{"ID":2873640,"CreatedAt":"2026-06-01T04:54:23.091178241Z","UpdatedAt":"2026-06-01T04:54:23.091178241Z","DeletedAt":null,"paper_url":"https://arxiv.org/abs/2509.07225","arxiv_id":"2509.07225","title":"All You Need Is A Fuzzing Brain: An LLM-Powered System for Automated Vulnerability Detection and Patching","abstract":"Our team, All You Need Is A Fuzzing Brain, was one of seven finalists in DARPA's Artificial Intelligence Cyber Challenge (AIxCC), placing fourth in the final round. During the competition, we developed a Cyber Reasoning System (CRS) that autonomously discovered 28 security vulnerabilities - including six previously unknown zero-days - in real-world open-source C and Java projects, and successfully patched 14 of them. The complete CRS is open source at https://github.com/o2lab/afc-crs-all-you-need-is-a-fuzzing-brain. This paper provides a detailed technical description of our CRS, with an emphasis on its LLM-powered components and strategies. Building on AIxCC, we further introduce a public leaderboard for benchmarking state-of-the-art LLMs on vulnerability detection and patching tasks, derived from the AIxCC dataset. The leaderboard is available at https://o2lab.github.io/FuzzingBrain-Leaderboard/.","short_abstract":"Our team, All You Need Is A Fuzzing Brain, was one of seven finalists in DARPA's Artificial Intelligence Cyber Challenge (AIxCC), placing fourth in the final round. During the competition, we developed a Cyber Reasoning System (CRS) that autonomously discovered 28 security vulnerabilities - including six previously unk...","url_abs":"https://arxiv.org/abs/2509.07225","url_pdf":"https://arxiv.org/pdf/2509.07225v1","authors":"[\"Ze Sheng\",\"Qingxiao Xu\",\"Jianwei Huang\",\"Matthew Woodcock\",\"Heqing Huang\",\"Alastair F. Donaldson\",\"Guofei Gu\",\"Jeff Huang\"]","published":"2025-09-08T21:08:01Z","proceeding":"cs.CR","tasks":"[\"cs.CR\"]","methods":"[\"Large Language Model\"]","has_code":false,"code_links":[{"ID":610078,"CreatedAt":"2026-06-01T04:54:23.091178241Z","UpdatedAt":"2026-06-01T04:54:23.091178241Z","DeletedAt":null,"paper_id":2873640,"paper_url":"https://arxiv.org/abs/2509.07225","paper_title":"All You Need Is A Fuzzing Brain: An LLM-Powered System for Automated Vulnerability Detection and Patching","repo_url":"https://github.com/o2lab/afc-crs-all-you-need-is-a-fuzzing-brain","is_official":false,"mentioned_in_paper":false,"mentioned_in_github":true,"github_stars":0}]}
