Skip to content
STIMSMITH

SOURCE ARCHIVE

SHA256: 138ead6254318af960a41e384f7ccedb967c293d211921d641823946aca0f95c
TYPE: text/html
SIZE: 51.2 KB
FETCHED: 8/3/2026, 10:21:47 AM
EXTRACTOR: http-html
CHARS: 4,035

EXTRACTED CONTENT

4,035 chars

TY - GEN

T1 - GenHuzz

T2 - The 34th USENIX Conference on Security Symposium

AU - Wu, Lichao

AU - Rostami, Mohamadreza

AU - Li, Huimin

AU - Rajendran, Jeyavijayan

AU - Sadeghi, Ahmad-Reza

N1 - Publisher Copyright: © 2025 The USENIX Association.

PY - 2025/8/13

Y1 - 2025/8/13

N2 - Hardware security is crucial for ensuring trustworthy computing systems. However, the growing complexity of hardware designs has introduced new vulnerabilities that are challenging and expensive to address after fabrication. Hardware fuzz testing, particularly whitebox fuzzing, is promising for scalable and adaptable hardware vulnerability detection. Despite its potential, existing hardware fuzzers face significant challenges, including the complexity of input semantics, limited feedback utilization, and the need for extensive test cases. To address these limitations, we propose GenHuzz, a novel white-box hardware fuzzing framework that reframes fuzzing as an optimization problem by optimizing the fuzzing policy to generate more subtle and effective test cases for vulnerability and bug detection. GenHuzz utilizes a language modelbased fuzzer to intelligently generate RISC-V assembly instructions, which are then dynamically optimized through a Hardware-Guided Reinforcement Learning framework incorporating real-time feedback from the hardware. GenHuzz is uniquely capable of understanding and exploiting complex interdependences between instructions, enabling the discovery of deeper bugs and vulnerabilities. Our evaluation of three RISC-V cores demonstrates that GenHuzz achieves significantly higher hardware coverage with fewer test cases than four state-of-the-art fuzzers. GenHuzz detects all known bugs reported in existing studies with fewer test cases. Furthermore, it uncovers 10 new vulnerabilities, 5 of which are the most severe hardware vulnerabilities ever detected by a hardware fuzzer targeting the same cores, with CVSS v3 severity scores exceeding 7.3 out of 10.

AB - Hardware security is crucial for ensuring trustworthy computing systems. However, the growing complexity of hardware designs has introduced new vulnerabilities that are challenging and expensive to address after fabrication. Hardware fuzz testing, particularly whitebox fuzzing, is promising for scalable and adaptable hardware vulnerability detection. Despite its potential, existing hardware fuzzers face significant challenges, including the complexity of input semantics, limited feedback utilization, and the need for extensive test cases. To address these limitations, we propose GenHuzz, a novel white-box hardware fuzzing framework that reframes fuzzing as an optimization problem by optimizing the fuzzing policy to generate more subtle and effective test cases for vulnerability and bug detection. GenHuzz utilizes a language modelbased fuzzer to intelligently generate RISC-V assembly instructions, which are then dynamically optimized through a Hardware-Guided Reinforcement Learning framework incorporating real-time feedback from the hardware. GenHuzz is uniquely capable of understanding and exploiting complex interdependences between instructions, enabling the discovery of deeper bugs and vulnerabilities. Our evaluation of three RISC-V cores demonstrates that GenHuzz achieves significantly higher hardware coverage with fewer test cases than four state-of-the-art fuzzers. GenHuzz detects all known bugs reported in existing studies with fewer test cases. Furthermore, it uncovers 10 new vulnerabilities, 5 of which are the most severe hardware vulnerabilities ever detected by a hardware fuzzer targeting the same cores, with CVSS v3 severity scores exceeding 7.3 out of 10.

M3 - Conference Contribution (Conference Proceeding)

T3 - Proceedings of the 34th USENIX Conference on Security Symposium

SP - 1787

EP - 1805

BT - 34th USENIX Security Symposium (USENIX Security 25)

A2 - Bauer, Lujo

A2 - Pellegrino, Giancarlo

PB - Association for Computing Machinery

Y2 - 13 August 2025 through 15 August 2025

ER -