5uGUE Research-Question Dashboard

An exposition of the research questions behind 5uGUE

5uGUE is an LLM-driven agent that autonomously fuzzes closed-source wireless targets (5G baseband firmware and Bluetooth Classic stacks) to discover crashes. This site lets interested readers inspect the evidence behind each research question, down to every individual experimental run.

Research Questionone scientific question (one axis of experimentation)
Experimentone configuration variance
Runs5 repeated fuzzing sessions; reported numbers are the mean

We study five experimental axes, each addressing a key research question:

  • (VII-A) Capability Ablation: Evaluates progressive agent capabilities (V1 base agent, V2 +GitHub-aware fetch, V3 +batched execution).
  • (VII-B) Device Generalisation: Evaluates 5uGUE across five targets spanning two chipset vendors (MediaTek and UNISOC).
  • (VII-C) Protocol Adaptability: Demonstrates extension beyond 5G to Bluetooth Classic on the ESP32 target.
  • (VII-D) Knowledge-Restricted Seeding: Evaluates bootstrapping exploration without target-specific seed packets (V3-filtered).
  • (VII-E) LLM Comparison: Benchmarks performance across six underlying frontier LLMs.

Note on crash counts

In some cases the crash string cannot be recovered. The crash is still detected, but without its string it cannot be classified or counted, so the category breakdown can sum to less than the total. These cases are flagged inline as unclassified crash. They occur in the following tests: