<?xml version='1.0' encoding='utf-8'?>
<?xml-stylesheet type="text/xsl" href="/v2/static/oai2.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-10-06T10:26:08Z</responseDate>
  <request identifier="oai:figshare.com:article/33457453" metadataPrefix="oai_dc" verb="GetRecord">https://api.figshare.com/v2/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:figshare.com:article/33457453</identifier>
        <datestamp>2026-09-20T06:48:57Z</datestamp>
        <setSpec>category_29200</setSpec>
        <setSpec>item_type_3</setSpec>
        <setSpec>month_year_09_2026</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"  xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>CLADFuzz</dc:title>
          <dc:creator>anymous anymous (24918261)</dc:creator>
          <dc:subject>Software testing, verification and validation</dc:subject>
          <dc:subject>software security</dc:subject>
          <dc:subject>Fuzzing Testing</dc:subject>
          <dc:description>&lt;p dir="ltr"&gt;&lt;b&gt;Description&lt;/b&gt;&lt;/p&gt;&lt;p dir="ltr"&gt;This deposit contains the complete implementation and test corpus of CLADFuzz, a constraint-guided fuzzing framework for OOXML office documents, corresponding to the research paper on constraint-aware dependency-guided OOXML fuzzing.&lt;/p&gt;&lt;p dir="ltr"&gt;&lt;b&gt;Background&lt;/b&gt;&lt;/p&gt;&lt;p dir="ltr"&gt;Office documents are OOXML ZIP packages whose interdependent parts determine whether an application opens, repairs, or rejects them. Fuzzing must balance early rejection of malformed packages against validity-preserving mutations that miss inconsistent-but-parseable states. CLADFuzz com bines a Reference Constraint Graph, dependency-aware rewrit ing, and a seed-captured PackageContract. Before repacking, HardValidity gates mutated package states; TargetViolation isolates one requested new soft violation whenever a target identifier is recorded. A probabilistic destructive path also permits malformed candidates. Across 3,000 native-extension DOCX/XLSX/PPTX samples, HardValidity predicts Office ad mission with 96.3% precision and 99.8% recall. Sole-new violation realization is 99.8% for DOCX, 98.9% for XLSX, and 100% for PPTX under the modeled evaluator. Across ten independent runs compared over the first 20 hours, CLAD Fuzz’s median post-initial occupied edge-map-slot gain is 3.6× 17.6× that of AFL++/Nyx or OpenXMolar/Nyx (Holm-adjusted p &lt;0.001). A one-year Microsoft 365 Apps campaign produced ten vendor-confirmed, patched CVEs.&lt;/p&gt;&lt;p dir="ltr"&gt;&lt;b&gt;CLADFuzz Design&lt;/b&gt;&lt;/p&gt;&lt;p dir="ltr"&gt;CLADFuzz models OOXML packages as &lt;b&gt;Reference Constraint Graphs&lt;/b&gt; and combines dependency-aware rewriting with a seed-captured &lt;i&gt;PackageContract&lt;/i&gt; to maintain structural validity while enabling precise consistency mutations.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;HardValidity&lt;/b&gt;: A structure-aware gating mechanism that filters out structurally invalid inputs before they are sent to the target application&lt;/li&gt;&lt;li&gt;&lt;b&gt;TargetViolation&lt;/b&gt;: A control predicate for targeted consistency mutation, which isolates exactly one requested soft-constraint violation per generated input&lt;/li&gt;&lt;li&gt;A bounded destructive channel to retain malformed inputs for broader exploration of parser boundary behavio&lt;/li&gt;&lt;/ul&gt;&lt;p dir="ltr"&gt;&lt;b&gt;Contents of This Deposit&lt;/b&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Full source code of the CLADFuzz fuzzing framework&lt;/li&gt;&lt;li&gt;A curated benchmark corpus of 300 native-extension DOCX, XLSX, and PPTX seed samples&lt;/li&gt;&lt;li&gt;Experiment configuration files and run scripts for comparative testing with AFL++/Nyx and OpenXMolar/Nyx&lt;/li&gt;&lt;li&gt;Proof-of-concept samples for the 10 vendor-confirmed CVEs (all vulnerabilities have been patched by Microsoft)&lt;/li&gt;&lt;/ol&gt;&lt;p dir="ltr"&gt;&lt;b&gt;Citation&lt;/b&gt;&lt;/p&gt;&lt;p dir="ltr"&gt;Please cite the associated research paper when using this framework or dataset in your work.&lt;/p&gt;</dc:description>
          <dc:date>2026-09-20T06:48:57Z</dc:date>
          <dc:type>Dataset</dc:type>
          <dc:type>Dataset</dc:type>
          <dc:identifier>10.6084/m9.figshare.33457453.v6</dc:identifier>
          <dc:relation>https://figshare.com/articles/dataset/CLADFuzz/33457453</dc:relation>
          <dc:rights>MIT</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
