WhisperFuzz
ToolFirst seen 8/5/2026
Last seen 8/5/2026
Evidence 20 chunks
NEIGHBORHOOD
No graph connections found for this entity yet. It may appear in future ingestion runs.
explore full graph →RELATIONSHIPS
28 connectionsWhisperFuzz uses Micro-Event Paths as timing coverage metrics and for vulnerability localization.
WhisperFuzz is evaluated on the CVA6 processor, detecting new timing vulnerabilities.
WhisperFuzz uses the Micro-Event Graph to capture microarchitectural transitions and localize timing vulnerabilities.
WhisperFuzz uses hardware fuzzing to explore processor design spaces.
WhisperFuzz uses static program analysis to extract the Micro-Event Graph and identify root causes of vulnerabilities.
WhisperFuzz extracts microarchitectural state transitions from a processor design at the register-transfer level.
WhisperFuzz collects and analyzes simulation traces to detect and localize timing vulnerabilities.
WhisperFuzz employs hierarchical leakage analysis to prioritize modules for timing vulnerability detection.
WhisperFuzz uses operand mutation to generate data-dependent inputs for timing vulnerability detection.
WhisperFuzz converts MEPs into SystemVerilog Assertion cover properties to monitor timing coverage.
WhisperFuzz introduces and uses a timing coverage metric to evaluate timing behaviors explored.
WhisperFuzz is a directed fuzzer targeting data-dependent timing channels.
WhisperFuzz relies on register dependencies for its leakage analysis.
WhisperFuzz is a white-box fuzzer implementing white-box fuzzing techniques for hardware.
WhisperFuzz has a seed generation module that produces initial instruction sequences for fuzzing.
WhisperFuzz generates instruction sequences as test inputs to detect timing vulnerabilities.
WhisperFuzz instruments and simulates the design-under-test to detect timing vulnerabilities.
WhisperFuzz is evaluated on the BOOM processor, detecting new timing vulnerabilities.
WhisperFuzz is evaluated on the Rocket Core processor, detecting new timing vulnerabilities.
WhisperFuzz is compared with black-box fuzzing approaches that cannot locate timing vulnerability root causes.
WhisperFuzz is compared with grey-box fuzzing approaches that cannot locate timing vulnerability root causes.
WhisperFuzz uses a coverage-feedback fuzzer in its seed generation module.
WhisperFuzz uses the Chipyard environment for processor evaluation.
WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in Processors ← introduces 100% 1e
The paper introduces WhisperFuzz as its primary contribution.
WhisperFuzz uses differential testing by comparing simulation traces to detect timing vulnerabilities.
WhisperFuzz's Diagnozer uses breadth-first search to trace combinational signals to sequential elements.
WhisperFuzz uses HyPFuzz to generate seeds for its Operand mutator.
WhisperFuzz uses VCS to collect coverage reports and simulation traces.