Skip to content
STIMSMITH

TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities

Paper

A 2022 USENIX Security paper by Rahul Kande and coauthors presenting TheHuzz, a hardware fuzzer for processors. The paper argues that prior hardware fuzzing approaches have important limitations, and proposes assembly-level instruction fuzzing guided by coverage metrics derived from intrinsic HDL behaviors. In the reported evaluation on four open-source processors, TheHuzz achieved higher speed than random regression and DifuzzRTL, found 11 bugs including 8 new ones, demonstrated exploits, and was compared against Cadence JasperGold.

First seen 6/14/2026
Last seen 7/10/2026
Evidence 3 chunks
Wiki v2

WIKI

Overview

TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities is a paper by Rahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig, Ahmad-Reza Sadeghi, Aakash Tyagi, and Jeyavijayan Rajendran. It appeared in the 31st USENIX Security Symposium (USENIX Security 2022).

What the paper presents

The paper presents TheHuzz, described as a novel hardware fuzzer intended to detect software-exploitable processor bugs. The work is framed around limitations in prior hardware fuzzing approaches, including limited applicability to common HDLs such as Verilog and VHDL, substantial human intervention, and difficulty capturing intrinsic hardware behaviors such as signal transitions and floating wires.

According to the abstract, TheHuzz analyzes intrinsic behaviors of hardware designs in HDLs and measures coverage metrics that model those behaviors. It then generates assembly-level instructions to increase the desired coverage values, with the goal of finding hardware bugs that are exploitable from software. The paper title explicitly states that this instruction fuzzing is done using golden-reference models.

READ FULL ARTICLE →

NEIGHBORHOOD

No graph connections found for this entity yet. It may appear in future ingestion runs.

explore full graph →

RELATIONSHIPS

14 connections
TheHuzz introduces → 100% 3e
The paper introduces TheHuzz as the tool described in its title.
Aakash Tyagi authored by → 100% 2e
Aakash Tyagi is listed as an author of the paper in the BibTeX entry.
Jeyavijayan Rajendran authored by → 100% 2e
Jeyavijayan Rajendran is listed as an author of the paper in the BibTeX entry.
Garrett Persyn authored by → 100% 2e
Garrett Persyn is listed as an author of the paper in the BibTeX entry.
Rahul Kande authored by → 100% 2e
Rahul Kande is listed as an author of the paper in the BibTeX entry.
Addison Crump authored by → 100% 2e
Addison Crump is listed as an author of the paper in the BibTeX entry.
Ahmad-Reza Sadeghi authored by → 100% 2e
Ahmad-Reza Sadeghi is listed as an author of the paper in the BibTeX entry.
Patrick Jauernig authored by → 100% 2e
Patrick Jauernig is listed as an author of the paper in the BibTeX entry.
Processor Security mentions → 80% 1e
The paper addresses processor security by finding software-exploitable vulnerabilities in processors.
instruction fuzzing uses → 90% 1e
The study centers on instruction fuzzing to test processors.
Texas A&M University published by → 100% 1e
The paper is affiliated with Texas A&M University.
Technische Universität Darmstadt published by → 100% 1e
The paper is affiliated with Technische Universität Darmstadt.
USENIX Association published by → 100% 1e
The paper was published by USENIX Association at USENIX Security 22.
Golden Reference Model uses → 95% 1e
The work leverages golden-reference models in its methodology.

CITATIONS

6 sources
6 citations — click to expand
[1] The paper was authored by Rahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig, Ahmad-Reza Sadeghi, Aakash Tyagi, and Jeyavijayan Rajendran. TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities - USENIX
[2] The paper was published in the 31st USENIX Security Symposium (USENIX Security 2022), pages 3219-3236, by USENIX Association, in Boston, MA, in August 2022. TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities - USENIX
[3] The paper introduces TheHuzz, a novel hardware fuzzer for detecting software-exploitable processor bugs via instruction fuzzing using golden-reference models. TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities - USENIX
[4] TheHuzz was evaluated on four popular open-source processors, achieved 1.98× the speed of random regression and 3.33× the speed of DifuzzRTL, and detected 11 bugs including 8 new bugs with demonstrated exploits. TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities - researchr publication
[5] The paper compares TheHuzz against Cadence JasperGold and argues it overcomes limitations of industry formal verification tools. TheHuzz: Instruction Fuzzing of Processors Using Golden-Reference Models for Finding Software-Exploitable Vulnerabilities - researchr publication