USENIX Security2026Top-tier venue
Fuzzing Open-Source GPU Hardware with SIMT Program Generation
Zibo Gao, Jie Wang, Qihang Zhou, Lixiao Shan, Junjie Hu, Xiaoqi Jia, Zhiqiang Lv
Abstract
GPUs have become critical components in computing systems. In the post-Moore's Law era, the demand for performance is driving increasing GPU microarchitectural complexity, which in turn gives rise to new vulnerabilities.
In this paper, we present the first framework for fuzzing GPU hardware designs at the Register Transfer Level (RTL) to automatically discover vulnerabilities. At the core of Fuz-zGPU is a novel generator that randomly constructs valid SIMT test programs with complex data and control flow, explicitly exercising the GPU execution model and thereby triggering diverse hardware behaviors. This bridges a key gap: prior processor fuzzers predominantly target CPUs and largely ignore GPU hardware. FuzzGPU further implements a GPU-specific differential testing harness. It tackles microarchitectural non-determinism (e.g., caches and memory timing) and enables trace-driven differential testing against an ISAlevel oracle. This technique unlocks vulnerability detection and localization with instruction-level precision. We evaluated FuzzGPU on two real-world open-source GPUs, Vortex and Ventus OpenGPGPU, uncovering 20 previously unknown bugs, including 17 RTL bugs and 3 ISS bugs, 10 of which were assigned CVE identifiers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0a530bd3-2554-4cff-954e-78367537bac0Builds on31
- A2: Analog Malicious HardwareKaiyuan Yang, Matthew Hicks, Qing Dong, Todd M. Austin et al.S&P 2016 · 242 citations
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek et al.S&P 2021 · 126 citations
- Towards Developing High Performance RISC-V Processors Using Agile MethodologyYinan Xu, Zihao Yu, Dan Tang, Guokai Chen et al.MICRO 2022 · 108 citations
- Vortex: Extending the RISC-V ISA for GPGPU and 3D-GraphicsBlaise Tine, Krishna Praveen Yalamarthy, Fares Elsabbagh, Hyesoon KimMICRO 2021 · 61 citations
- DirectFuzz: Automated Test Generation for RTL Designs using Directed Graybox FuzzingSadullah Canakci, Leila Delshadtehrani, Furkan Eris, Michael Bedford Taylor et al.DAC 2021 · 53 citations
Related papers
- GenFuzz: GPU-accelerated Hardware Fuzzing using Genetic Algorithm with Multiple InputsDian-Lun Lin, Yanqing Zhang, Haoxing Ren, Brucek Khailany et al.DAC 2023 · 40 citations
- TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable VulnerabilitiesRahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig et al.USENIX Security 2022
- sCROOGe: Circuit-level Design and Optimization Framework for RISC-V Out-of-Order GPUsMaria Zerva, Panagiotis-Eleftherios Eleftherakis, Alexis Maras, Konstantinos Iliakis et al.ISCA 2026
- Hunting CUDA Bugs at Scale with cuFuzzMohamed Tarek Ibn Ziad, Christos KozyrakisOOPSLA 2026
- DRVFuzz: Data-Sensitive RISC-V CPU FuzzingZehong Yu, Yuanliang Chen, Zhen Yan, Xudong Zhang et al.USENIX Security 2026
