Lune

USENIX Security2026Top-tier venue

Fuzzing Open-Source GPU Hardware with SIMT Program Generation

Zibo Gao, Jie Wang, Qihang Zhou, Lixiao Shan, Junjie Hu, Xiaoqi Jia, Zhiqiang Lv

2026Year

Abstract

GPUs have become critical components in computing systems. In the post-Moore's Law era, the demand for performance is driving increasing GPU microarchitectural complexity, which in turn gives rise to new vulnerabilities.

In this paper, we present the first framework for fuzzing GPU hardware designs at the Register Transfer Level (RTL) to automatically discover vulnerabilities. At the core of Fuz-zGPU is a novel generator that randomly constructs valid SIMT test programs with complex data and control flow, explicitly exercising the GPU execution model and thereby triggering diverse hardware behaviors. This bridges a key gap: prior processor fuzzers predominantly target CPUs and largely ignore GPU hardware. FuzzGPU further implements a GPU-specific differential testing harness. It tackles microarchitectural non-determinism (e.g., caches and memory timing) and enables trace-driven differential testing against an ISAlevel oracle. This technique unlocks vulnerability detection and localization with instruction-level precision. We evaluated FuzzGPU on two real-world open-source GPUs, Vortex and Ventus OpenGPGPU, uncovering 20 previously unknown bugs, including 17 RTL bugs and 3 ISS bugs, 10 of which were assigned CVE identifiers.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 0a530bd3-2554-4cff-954e-78367537bac0

Builds on31

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines