: Non-intrusive Feedback-driven Fuzzing for Microcontroller Firmware
Wenqiang Li, Jiameng Shi, Fengjun Li, Jingqiang Lin, Wei Wang, Le Guan
Abstract
Fuzzing is one of the most effective approaches to finding software flaws. However, applying it to microcontroller firmware incurs many challenges. For example, rehosting-based solutions cannot accurately model peripheral behaviors and thus cannot be used to fuzz the corresponding driver code. In this work, we present μAFL, a hardware-in-the-loop approach to fuzzing microcontroller firmware. It leverages debugging tools in existing embedded system development to construct an AFL-compatible fuzzing framework. Specifically, we use the debug dongle to bridge the fuzzing environment on the PC and the target firmware on the microcontroller device. To collect code coverage information without costly code instrumentation, μAFL relies on the ARM ETM hardware debugging feature, which transparently collects the instruction trace and streams the results to the PC. However, the raw ETM data is obscure and needs enormous computing resources to recover the actual instruction flow. We therefore propose an alternative representation of code coverage, which retains the same path sensitivity as the original AFL algorithm, but can directly work on the raw ETM data without matching them with disassembled instructions. To further reduce the workload, we use the DWT hardware feature to selectively collect runtime information of interest. We evaluated μAFL on two real evaluation boards from two major vendors: NXP and STMicroelectronics. With our prototype, we discovered ten zero-day bugs in the driver code shipped with the SDK of STMicroelectronics and three zero-day bugs in the SDK of NXP. Eight CVEs have been allocated for them. Considering the wide adoption of vendor SDKs in real products, our results are alarming.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c8fa90f5-5645-431e-a346-9624dac329f0Cited by top-tier papers5
- JITfuzz: Coverage-guided Fuzzing for JVM Just-in-Time CompilersMingyuan Wu, Minghai Lu, Heming Cui, Junjie Chen et al.ICSE 2023 · 36 citations
- GDMA: Fully Automated DMA Rehosting via Iterative Type OverlaysTobias Scharnowski, Simeon Hoffmann, Moritz Bley, Simon Wörner et al.USENIX Security 2025
- Signal Breaker: Fuzzing Digital Signal ProcessorsCameron Santiago Garcia, Matthew HicksASPLOS 2026
- Understanding Binary Code Similarity for Real-World Vulnerability Detection: A Large-Scale Empirical StudyJingdong Guo, Chaopeng Dong, Yimo Ren, Siyuan Li et al.FSE 2026
- DyMA-Fuzz: Dynamic Direct Memory Access Abstraction for Re-hosted Monolithic Firmware FuzzingGuy Farrelly, Michael Chesser, Seyit Camtepe, Damith C. RanasingheICSE 2026
Builds on9
- Inception: System-Wide Security Testing of Real-World Embedded Systems SoftwareNassim Corteggiani, Giovanni Camurati, Aurélien FrancillonUSENIX Security 2018 · 117 citations
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz et al.CCS 2017 · 98 citations
- DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware AnalysisAlejandro Mera, Bo Feng, Long Lu, Engin KirdaS&P 2021 · 81 citations
- Automatic Firmware Emulation through Invalidity-guided Knowledge InferenceWei Zhou, Le Guan, Peng Liu, Yuqing ZhangUSENIX Security 2021 · 76 citations
- Jetset: Targeted Firmware Rehosting for Embedded SystemsEvan Johnson, Maxwell Bland, Yifei Zhu, Joshua Mason et al.USENIX Security 2021 · 76 citations
Related papers
- Fuzzing Embedded Systems using Debug InterfacesMax Eisele, Daniel Ebert, Christopher Huth, Andreas ZellerISSTA 2023 · 20 citations
- Forming Faster Firmware FuzzersLukas Seidel, Dominik Christian Maier, Marius MuenchUSENIX Security 2023
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson et al.USENIX Security 2022
- Facilitating Non-Intrusive In-Vivo Firmware Testing with Stateless InstrumentationJiameng Shi, Wenqiang Li, Wenwen Wang, Le GuanNDSS 2024
- AidFuzzer: Adaptive Interrupt-Driven Firmware Fuzzing via Run-Time State RecognitionJianqiang Wang, Qinying Wang, Tobias Scharnowski, Li Shi et al.USENIX Security 2025
