Please use this identifier to cite or link to this item: https://elib.vku.udn.vn/handle/123456789/7751
Full metadata record
DC FieldValueLanguage
dc.contributor.authorLe, Thi Khanh Dung-
dc.contributor.authorNguyen, Bao Tich-
dc.contributor.authorTran, The Son-
dc.date.accessioned2026-09-11T07:29:44Z-
dc.date.available2026-09-11T07:29:44Z-
dc.date.issued2026-07-
dc.identifier.isbn979-8-3315-4678-6 (p)-
dc.identifier.isbn979-8-3315-4677-9 (e)-
dc.identifier.uri10.1109/ATiGB70203.2026.11628095-
dc.identifier.urihttps://elib.vku.udn.vn/handle/123456789/7751-
dc.description2026 11th International Conference on Applying New Technology in Green Buildings (ATiGB); pp: 1877-1881vi_VN
dc.description.abstractThis paper proposes the application of the small language model to improve the effectiveness of fuzz penetration test (so-called pentest) techniques for web application. Fuzz pentest is known as an effective technique for detecting vulnerabilities of web applications, software, and network protocols by testing the target system with unusual input sequences (a.k.a payloads) which is usually generated by random functions or algorithms. However, it could cause existing fuzz pentesting models (such as Wfuzz) to have a lack of context-awareness and, thus reducing the effectiveness of pentest. Recently, large language models (LLMs) are exploited to do this kind of pentest thanks to their strong capability in generating fuzz pentest payloads based on big data and generative artificial intelligence (GenAI). However, this approach faces a challenge from input-censored mechanism of LLMs in order to block those who have malicious intent (also considered as illegal actions). This paper introduces the nanoGPTFuzz, a small language model (SLM) with 0.83 million parameters which is much smaller than that of a LLM (e.g. GPT-OSS-120B with 120 billion of parameters). The proposed model is trained by a dataset with 5,347 high-quality security payloads covering top 10 common vulnerabilities published by the Open Worldwide Application Security Project (OWASP) which is an online community that published open-source information and resources on web application security. Experimental results show that the proposed nanoGPTFuzz is able to generate fuzz payloads with an average success rate of 82.50% for pentesting, which are significantly higher than the 49.90% success rate achieved by the GPT-OSS-120B. The payloads generated by the proposed model recognized as diversity, thus providing a wide coverage of vulnerabilities compared to traditional Wfuzz-based pentesting approaches.vi_VN
dc.language.isoenvi_VN
dc.publisherIEEEvi_VN
dc.subjectFuzz Penetration Testvi_VN
dc.subjectLarge Language Modelvi_VN
dc.subjectSmall Language Modelvi_VN
dc.subjectnanoGPTvi_VN
dc.subjectWeb Application Securityvi_VN
dc.titleAn Effective SLM-Assisted Model for Fuzz Penetration Testing of Web Applicationvi_VN
dc.typeWorking Papervi_VN
Appears in Collections:NĂM 2026

Files in This Item:

 Sign in to read



Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.