | [OOB read](https://github.com/hunspell/hunspell/issues/996) | Vertex AI | [default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | [`zstd`](https://github.com/google/oss-fuzz/tree/master/projects/zstd) | [OOB write](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67497) | Vertex AI | [default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | [`gdbm`](https://github.com/google/oss-fuzz/tree/master/projects/gdbm) | [Stack buffer underflow](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67483) | Vertex AI | [default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | [`hoextdown`](https://github.com/google/oss-fuzz/tree/master/projects/hoextdown) | [Use of uninitialised memory](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67516) | Vertex AI | [default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | [`pjsip`](https://github.com/google/oss-fuzz/tree/master/projects/pjsip) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71356) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | फ़ज़ कीवर्ड + आसान पैरामीटर के साथ कम कवरेज, दूर की पहुँच | | [`pjsip`](https://github.com/google/oss-fuzz/tree/master/projects/pjsip) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71357) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | फ़ज़ कीवर्ड + आसान पैरामीटर के साथ कम कवरेज, दूर की पहुँच | | [`gpac`](https://github.com/google/oss-fuzz/tree/master/projects/gpac) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71358) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | फ़ज़ कीवर्ड + आसान पैरामीटर के साथ कम कवरेज, दूर की पहुँच | | [`gpac`](https://github.com/google/oss-fuzz/tree/master/projects/gpac) | [OOB read/write](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71542) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`gpac`](https://github.com/google/oss-fuzz/tree/master/projects/gpac) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71543) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`gpac`](https://github.com/google/oss-fuzz/tree/master/projects/gpac) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71544) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`sqlite3`](https://github.com/google/oss-fuzz/tree/master/projects/sqlite3) | [OOB read](https://issues.oss-fuzz.com/issues/42538590) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`htslib`](https://github.com/google/oss-fuzz/tree/master/projects/htslib) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71740) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`libical`](https://github.com/google/oss-fuzz/tree/master/projects/libical) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71741) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`croaring`](https://github.com/google/oss-fuzz/tree/master/projects/croaring) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71738) | Vertex AI | [Test-to-harness](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`openssl`](https://github.com/google/oss-fuzz/tree/master/projects/openssl) | [CVE-2024-9143](https://www.cve.org/CVERecord?id=CVE-2024-9143) - [OOB read/write](https://g-issues.oss-fuzz.com/issues/42538437) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`liblouis`](https://github.com/google/oss-fuzz/tree/master/projects/liblouis) | [Use of uninitialised memory](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71354) | Vertex AI | Test-to-harness | टेस्ट पहचानकर्ता | | [`libucl`](https://github.com/google/oss-fuzz/tree/master/projects/libucl) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71359) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | फ़ज़ कीवर्ड + आसान पैरामीटर के साथ कम कवरेज, दूर की पहुँच | | [`openbabel`](https://github.com/google/oss-fuzz/tree/master/projects/openbabel) | [Use after free](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71360) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | फ़ज़ कीवर्ड + आसान पैरामीटर के साथ कम कवरेज, दूर की पहुँच | | [`libyang`](https://github.com/google/oss-fuzz/tree/master/projects/libyang) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71619) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`openbabel`](https://github.com/google/oss-fuzz/tree/master/projects/openbabel) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71650) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | [`exiv2`](https://github.com/google/oss-fuzz/tree/master/projects/exiv2) | [OOB read](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=71759) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | अज्ञात | Java RCE (मेंटेनर ट्राएज की प्रतीक्षा है) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | अज्ञात | Regexp DoS (मेंटेनर ट्राएज की प्रतीक्षा है) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | दूर की पहुँच, कम कवरेज | | अज्ञात | [OOB read](https://issues.oss-fuzz.com/issues/370872803) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | अज्ञात | [OOB write](https://issues.oss-fuzz.com/issues/378009361) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | अज्ञात | [OOB read](https://issues.oss-fuzz.com/issues/391234167) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | अज्ञात | [OOB read](https://issues.oss-fuzz.com/issues/391453674) | Vertex AI | [Default](https://github.com/google/oss-fuzz-gen/blob/main/prompts/template_xml) | सभी | | अज्ञात | [Use after free](https://issues.oss-fuzz.com/issues/391456091) | Vertex AI | Agent prompt | सभी | ये बग केवल नए उत्पन्न टार्गेट के साथ ही खोजे जा सकते थे। ये मौजूदा OSS-Fuzz टार्गेट के साथ पहुँच योग्य नहीं थे। ## प्रोजेक्ट द्वारा वर्तमान शीर्ष कवरेज सुधार | प्रोजेक्ट | कुल कवरेज लाभ | कुल सापेक्ष लाभ | OSS-Fuzz-gen कुल कवर की गई लाइनें | OSS-Fuzz-gen नई कवर की गई लाइनें | मौजूदा कवर की गई लाइनें | कुल प्रोजेक्ट लाइनें | | --------| ------------------- | ------------------- | -------------------------------- | ------------------------------ | ---------------------- | ------------------- | | phmap | 98.42% | 205.75% | 1601 | 1181 | 574 | 1120 | | usbguard | 97.62% | 26.04% | 24550 | 5463 | 20979 | 3564 | | onednn | 96.67% | 7057.14% | 5434 | 5434 | 77 | 210 | | avahi | 82.06% | 155.90% | 3358 | 2814 | 1805 | 3046 | | pugixml | 72.98% | 194.95% | 9015 | 6646 | 3409 | 7662 | | librdkafka | 66.88% | 845.57% | 5019 | 4490 | 531 | 1169 | | casync | 66.75% | 903.23% | 1171 | 1120 | 124 | 1678 | | tomlplusplus | 61.06% | 331.10% | 4755 | 3652 | 1103 | 5981 | | astc-encoder | 59.35% | 177.88% | 2726 | 1745 | 981 | 2940 | | mruby | 48.56% | 0.00% | 34493 | 34493 | 0 | 71038 | | arduinojson | 42.10% | 85.80% | 3344 | 1800 | 2098 | 4276 | | json | 41.13% | 66.51% | 5051 | 3339 | 5020 | 8119 | | double-conversion | 40.40% | 88.12% | 1663 | 779 | 884 | 1928 | | tinyobjloader | 38.26% | 77.01% | 1157 | 717 | 931 | 1874 | | glog | 38.18% | 58.69% | 895 | 331 | 564 | 867 | | cppitertools | 35.78% | 45.07% | 253 | 151 | 335 | 422 | | eigen | 35.38% | 190.70% | 2643 | 1947 | 1021 | 5503 | | glaze | 34.55% | 30.06% | 2920 | 2416 | 8036 | 6993 | | rapidjson | 31.83% | 148.07% | 1585 | 958 | 647 | 3010 | | libunwind | 30.58% | 83.25% | 2899 | 1342 | 1612 | 4388 | | openh264 | 30.07% | 50.14% | 6607 | 5751 | 11470 | 19123 | \* "कुल प्रोजेक्ट लाइनें" उस प्रोजेक्ट-अंडर-टेस्ट के सोर्स कोड को मापता है जिसे OSS-Fuzz के पहले से मौजूद मानव-लिखित फ़ज़ टार्गेट द्वारा संकलित और लिंक किया गया है। \* "कुल कवरेज लाभ" की गणना "कुल प्रोजेक्ट लाइनें" के हर के रूप में उपयोग करके की जाती है। "कुल सापेक्ष लाभ" कवर की गई पुरानी लाइनों की संख्या की तुलना में कवरेज में वृद्धि है। \* प्रोजेक्ट-अंडर-टेस्ट का अतिरिक्त कोड नए फ़ज़ टार्गेट संकलित करते समय शामिल हो सकता है और उच्च प्रतिशत लाभ में परिणाम दे सकता है। ## इस कार्य का उद्धरण उद्धरण विवरण के लिए कृपया इस GitHub पृष्ठ के दाईं ओर स्थित _'Cite this repository'_ बटन पर क्लिक करें।