Skip to content
Preprint

Dynamic Conformance Testing of WebGPU Through Specification-Driven Mutation

Sep 2026 · 0 citations · 41 references
Computer Science

TL;DR

LANTERN, a specification-guided dynamic conformance testing framework that mutates CTS tests using constraints extracted from the WebGPU specification, is introduced, demonstrating that syntactically seeded, semantics-aware mutation of conformance tests provides a way to uncover browser bugs during WebGPU testing.

Abstract

WebGPU is a low-level graphics and compute API that exposes modern GPU functionality to web applications. While the official WebGPU Conformance Test Suite (CTS) focuses on well-formed usage under the WebGPU specification, it is not designed to stress implementations with semantic edge cases or adversarial inputs. General-purpose fuzzers, in contrast, struggle with WebGPU because of its complex graphics stack and multi-process architecture. We introduce LANTERN, a specification-guided dynamic conformance testing framework that mutates CTS tests using constraints extracted from the WebGPU specification. LANTERN extracts explicit syntactic API rules from WebIDL definitions and recovers semantic constraints, such as command ordering and object lifetimes, from natural-language specification text. Selected rules guide AST-located textual transformations that generate both valid and intentionally invalid CTS variants. We execute the resulting tests at scale on AddressSanitizer-instrumented Chromium to discover bugs. Our evaluation discovers three reproducible bugs, including a heap corruption, in Chromium versions current at the time of study. These results demonstrate that syntactically seeded, semantics-aware mutation of conformance tests provides a way to uncover browser bugs during WebGPU testing.

View source

Similar papers

Book Open access Oct 2026

WGSLsmith: Randomised Testing for the WebGPU Shading Language

We present WGSLsmith, a tool for randomised testing of compilers for the WebGPU Shading Language (WGSL). Under the WebGPU API---now supported by all three major browsers---GPU programs are written in the WebGPU Shading Language (WGSL), and every implementation ships a WGSL compiler that validates shaders and translates...

Michał Andryskowski, Amber Gorzynski, Hasan Mohsin et al. · 0 citations
Preprint Sep 2026

TraceLib: System-Call Bitmap Feedback Mechanism for Language-Agnostic Web Fuzzing

Coverage feedback is an important source of guidance for fuzzing. However, obtaining such feedback normally requires application-level instrumentation that is specific to the language and runtime of the application. Given that modern web applications span multiple languages and runtimes, this application-level instrume...

I. P. A. Dharmaadi, Elias Athanasopoulos, Fatih Turkmen · 0 citations
Book Open access Sep 2026

State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation

The security of the modern web depends on the correctness of JavaScript (JS) engines, yet these complex systems remain vulnerable to high-impact bugs. A critical limitation of state-of-the-art fuzzers is the coverage plateau: once a fuzzer saturates the control-flow graph, edge coverage loses its ability to guide disco...

Wai-Kin Wong, Dong-Wei Xiao, Anthony Cheuk Tung Lai et al. · 0 citations
Open access 2026

A Systematic LLM-Based Procedure for the Deobfuscation of WebAssembly: Benchmark and Security Evaluation

This paper investigates the capability of large language models (LLMs) to perform automated Wasm deobfuscation and introduces a three-tier evaluation hierarchy for assessing deobfuscation quality, consisting of syntax correctness, execution validity, and semantic similarity.

Sebeom Cheon, Jin-Ho Jung, Sangkyun Lee · 0 citations
Review Open access 2026

Security Analysis of LLM-Generated Web API Backends

A security assessment on 75 FastAPI backends generated by three contemporary LLMs revealed a disconnect between functional correctness and secure logic, which is interpreted as a review-risk pattern, which is called the human-in-the-loop paradox.

Abdul Ali Khan, S. Rauti, T. Mäkilä · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.