SPLASH 2026
Sun 4 - Fri 9 October 2026 Oakland, California, United States
co-located with SPLASH/ISSTA 2026

This program is tentative and subject to change.

Tue 6 Oct 2026 11:42 - 12:00 at East Hall 1 - Fuzzing and Test Generation Chair(s): Michael Pradel

JavaScript obfuscators are widely deployed to protect intellectual property and resist reverse engineering, yet their correctness has been largely overlooked compared to performance and resilience. Existing evaluations typically measure resistance to deobfuscation, leaving the critical question of whether obfuscators preserve program semantics unanswered. Incorrect transformations can silently alter functionality, compromise reliability, and erode security—undermining the very purpose of obfuscation. To address this gap, we present OBsmith, a novel framework to systematically test JavaScript obfuscators using large language models (LLMs). OBsmith leverages LLMs to generate program sketches—abstract templates capturing diverse language constructs, idioms, and corner cases—which are instantiated into executable programs and subjected to obfuscation under different configurations. Besides LLM-powered sketching, OBsmith also employs a second source: automatic extraction of skeletons from real programs. This extraction path enables more focused testing of project-specific features and lets developers inject domain knowledge into the resulting test cases. OBsmith uses two techniques to derive test oracles: (i) reference-oriented equivalence testing, which takes the original
program as reference oracle (ground truth) and checks whether the obfuscated version preserves equivalent functionality, and (ii) metamorphic testing, which applies semantics-preserving transformations to the original program and checks if obfuscation violates expected behavior.

We evaluate OBsmith on two widely used obfuscators, Obfuscator.IO and JS-Confuser, generating 600
sketches using six popular LLMs. OBsmith fills these sketches and generates over 3,000 candidate programs and obfuscates them across seven obfuscation configurations. OBsmith uncovers 11 previously unknown correctness bugs. Under an equal program budget, five general purpose state-of-the-art JavaScript fuzzers (FuzzJIT, Jsfunfuzz, Superion, DIE, Fuzzilli) failed to detect these issues, highlighting OBsmith’s complementary focus on obfuscation-induced misbehavior. An ablation shows that all components except our generic MRs contribute to at least one bug class; the negative MR result suggests the need for obfuscator-specific metamorphic relations. Our results also seed a discussion on how to balance obfuscation presets and performance cost. We envision OBsmith as an important step towards automated testing and quality assurance of obfuscators and other semantic-preserving toolchains.

OBsmith_presentation_OOPSLA_2026 (OOPSLA 2026 OBsmith.pdf)581KiB

This program is tentative and subject to change.

Tue 6 Oct

Displayed time zone: Pacific Time (US & Canada) change

10:30 - 12:00
Fuzzing and Test GenerationOOPSLA at East Hall 1
Chair(s): Michael Pradel CISPA Helmholtz Center for Information Security
10:30
18m
Talk
Hunting CUDA Bugs at Scale with cuFuzz
OOPSLA
Mohamed Tarek Ibn Ziad NVIDIA, Christos Kozyrakis NVIDIA; Stanford University
Link to publication DOI Pre-print Media Attached
10:48
18m
Talk
RandSet: Randomized Corpus Reduction for Fuzzing Seed Scheduling
OOPSLA
Yuchong Xie Fudan University; Hong Kong University of Science and Technology, Kaikai Zhang Hong Kong University of Science and Technology, Yu Liu Fudan University, Rundong Yang Fudan University, Ping Chen Fudan University, Shuai Wang Hong Kong University of Science and Technology, Dongdong She Hong Kong University of Science and Technology
DOI
11:06
18m
Talk
Metamorphic Testing for Infrastructure-as-Code Engines
OOPSLA
David Spielmann University of St. Gallen, George Zakhour University of St. Gallen, Dominik Arnold University of Zurich, Matteo Biagiola USI Lugano; University of St. Gallen, Roland Meier armasuisse, Guido Salvaneschi University of St. Gallen
Link to publication DOI Pre-print
11:24
18m
Talk
Prunario: Testing Autonomous Driving Systems by Pruning Likely Redundant Scenarios
OOPSLA
Minsu Kim Korea University, Sunbeom So Korea University, Hakjoo Oh Korea University
DOI
11:42
18m
Talk
OBsmith: LLM-Powered JavaScript Obfuscator Testing
OOPSLA
Shan Jiang University of Texas at Austin, Chenguang Zhu University of Texas at Austin, Sarfraz Khurshid University of Texas at Austin
DOI File Attached
Hide past events