Fuzzing Graph Database Applications with Graph Transformations

Conference Paper (2025)
Author(s)

Stefania Dumbrava (ENSIIE)

Melchior W. M. Oudemans (Student TU Delft)

Burcu Kulahcioglu Ozkan (TU Delft - Software Engineering)

Research Group
Software Engineering
DOI related publication
https://doi.org/10.1007/978-3-031-94706-3_7
More Info
expand_more
Publication Year
2025
Language
English
Research Group
Software Engineering
Pages (from-to)
135-156
ISBN (print)
9783031947056
ISBN (electronic)
978-3-031-94706-3
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Graph databases have surged in popularity, and applications increasingly employ them to store and retrieve interconnected data. However, testing graph database-backed applications has distinctive challenges. Due to the sheer dimension of the graph schema state space, testing applications using naive random graph instances is unlikely to cover a large portion of an application program. We present PGFuzz, a graph transformation-based greybox fuzzer for testing graph database-backed applications, that is, to the best of our knowledge, the first fuzzer to specifically target graph database applications. PGFuzz builds on top of state-of-the-art graph generators and utilizes graph transformations guided by code coverage to produce application test inputs. PGFuzz ’s graph transformations are schema-aware and support recently introduced graph schema, key, and cardinality constraints. We evaluate PGFuzz on graph database applications that we curate from open-source repositories and show that PGFuzz substantially improves the test coverage of graph database-backed applications compared to the state-of-the-art.

Files

978-3-031-94706-3_7.pdf
(pdf | 1.45 Mb)
- Embargo expired in 15-12-2025
License info not available