Authors: Nelum Attanayake, Danushka Liyanage, Hoang Nguyen, Suranga Seneviratne, Clement Canonne, Rahul Gopinath
Venue: IEEE ISSRE 2026
The effectiveness of a fuzzing campaign is commonly assessed using program coverage. However, the total reachable coverage of complex real-world programs is unknown, making it difficult to determine when a campaign has sufficiently explored its target. Existing non-parametric estimators can be inaccurate and unstable, often overestimating reachable coverage.
Parametric estimators offer a potential alternative by modelling the distribution of coverage discovery. We evaluate Poisson, Exponential, Gamma, Gamma–Poisson, Negative Binomial, and Zipf–Mandelbrot distributions using seven benchmark programs.
Although the Zipf–Mandelbrot distribution provides the best statistical fit—achieving the lowest AIC and BIC and the highest log-likelihood—its resulting coverage estimates are no more accurate than those produced by non-parametric estimators.
This negative result demonstrates that a better model of coverage discovery does not necessarily yield a better estimate of reachable coverage. Improving coverage estimation therefore remains an open challenge for fuzz testing.