Skip to content
STIMSMITH

RISC-V

Concept

RISC-V is a free and open instruction set architecture (ISA) based on RISC design principles that has become a mainstream choice for embedded processors (including IoT devices) and high-performance research cores. The provided evidence portrays RISC-V as both an industry- and academia-relevant open ISA, and as a concrete target for hardware verification (formal, lockstep, constrained-random, symbolic execution, hardware fuzzing), security analysis (ROP, microarchitectural side channels, fault injection), benchmark generation, instruction-set simulation, and CPU fuzzing across many RISC-V processor implementations.

First seen 5/25/2026
Last seen 7/19/2026
Evidence 450 chunks
Wiki v32

WIKI

Overview

RISC-V is a free and open instruction set architecture (ISA) based on RISC design principles. The provided evidence portrays RISC-V as both an industry- and academia-relevant open ISA that increasingly powers embedded processors (including IoT devices) and high-performance research cores, and as a concrete target for verification, security analysis, fault-injection modeling, benchmark generation, instruction-set simulation, and CPU fuzzing across multiple RISC-V processor implementations.

Characteristics described in the sources

READ FULL ARTICLE →

NEIGHBORHOOD

15 nodes · 43 edges
graph · RISC-V · depth=1

RELATIONSHIPS

50 connections
TestRIG ← evaluates 100% 13e
TestRIG is designed to evaluate and verify RISC-V implementations.
RV32I ← part of 100% 8e
RV32I is the base 32-bit integer instruction set that is part of the RISC-V ISA.
BOOM ← implements 100% 7e
BOOM is a RISC-V out-of-order CPU implementation.
Instruction Set Architecture part of → 100% 7e
RISC-V is an open instruction set architecture.
CVA6 ← implements 100% 6e
CVA6 is an open-source RISC-V CPU design.
Toooba ← implements 100% 6e
Toooba is a RISC-V out-of-order superscalar CPU implementation.
Ibex ← implements 100% 5e
Ibex is a simple 32-bit RISC-V implementation.
Control and Status Registers (CSRs) ← part of 100% 5e
CSRs are defined in the RISC-V privileged architecture specification.
Flute ← implements 100% 5e
Flute is a 5-stage in-order pipeline processor implementing RV64.
Piccolo ← implements 100% 5e
Piccolo is a simple 32-bit RISC-V implementation.
Ibex ← implements 100% 5e
Ibex implements the RISC-V ISA.
Rocket Core ← implements 100% 5e
Rocket Core is a RISC-V processor core implementing RV64G,C ISA.
Toooba ← implements 100% 4e
Toooba is a RISC-V out-of-order processor derived from RiscyOO.
riscv-dv ← uses 100% 4e
RISC-V DV targets the RISC-V ISA for its verification environment.
Sail RISC-V Model ← implements 100% 4e
The Sail RISC-V model is a formal specification of the RISC-V ISA.
Sail RISC-V Formal Model ← implements 100% 4e
The Sail RISC-V formal model is a formal specification of the RISC-V ISA.
VexRiscv ← implements 100% 4e
VexRiscv implements the RISC-V RV32I ISA.
MINRES The Good Core (TGC) ← implements 100% 4e
TGC is a RISC-V processor implementation
MicroRV32 ← implements 100% 4e
MicroRV32 is an open source RISC-V based processor implementation.
XiangShan ← implements 100% 4e
XiangShan is a RISC-V processor design.
PicoRV32 ← implements 100% 3e
PicoRV32 implements the RISC-V RV32I ISA.
RVBS ← implements 100% 3e
RVBS is a reference RISC-V implementation.
spike ← implements 100% 3e
Spike is a high-performance RISC-V emulator.
RISC-V VP ← implements 100% 3e
RISC-V VP++ is a RISC-V virtual prototype.
CHERI-RISC-V ← extends 100% 3e
CHERI-RISC-V extends the RISC-V ISA with CHERI capability instructions.
RISC-V International ← mentions 100% 3e
RISC-V International now manages the RISC-V standard.
Rocket Chip ← implements 100% 3e
RocketChip is a RISC-V processor.
The paper considers RISC-V as the target ISA for verification.
The paper mentions RISC-V as a new ISA driving demand for agile verification.
Formal Verification ← evaluates 97% 3e
Formal verification is used to verify properties and correctness of RISC-V processors.
Pre-Silicon Verification ← evaluates 93% 3e
Pre-silicon verification is used to validate RISC-V processors before tape-out.
fence.i Instruction ← part of 100% 2e
FENCE.I is a RISC-V instruction for cache coherency management.
BOOM Core ← mentions 100% 2e
The BOOM core is described as an open-source RISC-V core.
BOOM Processor ← implements 95% 2e
BOOM is an open-source out-of-order RISC-V processor implementation.
The paper uses RISC-V processors as benchmarks.
Rocket Core ← mentions 100% 2e
The Rocket Core is described as an open-source RISC-V core.
CHERI ← part of 85% 2e
CHERI is described as an experimental security extension to RISC-V.
Rocket Chip Generator ← implements 95% 2e
Rocket Chip is an open-source RISC-V processor implementation.
The paper evaluates synthesis of rewrite rules from WebAssembly to RISC-V.
CHERI Early Benchmarks ← uses 100% 2e
The benchmarks target CHERI-based RISC-V systems.
QEMU ← implements 100% 2e
QEMU is a high-performance RISC-V emulator.
The paper surveys RISC-V testability and security mechanisms.
The paper uses RISC-V as the ISA for the processor verification case study.
RISC-V Torture Test Generator ← uses 90% 2e
RISC-V Torture Test Generator generates test cases for RISC-V processors.
Custom Instruction Extension Verification ← part of 93% 2e
RISC-V allows custom instruction extensions that require their own verification.
CHERI ← extends 95% 2e
CHERI is a security extension to the RISC-V architecture.
ProcessorFuzz ← uses 95% 2e
ProcessorFuzz is evaluated on RISC-V processor implementations
LyraGen ← uses 100% 2e
LyraGen learns RISC-V instruction semantics and generates RISC-V instructions.
Random Instruction Generator ← uses 95% 2e
The random instruction generator is designed for RISC-V processors.
Sail ← implements 100% 2e
Sail provides a golden RISC-V model used as the reference in TestRIG.

