USENIX Security2026Top-tier venue
DRVFuzz: Data-Sensitive RISC-V CPU Fuzzing
Zehong Yu, Yuanliang Chen, Zhen Yan, Xudong Zhang, Zhensheng Xian, Yu Jiang
Abstract
The rapid adoption of RISC-V across modern computing systems has made the security integrity of its implementations a paramount concern. Logic bugs in RISC-V cores can lead to critical failures, such as faulty privilege transitions and architectural state corruption. While hardware fuzzing has emerged as a powerful technique for automated bug discovery, existing frameworks remain largely data-agnostic. By prioritizing instruction sequence diversity while treating operands as incidental random values, these tools often fail to trigger guarded microarchitectural states that manifest only under precise, data-dependent conditions. In this work, we present DRVFuzz, a data-sensitive fuzzing framework designed to expose hardware vulnerabilities by explicitly modeling and navigating the data-sensitive semantics. First, DRVFuzz introduces a sensitive data model (SDModel) that hierarchically codifies ISA semantics to synthesize tailored operands, including boundary values and exception triggers. Second, to effectively exploring data-dependent paths, DRVFuzz employs transition-guided fuzzing, prioritizing testcases that trigger previously unseen state transitions as labeled by the SDModel. We evaluated DRVFuzz on six real-world RISC-V CPUs with varying microarchitectural complexity, uncovering 22 previously unknown bugs (19 new CVEs).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 65055c77-791d-467e-844d-aa241407dd0aBuilds on18
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss et al.CCS 2019 · 289 citations
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek et al.S&P 2021 · 126 citations
- Data Oblivious ISA Extensions for Side Channel-Resistant and High Performance ComputingJiyong Yu, Lucas Hsiung, Mohamad El Hajj, Christopher W. FletcherNDSS 2019 · 106 citations
- Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution AttacksHany Ragab, Enrico Barberis, Herbert Bos, Cristiano GiuffridaUSENIX Security 2021 · 76 citations
- DirectFuzz: Automated Test Generation for RTL Designs using Directed Graybox FuzzingSadullah Canakci, Leila Delshadtehrani, Furkan Eris, Michael Bedford Taylor et al.DAC 2021 · 53 citations
Related papers
- GenHuzz: An Efficient Generative Hardware FuzzerLichao Wu, Mohamadreza Rostami, Huimin Li, Jeyavijayan Rajendran et al.USENIX Security 2025
- MorFuzz: Fuzzing Processor via Runtime Instruction Morphing enhanced Synchronizable Co-simulationJinyan Xu, Yiyuan Liu, Sirui He, Haoran Lin et al.USENIX Security 2023
- DevFuzz: Automatic Device Model-Guided Device Driver FuzzingYilun Wu, Tong Zhang, Changhee Jung, Dongyoon LeeS&P 2023
- GoldenFuzz: Generative Golden Reference Hardware FuzzingLichao Wu, Mohamadreza Rostami, Huimin Li, Nikhilesh Singh et al.NDSS 2026 · 3 citations
- RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUsFabian Thomas, Eric García Arribas, Lorenz Hetterich, Daniel Weber et al.CCS 2025
