ML4Fz ML-assisted Windows DLL Fuzzer

ML4Fz is a ML-assisted extensible Windows DLL fuzzer designed to identify potential stack-based buffer overflow vulnerabilities in functions in Export Address Table (EAT) of the target DLL

01 / 04
TARGET SURFACE

Export Discovery

Enumerate exported DLL functions and build a clear target surface before fuzzing begins.

EAT EXPORTS TARGET MAP
ML4Fz export discovery example
VIEW / EXPORT DISCOVERY 0x140001120
sub_140001120

Getting Started

Four entry points from project context to the first fuzzing run.

sub_140001280

Fuzzing Graph

The graph shows target discovery, seed generation, ML-guided mutation, execution, triage and feedback as one fuzzing loop.

01 0x1280
Discover

Inspect the EAT function list and identify user-configured fuzzing targets.

EAT / target identification
02 0x12B0
Generate

Automatically generate seed inputs for the target function or use user-specified seeds.

automatic / user seed input
03 0x12F0
Mutate

Use ML to adapt the fuzzing strategy and mutate fuzzing data for the selected target.

ML-ASSISTED
ML-guided strategy / data mutation
04 0x1340
Execute

Provide the fuzzing data to the target function and execute it.

target execution
05 0x13A0
Triage

Identify and analyze crash data and branches reached during execution.

crash / reached-branch analysis
06 0x1380
Feedback

Use observed results to provide ML-based feedback for fuzzing strategy and data mutation.

ML strategy / mutation feedback
CYCLE 001
ACTIVE STAGE DISCOVER
STATUS Enumerating exported entry points.
SIGNALS
idle
sub_1400015A0

References