CITATIONS

7 sources
7 citations — click to expand
[1] RISC-V is a free and open instruction set architecture (ISA) based on RISC design principles, becoming a mainstream choice for embedded processors (including IoT devices), and the RISC-V community is studying security solutions aimed at achieving a root of trust (RoT) and preventing tampering or leakage of sensitive information on RISC-V devices. A Survey on RISC-V Security: Hardware and Architecture
[2] RISC-V is an open-source hardware ISA based on RISC design principles; RISC-V ROP has been demonstrated to be Turing complete and capable of arbitrary function calls using GNU libc gadgets, with algorithmic ROP-chain generation compiling arbitrary code into RISC-V ROP chains. Return-Oriented Programming in RISC-V
[3] Google RISCV-DV is a SV/UVM-based open-source instruction generator for RISC-V processor verification supporting RV32IMAFDC and RV64IMAFDC, machine/supervisor/user privilege modes, page-table randomization, privileged-CSR tests, trap/interrupt handling, MMU stress tests, sub-program generation, illegal/HINT instructions, random branches, directed/random mixing, debug mode with randomized debug ROM, an instruction-generation coverage model, SV testbench handshaking, and co-simulation with spike, riscv-ovpsim, and sail-riscv; it has been verified with Synopsys VCS, Cadence Incisive/Xcelium, and Mentor Questa, and is also reported to work with dsim. third_party/tests/IbexGoogle - third_party/Surelog - Git at Google
[4] The RISCV-DV IbexGoogle flow is applied to LowRISC Ibex, extends RISCV-DV via the user_extension directory and --custom_target/--isa/--mabi/--sim_opts=+uvm_set_type_override invocation, and exposes a handshaking mechanism (HANDSHAKE.md), a Spike-based functional coverage flow via cov.py and riscv_instr_cover_group.sv, runtime options such as instr_cnt, num_of_sub_program, illegal_instr_ratio, hint_instr_ratio, boot_mode, no_wfi, no_dret, gen_debug_section, set_dcsr_ebreak, and a YAML testlist.yaml driving run.py with --test, --iterations, --iss spike|ovpsim|sail[,...], --isa, --mabi, --steps, --co, --seed, --verbose, --target, --custom_target, and --simulator options. third_party/tests/IbexGoogle - third_party/Surelog - Git at Google
[5] PORTRUSH is a hardware-fuzzing framework that constructs a Write Request Graph (WRG) to model arbitration/priority among RISC-V CPU write entities, uses Hierarchical Aggregation and Decoding of selection-element signals to detect write-port contention, and drives a Contention-guided Hardware Fuzzing loop that combines contention-triggering instruction sequences with transient/speculative execution attack patterns; it was evaluated on BOOM, NutShell, and Rocket Core RISC-V CPUs. PORTRUSH: Detect Write Port Contention Side-Channel Vulnerabilities via Hardware Fuzzing
[6] PORTRUSH reports two novel write-port contention side-channel attacks on RISC-V CPUs: MSHRush (LSU vs. Miss Status Handling Register contention at the L1 data cache, demonstrated on BOOM) and Birgus-variant (physical register file contention in the Reorder Buffer, demonstrated on NutShell), as well as the known Spectre-STC attack on BOOM, and notes that write-port contention side channels can leak information even in processors with secure or partitioned caches. PORTRUSH: Detect Write Port Contention Side-Channel Vulnerabilities via Hardware Fuzzing
[7] Alpinum's RISC-V verification blog describes a coverage-driven RISC-V verification loop combining architectural tests, constrained-random generation, formal checks, lockstep comparison, and software-driven scenarios, and lists riscv-arch-test, Google riscv-dv, RISCOF, YosysHQ riscv-formal, the RISC-V Instruction Set Manual Volume I, the RISC-V Debug Specification, and the OpenHW Group CORE-V Verification Strategy as supporting infrastructure. RISC-V Verification: Five Places Projects Lose Weeks