USENIX Security2023Top-tier venue
HyPFuzz: Formal-Assisted Processor Fuzzing
Chen Chen, Rahul Kande, Nathan Nguyen, Flemming Andersen, Aakash Tyagi, Ahmad-Reza Sadeghi, Jeyavijayan Rajendran
Abstract
Recent research has shown that hardware fuzzers can effectively detect security vulnerabilities in modern processors. However, existing hardware fuzzers do not fuzz well the hard-to-reach design spaces. Consequently, these fuzzers cannot effectively fuzz security-critical control- and data-flow logic in the processors, hence missing security vulnerabilities. To tackle this challenge, we present HyPFuzz, a hybrid fuzzer that leverages formal verification tools to help fuzz the hard-to-reach part of the processors. To increase the effectiveness of HyPFuzz, we perform optimizations in time and space. First, we develop a scheduling strategy to prevent under- or over-utilization of the capabilities of formal tools and fuzzers. Second, we develop heuristic strategies to select points in the design space for the formal tool to target. We evaluate HyPFuzz on five widely-used open-source processors. HyPFuzz detected all the vulnerabilities detected by the most recent processor fuzzer and found three new vulnerabilities that were missed by previous extensive fuzzing and formal verification. This led to two new common vulnerabilities and exposures (CVE) entries. HyPFuzz also achieves 11.68× faster coverage than the most recent processor fuzzer.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6e4287b4-c26d-40e7-bfd1-d9e7a0f3282fCited by top-tier papers15
- Cascade: CPU Fuzzing via Intricate Program GenerationFlavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviUSENIX Security 2024 · 46 citations
- DejaVuzz: Disclosing Transient Execution Bugs with Dynamic Swappable Memory and Differential Information Flow Tracking Assisted Processor FuzzingJinyan Xu, Yangye Zhou, Xingzhi Zhang, Yinshuai Li et al.ASPLOS 2025 · 4 citations
- SymbFuzz: Symbolic Execution Guided Hardware FuzzingSamit Shahnawaz Miftah, Amisha Srivastava, Hyunmin Kim, Shiyi Wei et al.MICRO 2025 · 4 citations
- ReFuzz: Reusing Tests for Processor Fuzzing with Contextual BanditsChen Chen, Zaiyan Xu, Mohamadreza Rostami, David Liu et al.NDSS 2026 · 4 citations
- μCFI: Formal Verification of Microarchitectural Control-flow IntegrityKatharina Ceesay-Seitz, Flavien Solt, Kaveh RazaviCCS 2024 · 3 citations
Builds on5
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid FuzzingLei Zhao, Yue Duan, Heng Yin, Jifeng XuanNDSS 2019 · 157 citations
- A Formal Approach for Detecting Vulnerabilities to Transient Execution Attacks in Out-of-Order ProcessorsMohammad Rahmani Fadiheh, Johannes Müller, Raik Brinkmann, Subhasish Mitra et al.DAC 2020 · 38 citations
- Cats vs. Spectre: An Axiomatic Approach to Modeling Speculative Execution AttacksHernán Ponce de León, Johannes KinderS&P 2022 · 35 citations
- Fuzzing Hardware Like SoftwareTimothy Trippel, Kang G. Shin, Alex Chernyakhovsky, Garret Kelly et al.USENIX Security 2022
Related papers
- TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable VulnerabilitiesRahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig et al.USENIX Security 2022
- HyperFuzzer: An Efficient Hybrid Fuzzer for Virtual CPUsXinyang Ge, Ben Niu, Robert Brotzman, Yaohui Chen et al.CCS 2021 · 9 citations
- HyperMirage: Direct State Manipulation in Hybrid Virtual CPU FuzzingManuel Andreas, Fabian Specht, Marius MomeuNDSS 2026
- GenHuzz: An Efficient Generative Hardware FuzzerLichao Wu, Mohamadreza Rostami, Huimin Li, Jeyavijayan Rajendran et al.USENIX Security 2025
- WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in ProcessorsPallavi Borkar, Chen Chen, Mohamadreza Rostami, Nikhilesh Singh et al.USENIX Security 2024 · 31 citations
