DRVFuzz: Data-Sensitive RISC-V CPU Fuzzing
Zehong Yu, Yuanliang Chen, Zhen Yan, Xudong Zhang, Zhensheng Xian, Yu Jiang
摘要
The rapid adoption of RISC-V across modern computing systems has made the security integrity of its implementations a paramount concern. Logic bugs in RISC-V cores can lead to critical failures, such as faulty privilege transitions and architectural state corruption. While hardware fuzzing has emerged as a powerful technique for automated bug discovery, existing frameworks remain largely data-agnostic. By prioritizing instruction sequence diversity while treating operands as incidental random values, these tools often fail to trigger guarded microarchitectural states that manifest only under precise, data-dependent conditions. In this work, we present DRVFuzz, a data-sensitive fuzzing framework designed to expose hardware vulnerabilities by explicitly modeling and navigating the data-sensitive semantics. First, DRVFuzz introduces a sensitive data model (SDModel) that hierarchically codifies ISA semantics to synthesize tailored operands, including boundary values and exception triggers. Second, to effectively exploring data-dependent paths, DRVFuzz employs transition-guided fuzzing, prioritizing testcases that trigger previously unseen state transitions as labeled by the SDModel. We evaluated DRVFuzz on six real-world RISC-V CPUs with varying microarchitectural complexity, uncovering 22 previously unknown bugs (19 new CVEs).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss 等CCS 2019 · 被引用 289 次
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek 等S&P 2021 · 被引用 126 次
- Data Oblivious ISA Extensions for Side Channel-Resistant and High Performance ComputingJiyong Yu, Lucas Hsiung, Mohamad El Hajj, Christopher W. FletcherNDSS 2019 · 被引用 106 次
- Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution AttacksHany Ragab, Enrico Barberis, Herbert Bos, Cristiano GiuffridaUSENIX Security 2021 · 被引用 76 次
- DirectFuzz: Automated Test Generation for RTL Designs using Directed Graybox FuzzingSadullah Canakci, Leila Delshadtehrani, Furkan Eris, Michael Bedford Taylor 等DAC 2021 · 被引用 53 次
相关 Paper
- GenHuzz: An Efficient Generative Hardware FuzzerLichao Wu, Mohamadreza Rostami, Huimin Li, Jeyavijayan Rajendran 等USENIX Security 2025
- MorFuzz: Fuzzing Processor via Runtime Instruction Morphing enhanced Synchronizable Co-simulationJinyan Xu, Yiyuan Liu, Sirui He, Haoran Lin 等USENIX Security 2023
- DevFuzz: Automatic Device Model-Guided Device Driver FuzzingYilun Wu, Tong Zhang, Changhee Jung, Dongyoon LeeS&P 2023
- GoldenFuzz: Generative Golden Reference Hardware FuzzingLichao Wu, Mohamadreza Rostami, Huimin Li, Nikhilesh Singh 等NDSS 2026 · 被引用 3 次
- RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUsFabian Thomas, Eric García Arribas, Lorenz Hetterich, Daniel Weber 等CCS 2025
