Spec-Driven Multi-Agent Corpus Generation for Over-the-Air Wi-Fi Fuzzing

  • Jean D’Elboux Diogo UFRJ
  • Nilton Moura UFRJ
  • Thatyanne Prado UFRJ
  • Diego Cardoso Borda UFRJ
  • Cláudia Werner UFRJ

Resumo


Over-the-air (OTA) Wi-Fi fuzzers such as owfuzz test real IEEE 802.11 devices, but their reach is limited by a hand-written, static corpus that covers only a fraction of the 802.11 frame and information-element (IE) space. We present ongoing work on an autonomous multi-agent system that reads the protocol specification and builds the fuzzing corpus automatically. A Spec-Reader, a Synthesizer, and an LLM-reasoned Feedback/Triage agent cooperate through artifact contracts and drive owfuzz, an established OTA fuzzer, against real hardware. In a preliminary OTA study, correcting a mutation-fidelity defect let the corpus populate all 15 targeted IEs and deliver its size and length mutations on the air, widening the injected frame length from at most 66 to 348 bytes across roughly 24,000 frames per campaign. The same corpus, unchanged, then drove a different device class and band (a connected 5 GHz client), indicating the agent layer is deviceand band-independent. Against owfuzz’s own hand-written corpus, the agent corpus trades raw frame volume for structural validity and stateful depth, completing a credential-gated four-way handshake the native corpus never reaches; a full coverage head-to-head is ongoing.

Referências

Cao, H., Huang, L., Hu, S., Shi, S., and Liu, Y. (2023). Owfuzz: Discovering wi-fi flaws in modern devices through over-the-air fuzzing. In Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), pages 263–273. DOI: 10.1145/3558482.3590174.

Garbelini, M. E., Wang, C., and Chattopadhyay, S. (2022). GREYHOUND: Directed greybox wi-fi fuzzing. IEEE Transactions on Dependable and Secure Computing (TDSC), 19(2):817–834. DOI: 10.1109/TDSC.2020.3014624.

Huang, C., Wang, D., and Zhou, Z. Q. (2025). LLM-assisted model-based fuzzing of protocol implementations. arXiv preprint arXiv:2508.01750.

Kampourakis, V., Chatzoglou, E., Kambourakis, G., Dolmes, A., and Zaroliagis, C. (2022). WPAxFuzz: Sniffing out vulnerabilities in Wi-Fi implementations. Cryptography (MDPI), 6(4):53. DOI: 10.3390/cryptography6040053.

Maklad, Y., Wael, F., Hamdi, A., Elsersy, W., and Shaban, K. (2025). MultiFuzz: A dense retrieval-based multi-agent system for network protocol fuzzing. arXiv preprint arXiv:2508.14300.

Meng, R., Mirchev, M., Böhme, M., and Roychoudhury, A. (2024). Large language model guided protocol fuzzing. In Proceedings of the 31st Annual Network and Distributed System Security Symposium (NDSS).

Schepers, D., Vanhoef, M., and Ranganathan, A. (2021). A framework to test and fuzz Wi-Fi devices. In Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), pages 368–370. DOI: 10.1145/3448300.3468261.

Zhong, M., Zeng, Z., Guo, Y., Zhao, D., Zhang, B., Li, S., Peng, H., and Ding, Z. (2025). Intelligent test case generation method for fuzzing iot protocols based on LLM. Automated Software Engineering. DOI: 10.1007/s10515-025-00557-x.
Publicado
19/10/2026
DIOGO, Jean D’Elboux; MOURA, Nilton; PRADO, Thatyanne; BORDA, Diego Cardoso; WERNER, Cláudia. Spec-Driven Multi-Agent Corpus Generation for Over-the-Air Wi-Fi Fuzzing. In: WORKSHOP-ESCOLA DE SISTEMAS DE AGENTES, SEUS AMBIENTES E APLICAÇÕES (WESAAC), 20. , 2026, Cuiabá/MT. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 412-419. ISSN 2326-5434. DOI: https://doi.org/10.5753/wesaac.2026.32123.