Rigor & Verification✓ Validated2026

ASAN Fuzzing Pipeline for Node.js Native Code

Automated coverage-guided fuzzing pipeline for native bindings

Overview

I engineered a reproducible fuzzing pipeline to systematically stress native addon interfaces. The workflow utilized AddressSanitizer (ASAN) to monitor execution and track coverage metrics. I designed specialized harnesses that generated targeted inputs to explore complex state transitions. The system automated the triage process by isolating unique execution paths and generating reproducible test cases. This approach established a robust framework for continuous validation, ensuring that the method could reliably surface edge cases without manual intervention. The resulting infrastructure provided a scalable template for integrating dynamic analysis into the development lifecycle.

AddressSanitizerlibFuzzerNode.js N-APIC++PythonLLVM

Highlights

  1. 01

    Coverage-guided fuzzing harnesses for native interfaces

  2. 02

    Automated triage workflow with reproducible test cases

  3. 03

    Continuous validation pipeline for dynamic analysis

System Architecture

Yes

No

Seed Corpus

Structure-Aware Mutator

ASAN-Instrumented Target

Crash Detected

Minimizer and Reporter

Coverage Feedback

Root-Cause Analysis

Coverage-guided fuzzing loop with ASAN crash detection and automated minimization

Questions people ask

How did you ensure the reliability of native Node.js bindings?
I built a coverage-guided fuzzing pipeline with AddressSanitizer to systematically stress interfaces and detect memory errors.
What tools did you use for dynamic analysis?
I utilized libFuzzer, LLVM, and AddressSanitizer to monitor execution and track coverage metrics during testing.
Did the pipeline automate the bug reporting process?
Yes, it automated triage by isolating unique execution paths and generating reproducible test cases for edge cases.

Sovereign Terminal

Sovereign Ecosystem

Sovereign research hub for industrial-academic inquiry into autonomous AI governance and swarm frameworks.

Sovereign Sync

Active Link

"Broadcasting from the Sovereign Systems Lab."

© 2026 Abhishek Khaparde • Sovereign AI Ecosystems

Non-Commercial Research
These projects represent my independent, non-commercial academic research at IIT Kanpur. These are distinct from my professional employment. All technical architectures discussed are academic design frameworks and do not represent the proprietary intellectual property, commercial methodologies, or official positions of my employer or any past professional affiliations.