Skip to content
STIMSMITH

ProcessorFuzz: Processor Fuzzing with Control and Status Registers Guidance

Paper

ProcessorFuzz is a HOST 2023 paper that presents a processor fuzzer for RTL verification. Its core idea is CSR-transition coverage, which treats new transitions in Control and Status Registers as coverage-increasing events that correspond to new processor states. The design also uses ISA simulation to quickly identify interesting inputs, reducing reliance on slower RTL simulation for fuzzing guidance. In evaluation on Rocket, BOOM, and BlackParrot RISC-V processors, the paper reports triggering bugs found by DIFUZZRTL 1.23× faster on average and finding eight new bugs in open-source processors plus one new bug in a reference model.

First seen 5/28/2026
Last seen 6/28/2026
Evidence 5 chunks
Wiki v2

WIKI

Overview

ProcessorFuzz: Processor Fuzzing with Control and Status Registers Guidance is a 2023 paper by Sadullah Canakci, Chathura Rajapaksha, Leila Delshadtehrani, Anoop Mysore Nataraja, Michael Bedford Taylor, Manuel Egele, and Ajay Joshi. It appeared at the IEEE International Symposium on Hardware Oriented Security and Trust (HOST 2023).[C1]

The paper presents ProcessorFuzz, a processor fuzzer for RTL verification. The work is motivated by a mismatch between conventional fuzzing feedback and processor verification needs: hardware is not directly executable on a host machine, and standard software coverage notions do not directly capture meaningful processor-state exploration.[C2][C3]

READ FULL ARTICLE →

NEIGHBORHOOD

No graph connections found for this entity yet. It may appear in future ingestion runs.

explore full graph →

RELATIONSHIPS

14 connections
ProcessorFuzz introduces → 100% 3e
The paper presents the ProcessorFuzz tool for processor fuzzing guided by control and status registers.
University of Washington authored by → 100% 2e
ProcessorFuzz paper is affiliated with University of Washington.
Sadullah Canakci authored by → 100% 2e
Sadullah Canakci is a co-author of the ProcessorFuzz paper.
Chathura Rajapaksha authored by → 100% 2e
Chathura Rajapaksha is a co-author of the ProcessorFuzz paper.
Leila Delshadtehrani authored by → 100% 2e
Leila Delshadtehrani is a co-author of the ProcessorFuzz paper.
Anoop Nataraja authored by → 100% 2e
Anoop Nataraja is a co-author of the ProcessorFuzz paper.
Michael Bedford Taylor authored by → 100% 2e
Michael Bedford Taylor is a co-author of the ProcessorFuzz paper.
Manuel Egele authored by → 100% 2e
Manuel Egele is a co-author of the ProcessorFuzz paper.
Boston University authored by → 100% 2e
ProcessorFuzz paper is affiliated with Boston University.
Ajay Joshi authored by → 100% 2e
Ajay Joshi is a co-author of the ProcessorFuzz paper.
DiFuzzRTL mentions → 100% 1e
The ProcessorFuzz paper mentions DifuzzRTL as the state-of-the-art baseline.
CSR-guided processor fuzzing introduces → 66% 1e
The work proposes a processor fuzzing approach guided by Control and Status Registers (CSR).
Control and Status Registers (CSR) uses → 70% 1e
The paper’s approach leverages CSRs to guide processor fuzzing.
CSR-transition coverage introduces → 100% 1e
The paper proposes CSR-transition coverage as a novel coverage metric for processor fuzzing.

CITATIONS

8 sources
8 citations — click to expand
[1] Paper metadata: title, authors, HOST 2023 venue, pages 1-12, and DOI. ProcessorFuzz: Processor Fuzzing with Control and Status Registers Guidance - researchr publication
[2] ProcessorFuzz presents two main features: CSR-transition coverage for guiding exploration of unique processor states and ISA-simulation-based determination of interesting inputs; it also summarizes evaluation and bug-finding results. ProcessorFuzz: Processor Fuzzing with Control and
[3] When adapting coverage-guided fuzzing to processors, hardware is not directly executable on a host machine and must be evaluated via RTL simulation. ProcessorFuzz: Processor Fuzzing with Control and
[4] CSR-transition coverage monitors transitions in Control and Status Registers, with some ISA-defined CSRs exposing processor FSM state such as privilege mode or floating-point exception cause. ProcessorFuzz: Processor Fuzzing with Control and
[5] Supporting slides describe ProcessorFuzz as using an ISA simulator to collect CSR-transition coverage, making collection more efficient and HDL agnostic. [PDF] Fuzzing for Discovering Bugs and Side Channels in Processors
[6] Evaluation targets Rocket, BOOM, and BlackParrot; supporting slides summarize 9 new bugs total, with 6 in BlackParrot, 2 in Rocket and BOOM, and 1 in the Dromajo ISA simulator. [PDF] Fuzzing for Discovering Bugs and Side Channels in Processors
[7] Compared with DIFUZZRTL, ProcessorFuzz triggers the bugs found by DIFUZZRTL 1.23× faster on average. ProcessorFuzz: Processor Fuzzing with Control and
[8] The paper reports 8 new bugs in open-source processors and 1 new bug in a reference model. ProcessorFuzz: Processor Fuzzing with Control and