The same loop runs against a Bluetooth chip (ESP32). Only the test tool and the prompt change.
Fuzzing means sending a program deliberately malformed input and watching for crashes.
There were an estimated 2.9 billion 5G subscriptions at the end of 2025. Each phone has a modem: a separate chip, with closed-source firmware, that handles the radio link. The modem processes some messages from the base station before encryption is established, and continues processing messages after encryption is enabled. In this work, we mainly focus on the messages processed before encryption is established. To test it, we run our own base station, send the phone modified messages, and check its logs for crashes.
Experts write rules for mutating packets. The fuzzer applies them.
A language model handles one step, such as writing starting inputs. The rest of the loop is fixed.
The agent runs every step: research, writing the test, sending it, reading the logs, choosing the next test.
Step controlled by an LLM
5uGUE V3 with Claude Sonnet 4.6 against a OnePlus Nord CE 2 (MediaTek Dimensity 900). 60 turns, 95 tests, 104 minutes.
Each column is one turn. A filled column is a turn that ran tests. Each gold dot is one crash. Counts and timings are from run 059c9b96.
for the previous best fuzzer, 5Ghoul. Five phones, five runs each.
Total crashes, mean of five runs.
Results vary between runs and between models. The firmware is closed, so the logs show where a crash happened but not always why.
Evaluated on six models.
Total crashes on the OnePlus Nord CE 2, mean of five runs.