Live
Black Hat USAAI BusinessBlack Hat AsiaAI BusinessComparing Today's Multi-Model DatabasesDEV CommunityBuilding a WeChat Mini Program Pre-Sale System from Scratch: A Builder's LogDEV Community26 Quizzes: What We've Learned About Which Results People Actually ShareDEV CommunityLayered Agentic Retrieval for Retail Floor Questions: A Solo PoCDEV CommunityHow to Handle Sensitive Data Securely in TerraformDEV CommunitySecure Cross-Platform File Sharing: A Unified Solution for Diverse Devices and NetworksDEV CommunityHere's what 'cracking' bitcoin in 9 minutes by quantum computers actually meansCoinDesk AII Tested a Real AI Agent for Security. The LLM Knew It Was Dangerous — But the Tool Layer Executed Anyway.DEV CommunityI Got Tired of Surprise OpenAI Bills, So I Built a Dashboard to Track ThemDEV CommunitySynthetic Population Testing for Recommendation SystemsDEV CommunityI Analyzed 500 AI Coding Mistakes and Built an ESLint Plugin to Catch ThemDEV CommunityAnthropic is having a moment in the private markets; SpaceX could spoil the partyTechCrunchBlack Hat USAAI BusinessBlack Hat AsiaAI BusinessComparing Today's Multi-Model DatabasesDEV CommunityBuilding a WeChat Mini Program Pre-Sale System from Scratch: A Builder's LogDEV Community26 Quizzes: What We've Learned About Which Results People Actually ShareDEV CommunityLayered Agentic Retrieval for Retail Floor Questions: A Solo PoCDEV CommunityHow to Handle Sensitive Data Securely in TerraformDEV CommunitySecure Cross-Platform File Sharing: A Unified Solution for Diverse Devices and NetworksDEV CommunityHere's what 'cracking' bitcoin in 9 minutes by quantum computers actually meansCoinDesk AII Tested a Real AI Agent for Security. The LLM Knew It Was Dangerous — But the Tool Layer Executed Anyway.DEV CommunityI Got Tired of Surprise OpenAI Bills, So I Built a Dashboard to Track ThemDEV CommunitySynthetic Population Testing for Recommendation SystemsDEV CommunityI Analyzed 500 AI Coding Mistakes and Built an ESLint Plugin to Catch ThemDEV CommunityAnthropic is having a moment in the private markets; SpaceX could spoil the partyTechCrunch
AI NEWS HUBbyEIGENVECTOREigenvector

Fuzzing REST APIs in Industry: Necessary Features and Open Problems

arXiv cs.SEby [Submitted on 2 Apr 2026]April 3, 20262 min read1 views
Source Quiz

arXiv:2604.01759v1 Announce Type: new Abstract: REST APIs are widely used in industry, in all different kinds of domains. An example is Volkswagen AG, a German automobile manufacturer. Established testing approaches for REST APIs are time consuming, and require expertise from professional test engineers. Due to its cost and importance, in the scientific literature several approaches have been proposed to automatically test REST APIs. The open-source, search-based fuzzer EvoMaster is one of such tools proposed in the academic literature. However, how academic prototypes can be integrated in industry and have real impact to software engineering practice requires more investigation. In this paper, we report on our experience in using EvoMaster at Volkswagen AG, as an EvoMaster user from 2023

View PDF HTML (experimental)

Abstract:REST APIs are widely used in industry, in all different kinds of domains. An example is Volkswagen AG, a German automobile manufacturer. Established testing approaches for REST APIs are time consuming, and require expertise from professional test engineers. Due to its cost and importance, in the scientific literature several approaches have been proposed to automatically test REST APIs. The open-source, search-based fuzzer EvoMaster is one of such tools proposed in the academic literature. However, how academic prototypes can be integrated in industry and have real impact to software engineering practice requires more investigation. In this paper, we report on our experience in using EvoMaster at Volkswagen AG, as an EvoMaster user from 2023 to 2026. We share our learnt lessons, and discuss several features needed to be implemented in EvoMaster to make its use in an industrial context successful. Feedback about value in industrial setups of EvoMaster was given from Volkswagen AG about 4 APIs. Additionally, a user study was conducted involving 11 testing specialists from 4 different companies. We further identify several real-world research challenges that still need to be solved.

Comments: Extension from conference paper published at ICST'25

Subjects:

Software Engineering (cs.SE)

Cite as: arXiv:2604.01759 [cs.SE]

(or arXiv:2604.01759v1 [cs.SE] for this version)

https://doi.org/10.48550/arXiv.2604.01759

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Andrea Arcuri [view email] [v1] Thu, 2 Apr 2026 08:27:21 UTC (110 KB)

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by Eigenvector · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

More about

announceopen-sourcefeature

Knowledge Map

Knowledge Map
TopicsEntitiesSource
Fuzzing RES…announceopen-sourcefeaturereportstudypaperarXiv cs.SE

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 155 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!

More in Research Papers