ProcessorFuzz is a processor fuzzing tool that guides input generation with a CSR-transition coverage metric. It monitors transitions in Control and Status Registers (CSRs), treating CSR changes as signals that execution has reached new processor states. The tool is described as HDL-agnostic and requiring no instrumentation in the processor design. It was evaluated on the Rocket, BOOM, and BlackParrot open-source RISC-V processors, where it triggered ground-truth bugs 1.23× faster on average than DIFUZZRTL and exposed eight new RISC-V core bugs plus one reference-model bug.
First seen5/28/2026
Last seen7/15/2026
Evidence92 chunks
Wikiv5
01
WIKI
Overview
ProcessorFuzz is a processor fuzzer introduced to improve RTL processor verification using fuzzing feedback based on processor Control and Status Registers (CSRs). The paper listing for “ProcessorFuzz: Processor Fuzzing with Control and Status Registers Guidance” names Sadullah Canakci, Chathura Rajapaksha, Leila Delshadtehrani, Anoop Mysore Nataraja, Michael Bedford Taylor, Manuel Egele, and Ajay Joshi as authors, and lists the work in IEEE HOST 2023, pages 1–12. [publication]
The work is motivated by the increasing difficulty of finding processor bugs before manufacturing. Its abstract notes that undiscovered microarchitectural bugs can become security vulnerabilities, side channels, or functional bugs, and that earlier RTL hardware-fuzzing approaches can suffer from limited HDL support and misleading coverage signals. [motivation]