APIRL: Deep reinforcement learning for REST API fuzzing
File(s) apirl.pdf (410.49 KB)
Accepted version
Author(s)
Foley, Myles
Maffeis, Sergio
Type
Conference Paper
Abstract
REST APIs have become key components of web services. However, they often contain logic flaws resulting in server side errors or security vulnerabilities. HTTP requests are used as test cases to find and mitigate such issues. Existing methods to modify requests, including those using deep learning, suffer from limited performance and precision, relying on undirected search or making limited usage of the contextual information. In this paper we propose APIRL, a fully automated deep reinforcement learning tool for testing REST APIs. A key novelty of our approach is the use of feedback from a transformer module pre-trained on JSON-structured data, akin to that used in API responses. This allows APIRL to learn the subtleties relating to test outcomes, and generalise to unseen API endpoints. We show APIRL can find significantly more bugs than the state-of-the-art in real world REST APIs while minimising the number of required test cases. We also study how reward functions, and other key design choices, affect learnt policies with a thorough ablation study.
Date Issued
2025-04-11
Date Acceptance
2024-12-10
Citation
Proceedings of the ... AAAI Conference on Artificial Intelligence. AAAI Conference on Artificial Intelligence, 2025, Vol. 39 No. 1: AAAI-25 Technical Tracks 1, pp.191-199
ISSN
2159-5399
Publisher
Association for the Advancement of Artificial Intelligence
Start Page
191
End Page
199
Journal / Book Title
Proceedings of the ... AAAI Conference on Artificial Intelligence. AAAI Conference on Artificial Intelligence
Volume
Vol. 39 No. 1: AAAI-25 Technical Tracks 1
Copyright Statement
© 2025, Association for the Advancement of Artificial Intelligence.
Source
Conference on Artificial Intelligence
Publication Status
Published
Start Date
2025-02-25
Finish Date
2025-03-04
Coverage Spatial
Philadelphia, PA, USA
