MorFuzz: Fuzzing Processor via Runtime Instruction Morphing enhanced Synchronizable Co-simulation
Jinyan Xu, Yiyuan Liu, Sirui He, Haoran Lin, Yajin Zhou, Cong Wang
摘要
Modern processors are too complex to be bug free. Recently, a few hardware fuzzing techniques have shown promising results in verifying processor designs. However, due to the complexity of processors, they suffer from complex input grammar, deceptive mutation guidance, and model implementation differences. Therefore, how to effectively and efficiently verify processors is still an open problem. This paper proposes MorFuzz, a novel processor fuzzer that can efficiently discover software triggerable hardware bugs. The core idea behind MorFuzz is to use runtime information to generate instruction streams with valid formats and meaningful semantics. MorFuzz designs a new input structure to provide multi-level runtime mutation primitives and proposes the instruction morphing technique to mutate instruction dynamically. Besides, we also extend the co-simulation framework to various microarchitectures and develop the state synchronization technique to eliminate implementation differences. We evaluate MorFuzz on three popular open-source RISC-V processors: CVA6, Rocket, BOOM, and discover 17 new bugs (with 13 CVEs assigned). Our evaluation shows MorFuzz achieves 4.4× and 1.6× more state coverage than the state-of-the-art fuzzer, DifuzzRTL, and the famous constrained instruction generator, riscv-dv.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in ProcessorsPallavi Borkar, Chen Chen, Mohamadreza Rostami, Nikhilesh Singh 等USENIX Security 2024 · 被引用 31 次
- Atlas: Automating Cross-Language Fuzzing on Android Closed-Source LibrariesHao Xiong, Qinming Dai, Rui Chang, Mingran Qiu 等ISSTA 2024 · 被引用 6 次
- ReFuzz: Reusing Tests for Processor Fuzzing with Contextual BanditsChen Chen, Zaiyan Xu, Mohamadreza Rostami, David Liu 等NDSS 2026 · 被引用 4 次
- GoldenFuzz: Generative Golden Reference Hardware FuzzingLichao Wu, Mohamadreza Rostami, Huimin Li, Nikhilesh Singh 等NDSS 2026 · 被引用 3 次
- Fuzzilicon: A Post-Silicon Microcode-Guided x86 CPU FuzzerJohannes Lenzen, Mohamadreza Rostami, Lichao Wu, Ahmad-Reza SadeghiNDSS 2026 · 被引用 2 次
它引用的顶会 Paper17
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu 等S&P 2018 · 被引用 426 次
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck 等S&P 2020 · 被引用 369 次
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- HardFails: Insights into Software-Exploitable Hardware BugsGhada Dessouky, David Gens, Patrick Haney, Garrett Persyn 等USENIX Security 2019 · 被引用 149 次
相关 Paper
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek 等S&P 2021 · 被引用 126 次
- DiveFuzz: Enhancing CPU Fuzzing via Diverse Instruction ConstructionZihui Guo, Miaomiao Yuan, Yanqi Yang, Liwei Chen 等CCS 2025
- TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable VulnerabilitiesRahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig 等USENIX Security 2022
- Cascade: CPU Fuzzing via Intricate Program GenerationFlavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviUSENIX Security 2024 · 被引用 46 次
- DRVFuzz: Data-Sensitive RISC-V CPU FuzzingZehong Yu, Yuanliang Chen, Zhen Yan, Xudong Zhang 等USENIX Security 2026
