Please use this identifier to cite or link to this item: https://elib.vku.udn.vn/handle/123456789/7751
Title: An Effective SLM-Assisted Model for Fuzz Penetration Testing of Web Application
Authors: Le, Thi Khanh Dung
Nguyen, Bao Tich
Tran, The Son
Keywords: Fuzz Penetration Test
Large Language Model
Small Language Model
nanoGPT
Web Application Security
Issue Date: Jul-2026
Publisher: IEEE
Abstract: This paper proposes the application of the small language model to improve the effectiveness of fuzz penetration test (so-called pentest) techniques for web application. Fuzz pentest is known as an effective technique for detecting vulnerabilities of web applications, software, and network protocols by testing the target system with unusual input sequences (a.k.a payloads) which is usually generated by random functions or algorithms. However, it could cause existing fuzz pentesting models (such as Wfuzz) to have a lack of context-awareness and, thus reducing the effectiveness of pentest. Recently, large language models (LLMs) are exploited to do this kind of pentest thanks to their strong capability in generating fuzz pentest payloads based on big data and generative artificial intelligence (GenAI). However, this approach faces a challenge from input-censored mechanism of LLMs in order to block those who have malicious intent (also considered as illegal actions). This paper introduces the nanoGPTFuzz, a small language model (SLM) with 0.83 million parameters which is much smaller than that of a LLM (e.g. GPT-OSS-120B with 120 billion of parameters). The proposed model is trained by a dataset with 5,347 high-quality security payloads covering top 10 common vulnerabilities published by the Open Worldwide Application Security Project (OWASP) which is an online community that published open-source information and resources on web application security. Experimental results show that the proposed nanoGPTFuzz is able to generate fuzz payloads with an average success rate of 82.50% for pentesting, which are significantly higher than the 49.90% success rate achieved by the GPT-OSS-120B. The payloads generated by the proposed model recognized as diversity, thus providing a wide coverage of vulnerabilities compared to traditional Wfuzz-based pentesting approaches.
Description: 2026 11th International Conference on Applying New Technology in Green Buildings (ATiGB); pp: 1877-1881
URI: 10.1109/ATiGB70203.2026.11628095
https://elib.vku.udn.vn/handle/123456789/7751
ISBN: 979-8-3315-4678-6 (p)
979-8-3315-4677-9 (e)
Appears in Collections:NĂM 2026

Files in This Item:

 Sign in to read



Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.