Fuzzing REST APIs in Industry: Necessary Features and Open Problems
Imagine you have a super cool toy car, like a Volkswagen! 🚗
Sometimes, the car needs to talk to other cars or a big computer brain. It uses special secret messages called "APIs" to do this.
Grown-ups want to make sure these secret messages always work perfectly, so the car doesn't get confused! They used to check every message by hand, which took a super long time, like forever! 😴
Now, there's a clever robot helper named "EvoMaster." 🤖 EvoMaster is like a playful puppy that tries all sorts of silly messages to see if it can make the car's computer giggle or find a tiny boo-boo.
This paper says that EvoMaster is helping Volkswagen cars talk better. It's like teaching the puppy new tricks to make sure all the cars are super happy and safe! Yay! 🎉
arXiv:2604.01759v1 Announce Type: new Abstract: REST APIs are widely used in industry, in all different kinds of domains. An example is Volkswagen AG, a German automobile manufacturer. Established testing approaches for REST APIs are time consuming, and require expertise from professional test engineers. Due to its cost and importance, in the scientific literature several approaches have been proposed to automatically test REST APIs. The open-source, search-based fuzzer EvoMaster is one of such tools proposed in the academic literature. However, how academic prototypes can be integrated in industry and have real impact to software engineering practice requires more investigation. In this paper, we report on our experience in using EvoMaster at Volkswagen AG, as an EvoMaster user from 2023
View PDF HTML (experimental)
Abstract:REST APIs are widely used in industry, in all different kinds of domains. An example is Volkswagen AG, a German automobile manufacturer. Established testing approaches for REST APIs are time consuming, and require expertise from professional test engineers. Due to its cost and importance, in the scientific literature several approaches have been proposed to automatically test REST APIs. The open-source, search-based fuzzer EvoMaster is one of such tools proposed in the academic literature. However, how academic prototypes can be integrated in industry and have real impact to software engineering practice requires more investigation. In this paper, we report on our experience in using EvoMaster at Volkswagen AG, as an EvoMaster user from 2023 to 2026. We share our learnt lessons, and discuss several features needed to be implemented in EvoMaster to make its use in an industrial context successful. Feedback about value in industrial setups of EvoMaster was given from Volkswagen AG about 4 APIs. Additionally, a user study was conducted involving 11 testing specialists from 4 different companies. We further identify several real-world research challenges that still need to be solved.
Comments: Extension from conference paper published at ICST'25
Subjects:
Software Engineering (cs.SE)
Cite as: arXiv:2604.01759 [cs.SE]
(or arXiv:2604.01759v1 [cs.SE] for this version)
https://doi.org/10.48550/arXiv.2604.01759
arXiv-issued DOI via DataCite (pending registration)
Submission history
From: Andrea Arcuri [view email] [v1] Thu, 2 Apr 2026 08:27:21 UTC (110 KB)
Sign in to highlight and annotate this article

Conversation starters
Daily AI Digest
Get the top 5 AI stories delivered to your inbox every morning.
More about
announceopen-sourcefeature
AI slop got better, so now maintainers have more work
Once AI bug reports become plausible, someone still has to verify them If AI does more of the work but humans still have to check it, you need more reviewers. Now that AI models have gotten better at writing and evaluating code, open-source projects find themselves overwhelmed with the too-good-to-ignore output.…

Anthropic closes door on subscription use of OpenClaw
The company is having trouble meeting user demand OpenClaw is popular, but not with the people responsible for keeping Anthropic’s services online. The company has disallowed subscription-based pricing for users who use the open-source agentic tool with Claude to try to keep things moving.…
Knowledge Map
Connected Articles — Knowledge Graph
This article is connected to other articles through shared AI topics and tags.
More in Research Papers
VLMs Need Words: Vision Language Models Ignore Visual Detail In Favor of Semantic Anchors
Vision Language Models struggle with fine-grained visual perception tasks due to their language-centric training approach, performing poorly on unnamed visual entities despite having relevant information in their representations. (1 upvotes on HuggingFace)





Discussion
Sign in to join the discussion
No comments yet — be the first to share your thoughts!