μCFI: Formal Verification of Microarchitectural Control-flow Integrity
PaperFirst seen 7/6/2026
Last seen 7/6/2026
Evidence 15 chunks
NEIGHBORHOOD
No graph connections found for this entity yet. It may appear in future ingestion runs.
explore full graph →RELATIONSHIPS
30 connectionsThe paper verifies μCFI over unbounded instruction sequences.
The paper uses static design analysis to automatically extract taint injection conditions from CPU designs.
The paper uses Information Flow Tracking to formally verify the μCFI property.
The paper applies formal verification to verify the μCFI property on RISC-V CPUs.
The paper uses a model checker to exhaustively verify the μCFI property over hardware designs.
The paper uses logic abstraction to disconnect signals from their driving logic in verification.
The paper evaluates the μCFI property on the Kronos RISC-V CPU.
The paper evaluates the μCFI property on the PicoRV32 RISC-V CPU.
The paper evaluates the μCFI property on the Ibex RISC-V CPU.
The paper evaluates the μCFI property on the Scarv RISC-V CPU.
The paper uses taint tracking as a core mechanism for information flow analysis.
The paper operates at the Register Transfer Level for hardware verification.
The paper reports five new security vulnerabilities including 4 CVEs found through μCFI verification.
The paper introduces μCFI as a new generic security property.
The paper uses CellIFT for information flow tracking in the verification approach.
The paper uses Yosys passes for static design analysis and taint condition generation.
The paper uses SystemVerilog Assertions to express the μCFI property for formal verification.
The paper uses cell-level taint instrumentation via CellIFT and CellDFT.
Katharina Ceesay-Seitz is listed as an author of the paper.
Flavien Solt is listed as an author of the paper.
Kaveh Razavi is listed as an author of the paper.
The paper uses the Instruction Operand Constraint to isolate verification of information flows to specific instructions.
The paper introduces and open-sources the μCFI verification toolchain.
The paper introduces CellDFT, a new data flow tracking variant of CellIFT.
The paper mentions delay injection attacks as a class of vulnerability captured by μCFI.
The paper uses Jasper FPV as the formal model checker for verification.
The paper mentions RISC-V's DIEL mode as motivation for microarchitectural CT verification.
The paper mentions hardware fuzzing as a related but incomplete verification approach.
The paper uses precise taint injection to correctly attribute information flows to specific instructions.
The paper discusses timing side-channel attacks as a threat model addressed by μCFI.