ProcessorFuzz: Guiding Processor Fuzzing using Control and Status Registers
Paper
A 2022 paper that introduces ProcessorFuzz, a processor fuzzing approach guided by a CSR-transition coverage metric. The paper presents an HDL-agnostic workflow that uses CSR transitions observed in ISA traces to identify interesting inputs for RTL checking, and reports faster triggering of ground-truth bugs than DIFUZZRTL as well as nine confirmed bugs.
First seen6/6/2026
Last seen6/29/2026
Evidence5 chunks
Wikiv1
01
WIKI
Overview
ProcessorFuzz: Guiding Processor Fuzzing using Control and Status Registers presents ProcessorFuzz, a processor fuzzer that uses a CSR-transition coverage metric to guide exploration of processor states. The paper is motivated by limitations in prior RTL hardware fuzzing, including lack of support for widely used HDLs and misleading coverage signals that can misidentify interesting inputs. [1]
[3][3] Design flow: ISA simulation produces an extended ISA trace log with CSR values, a transition unit extracts and records new CSR transitions via a transition map, only interesting inputs proceed to RTL simulation, and ISA/RTL mismatches indicate potential bugs.[PDF] Guiding Processor Fuzzing using Control and Status Registers - arXiv
[5][5] The paper was published in September 2022 on arXiv, and the listed authors are Sadullah Canakci, Chathura Rajapaksha, Anoop Mysore Nataraja, Leila Delshadtehrani, Michael Taylor, Manuel Egele, and Ajay Joshi.New Processor Fuzzing Mechanism