1. OWASP Foundation. (2020). OWASP Web Security Testing Guide (WSTG) v4.2. Section 4.7.4, "Fuzz Vector Generation and Injection (WSTG-INPV-04)". The guide defines fuzz testing as "a way of throwing a huge amount of random data at an application in an attempt to make it crash."
2. Manes, V. J., Han, H., Coviello, C., Cha, S. K., & Egele, M. (2018). The Art, Science, and Engineering of Fuzzing: A Survey. IEEE Transactions on Software Engineering, 46(2), 231-248. Section II-A, "Introduction to Fuzzing," states, "At its core, fuzzing (or fuzz testing) is a process of finding security vulnerabilities in a target program by repeatedly running the program with generated inputs..." (https://doi.org/10.1109/TSE.2018.2864553)
3. Sutton, M., Greene, A., & Amini, P. (2007). Fuzzing: Brute Force Vulnerability Discovery. Addison-Wesley Professional. Chapter 1, "What is Fuzzing?", page 1, defines fuzzing as "...the use of malformed or unexpected data as program input to find software vulnerabilities."
4. Carnegie Mellon University. (2012). 15-441: Computer Networks, Lecture 25: Network Security. Slide 23, "Fuzz Testing". The lecture slide defines fuzzing as "generating random/malformed packets and sending them to a target" to see if it crashes or behaves unexpectedly.