Live
Black Hat USAAI BusinessBlack Hat AsiaAI BusinessThe League of Legends KeSPA cup will air globally on Disney+EngadgetThe Gardenlesswrong.comGeneralist’s new physical robotics AI brings “production-level” success rates - Ars TechnicaGoogle News - AI roboticsAI slop got better, so now maintainers have more workThe Register AI/MLThe Silicon Protocol: The Model Hosting Decision — When Azure OpenAI Isn’t Enough (And When It’s…Towards AIIntel — Deep DiveDEV CommunitySecrets Management for Laravel: .env, Encrypted Config, and DeploynixDEV CommunitySemgrep vs Veracode: SAST Comparison for 2026DEV CommunityClaude's Source Code Got Leaked Across The Whole InternetMatt Wolfe (YouTube)OpenAI alums have been quietly investing from a new, potentially $100M fundTechCrunch VentureVibeNVR v1.25.3 – Open-source, self-hosted NVR for IP camerasDEV CommunityEmDash: A Full-Stack TypeScript CMS Built on Astro + Cloudflare — Can It Replace WordPress?DEV CommunityBlack Hat USAAI BusinessBlack Hat AsiaAI BusinessThe League of Legends KeSPA cup will air globally on Disney+EngadgetThe Gardenlesswrong.comGeneralist’s new physical robotics AI brings “production-level” success rates - Ars TechnicaGoogle News - AI roboticsAI slop got better, so now maintainers have more workThe Register AI/MLThe Silicon Protocol: The Model Hosting Decision — When Azure OpenAI Isn’t Enough (And When It’s…Towards AIIntel — Deep DiveDEV CommunitySecrets Management for Laravel: .env, Encrypted Config, and DeploynixDEV CommunitySemgrep vs Veracode: SAST Comparison for 2026DEV CommunityClaude's Source Code Got Leaked Across The Whole InternetMatt Wolfe (YouTube)OpenAI alums have been quietly investing from a new, potentially $100M fundTechCrunch VentureVibeNVR v1.25.3 – Open-source, self-hosted NVR for IP camerasDEV CommunityEmDash: A Full-Stack TypeScript CMS Built on Astro + Cloudflare — Can It Replace WordPress?DEV Community
AI NEWS HUBbyEIGENVECTOREigenvector

Fuzzing REST APIs in Industry: Necessary Features and Open Problems

arXiv cs.SEby [Submitted on 2 Apr 2026]April 3, 20262 min read2 views
Source Quiz
🧒Explain Like I'm 5Simple language

Imagine you have a super cool toy car, like a Volkswagen! 🚗

Sometimes, the car needs to talk to other cars or a big computer brain. It uses special secret messages called "APIs" to do this.

Grown-ups want to make sure these secret messages always work perfectly, so the car doesn't get confused! They used to check every message by hand, which took a super long time, like forever! 😴

Now, there's a clever robot helper named "EvoMaster." 🤖 EvoMaster is like a playful puppy that tries all sorts of silly messages to see if it can make the car's computer giggle or find a tiny boo-boo.

This paper says that EvoMaster is helping Volkswagen cars talk better. It's like teaching the puppy new tricks to make sure all the cars are super happy and safe! Yay! 🎉

arXiv:2604.01759v1 Announce Type: new Abstract: REST APIs are widely used in industry, in all different kinds of domains. An example is Volkswagen AG, a German automobile manufacturer. Established testing approaches for REST APIs are time consuming, and require expertise from professional test engineers. Due to its cost and importance, in the scientific literature several approaches have been proposed to automatically test REST APIs. The open-source, search-based fuzzer EvoMaster is one of such tools proposed in the academic literature. However, how academic prototypes can be integrated in industry and have real impact to software engineering practice requires more investigation. In this paper, we report on our experience in using EvoMaster at Volkswagen AG, as an EvoMaster user from 2023

View PDF HTML (experimental)

Abstract:REST APIs are widely used in industry, in all different kinds of domains. An example is Volkswagen AG, a German automobile manufacturer. Established testing approaches for REST APIs are time consuming, and require expertise from professional test engineers. Due to its cost and importance, in the scientific literature several approaches have been proposed to automatically test REST APIs. The open-source, search-based fuzzer EvoMaster is one of such tools proposed in the academic literature. However, how academic prototypes can be integrated in industry and have real impact to software engineering practice requires more investigation. In this paper, we report on our experience in using EvoMaster at Volkswagen AG, as an EvoMaster user from 2023 to 2026. We share our learnt lessons, and discuss several features needed to be implemented in EvoMaster to make its use in an industrial context successful. Feedback about value in industrial setups of EvoMaster was given from Volkswagen AG about 4 APIs. Additionally, a user study was conducted involving 11 testing specialists from 4 different companies. We further identify several real-world research challenges that still need to be solved.

Comments: Extension from conference paper published at ICST'25

Subjects:

Software Engineering (cs.SE)

Cite as: arXiv:2604.01759 [cs.SE]

(or arXiv:2604.01759v1 [cs.SE] for this version)

https://doi.org/10.48550/arXiv.2604.01759

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Andrea Arcuri [view email] [v1] Thu, 2 Apr 2026 08:27:21 UTC (110 KB)

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by Eigenvector · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

Knowledge Map

Knowledge Map
TopicsEntitiesSource
Fuzzing RES…announceopen-sourcefeaturereportstudypaperarXiv cs.SE

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 206 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!