USENIX Security2024Top-tier venue
Cascade: CPU Fuzzing via Intricate Program Generation
Flavien Solt, Katharina Ceesay-Seitz, Kaveh Razavi
Abstract
Generating interesting test cases for CPU fuzzing is akin to generating programs that exercise unusual states inside the CPU. The performance of CPU fuzzing is heavily influenced by the quality of these programs and by the overhead of bug detection. Our analysis of existing state-of-the-art CPU fuzzers shows that they generate programs that are either overly simple or execute a small fraction of their instructions due to invalid control flows. Combined with expensive instruction-granular bug detection mechanisms, this leads to inefficient fuzzing campaigns. We present Cascade, a new approach for generating valid RISC-V programs of arbitrary length with highly randomized and interdependent control and data flows. Cascade relies on a new technique called asymmetric ISA pre-simulation for entangling control flows with data flows when generating programs. This entanglement results in non-termination when a program triggers a bug in the target CPU, enabling Cascade to detect a CPU bug at program granularity without introducing any runtime overhead. Our evaluation shows that long Cascade programs are more effective in exercising the CPU's internal design. Cascade achieves 28.2x to 97x more coverage than the state-of-the-art CPU fuzzers and uncovers 37 new bugs (28 new CVEs) in 5 RISC-V CPUs with varying degrees of complexity. The programs that trigger these bugs are long and intricate, impeding triaging. To address this challenge, Cascade features an automated pruning method that reduces a program to a minimal number of instructions that trigger the bug.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 07ebb55c-d362-4c07-94ee-9a5def814efeCited by top-tier papers21
- WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in ProcessorsPallavi Borkar, Chen Chen, Mohamadreza Rostami, Nikhilesh Singh et al.USENIX Security 2024 · 31 citations
- DejaVuzz: Disclosing Transient Execution Bugs with Dynamic Swappable Memory and Differential Information Flow Tracking Assisted Processor FuzzingJinyan Xu, Yangye Zhou, Xingzhi Zhang, Yinshuai Li et al.ASPLOS 2025 · 4 citations
- ReFuzz: Reusing Tests for Processor Fuzzing with Contextual BanditsChen Chen, Zaiyan Xu, Mohamadreza Rostami, David Liu et al.NDSS 2026 · 4 citations
- AMuLeT: Automated Design-Time Testing of Secure Speculation CountermeasuresBo Fu, Leo Tenenbaum, David Adler, Assaf Klein et al.ASPLOS 2025 · 3 citations
- μCFI: Formal Verification of Microarchitectural Control-flow IntegrityKatharina Ceesay-Seitz, Flavien Solt, Kaveh RazaviCCS 2024 · 3 citations
Builds on14
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar et al.NDSS 2017 · 700 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek et al.S&P 2021 · 126 citations
- GRIMOIRE: Synthesizing Structure while FuzzingTim Blazytko, Cornelius Aschermann, Moritz Schlögel, Ali Abbasi et al.USENIX Security 2019 · 123 citations
- DirectFuzz: Automated Test Generation for RTL Designs using Directed Graybox FuzzingSadullah Canakci, Leila Delshadtehrani, Furkan Eris, Michael Bedford Taylor et al.DAC 2021 · 53 citations
Related papers
- DiveFuzz: Enhancing CPU Fuzzing via Diverse Instruction ConstructionZihui Guo, Miaomiao Yuan, Yanqi Yang, Liwei Chen et al.CCS 2025
- MorFuzz: Fuzzing Processor via Runtime Instruction Morphing enhanced Synchronizable Co-simulationJinyan Xu, Yiyuan Liu, Sirui He, Haoran Lin et al.USENIX Security 2023
- Encarsia: Evaluating CPU Fuzzers via Automatic Bug InjectionMatej Bölcskei, Flavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviUSENIX Security 2025
- HyperMirage: Direct State Manipulation in Hybrid Virtual CPU FuzzingManuel Andreas, Fabian Specht, Marius MomeuNDSS 2026
- kSTEP: Characterization and Deterministic Testing of Linux CPU Scheduler BugsTingjia Cao, Shawn (Wanxiang) Zhong, Caeden Whitaker, Ke Han et al.OSDI 2026 · 1 citation
