RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs
Fabian Thomas, Eric García Arribas, Lorenz Hetterich, Daniel Weber, Lukas Gerlach, Ruiyi Zhang, Michael Schwarz
2025Year
3Top-tier citations
Abstract
The open and extensible RISC-V instruction set has enabled many new CPU vendors and implementations, but most commercial CPUs are closed-source, significantly hindering vulnerability analysis—especially for bugs exploitable from unprivileged user space.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 69f56b57-03db-46f7-b468-79c6ca0ac1d3Cited by top-tier papers3
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 1 citation
- Fuzzing Open-Source GPU Hardware with SIMT Program GenerationZibo Gao, Jie Wang, Qihang Zhou, Lixiao Shan et al.USENIX Security 2026
- ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUsFabian Thomas, Michael Torres, Daniel Moghimi, Michael SchwarzCCS 2025
Builds on28
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
Related papers
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek et al.S&P 2021 · 126 citations
- DRVFuzz: Data-Sensitive RISC-V CPU FuzzingZehong Yu, Yuanliang Chen, Zhen Yan, Xudong Zhang et al.USENIX Security 2026
- A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUsLukas Gerlach, Daniel Weber, Ruiyi Zhang, Michael SchwarzS&P 2023
- WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in ProcessorsPallavi Borkar, Chen Chen, Mohamadreza Rostami, Nikhilesh Singh et al.USENIX Security 2024 · 31 citations
- DiveFuzz: Enhancing CPU Fuzzing via Diverse Instruction ConstructionZihui Guo, Miaomiao Yuan, Yanqi Yang, Liwei Chen et al.CCS 2025
