{"id":"W7126220716","doi":"10.1109/raid67961.2025.00034","title":"SyzGrapher: Resource-Centric Graph-Based Kernel Fuzzing","year":2025,"lang":"","type":"article","venue":"","topic":"Security and Verification in Computing","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Toronto","funders":"","keywords":"Fuzz testing; Exploit; Kernel (algebra); Code (set theory); System call; Call stack; Dependency (UML); Linux kernel","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001283327,0.001794425,0.0006706144,0.002227722,0.0005898918,0.001144007,0.00259228,0.001529227,0.002864763],"category_scores_gemma":[0.01111844,0.0009751827,0.001888747,0.0007269894,0.001926965,0.003184304,0.002116899,0.001844963,0.0008077949],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001314304,"about_ca_system_score_gemma":0.001460013,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.006304526,"about_ca_topic_score_gemma":0.01181269,"domain_scores_codex":[0.9985265,0.0003174575,0.00007930392,0.0004511522,0.0005137784,0.0001118456],"domain_scores_gemma":[0.9940675,0.003593766,0.0006190069,0.001248837,0.0003515976,0.0001192419],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.0008267523,0.0005846272,0.04274889,0.001199927,0.0006337114,0.001016869,0.001174668,0.4463342,0.06607959,0.02999657,0.03071969,0.3786846],"study_design_scores_gemma":[0.00008038378,0.0001519552,0.00253976,0.00005812621,0.00007326004,0.000271189,0.00007297393,0.9434007,0.02173074,0.02614132,0.005432202,0.0000474003],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1493916,0.0008807306,0.6790146,0.000982854,0.0001597652,0.0003789054,0.001950516,0.1632878,0.003953205],"genre_scores_gemma":[0.5525535,0.0003229965,0.4321568,0.0005782517,0.00003673876,0.0002403558,0.004638038,0.00663829,0.002835003],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.006304526,"threshold_uncertainty_score":0.01253569,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01873558124654708,"score_gpt":0.2607275642574595,"score_spread":0.2419919830109124,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}