SpecDoctor
ToolFirst seen 6/13/2026
Last seen 7/30/2026
Evidence 8 chunks
NEIGHBORHOOD
No graph connections found for this entity yet. It may appear in future ingestion runs.
explore full graph →RELATIONSHIPS
13 connectionsBoth SpecDoctor and DifuzzRTL are RTL fuzzers for CPU verification using differential fuzzing, making them comparable tools in the same domain.
SpecDoctor utilizes differential testing to detect sensitive data leakage.
PORTRUSH combines with SpecDoctor to monitor whether transient execution is successfully triggered.
SpecDoctor: Differential Fuzz Testing to Find Transient Execution Vulnerabilities ← introduces 99% 1e
The SpecDoctor paper introduces the SpecDoctor tool as an automated RTL fuzzer to discover transient execution vulnerabilities.
SpecDoctor uses differential fuzz testing to find transient execution vulnerabilities.
SpecDoctor is an automated RTL fuzzer targeting transient execution vulnerabilities.
SpecDoctor employs a multi-phase random instruction generation process for transient execution bug detection.
SpecDoctor designs a fuzzing template allowing it to test all transient execution vulnerability scenarios with a single template.
SpecDoctor is designed to find transient execution vulnerabilities in CPUs.
SpecDoctor was evaluated on the BOOM out-of-order RISC-V CPU.
SpecDoctor was evaluated on the NutShell-Argo out-of-order RISC-V CPU.
SpecDoctor discovered a Spectre-type attack with a port contention side channel in NutShell CPU.
SpecDoctor performs multi-phased fuzzing where each phase addresses an individual vulnerability constraint.