Please use this identifier to cite or link to this item:
https://elib.vku.udn.vn/handle/123456789/7751| Title: | An Effective SLM-Assisted Model for Fuzz Penetration Testing of Web Application |
| Authors: | Le, Thi Khanh Dung Nguyen, Bao Tich Tran, The Son |
| Keywords: | Fuzz Penetration Test Large Language Model Small Language Model nanoGPT Web Application Security |
| Issue Date: | Jul-2026 |
| Publisher: | IEEE |
| Abstract: | This paper proposes the application of the small language model to improve the effectiveness of fuzz penetration test (so-called pentest) techniques for web application. Fuzz pentest is known as an effective technique for detecting vulnerabilities of web applications, software, and network protocols by testing the target system with unusual input sequences (a.k.a payloads) which is usually generated by random functions or algorithms. However, it could cause existing fuzz pentesting models (such as Wfuzz) to have a lack of context-awareness and, thus reducing the effectiveness of pentest. Recently, large language models (LLMs) are exploited to do this kind of pentest thanks to their strong capability in generating fuzz pentest payloads based on big data and generative artificial intelligence (GenAI). However, this approach faces a challenge from input-censored mechanism of LLMs in order to block those who have malicious intent (also considered as illegal actions). This paper introduces the nanoGPTFuzz, a small language model (SLM) with 0.83 million parameters which is much smaller than that of a LLM (e.g. GPT-OSS-120B with 120 billion of parameters). The proposed model is trained by a dataset with 5,347 high-quality security payloads covering top 10 common vulnerabilities published by the Open Worldwide Application Security Project (OWASP) which is an online community that published open-source information and resources on web application security. Experimental results show that the proposed nanoGPTFuzz is able to generate fuzz payloads with an average success rate of 82.50% for pentesting, which are significantly higher than the 49.90% success rate achieved by the GPT-OSS-120B. The payloads generated by the proposed model recognized as diversity, thus providing a wide coverage of vulnerabilities compared to traditional Wfuzz-based pentesting approaches. |
| Description: | 2026 11th International Conference on Applying New Technology in Green Buildings (ATiGB); pp: 1877-1881 |
| URI: | 10.1109/ATiGB70203.2026.11628095 https://elib.vku.udn.vn/handle/123456789/7751 |
| ISBN: | 979-8-3315-4678-6 (p) 979-8-3315-4677-9 (e) |
| Appears in Collections: | NĂM 2026 |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.