REVIEW 4 major objections 5 minor 75 references
EmbedFuzz: High Speed Fuzzing Through Transplantation
T0 review · 4 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read By statically rewriting Cortex-M firmware into native Cortex-A Linux processes, EmbedFuzz achieves up to eightfold higher fuzzing throughput than emulation-based rehosting.
desk verdict Genuinely new transplantation technique with a substantial implementation; the headline 8x/4x numbers are muddied by cross-hardware comparison and RQ5's fidelity claim is argued rather than measured, but the core approach is sound and deserves a serious referee. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is the transplantation pipeline itself: a static binary rewriter that preserves the MCU's flat physical address layout in a user-space virtual address space, rewrites or traps the handful of Thumb-2 instructions whose behavior differs between Cortex-M and Cortex-A, instruments basic blocks for coverage, and replaces HAL functions with in-process handler calls; the companion runtime emulates exception entry/return, banked stack-pointer switching using Cortex-A-only floating point registers, and interrupt scheduling on an instruction-counted virtual clock. The key design decision is that only the semantically divergent instructions and peripheral interfaces are emulated, while all other code executes natively, which is what converts the emulation tax into a small runtime surcharge.
What would settle it
A concrete falsifier is a Cortex-M firmware whose peripheral I/O is implemented through direct MMIO with no HAL symbols: EmbedFuzz should still transplant and fuzz it end-to-end, and a failure to do so would show that the claimed general applicability collapses outside HAL-based firmware.
Extended reading notes
Core claim
Transplantation treats the overlap between the Arm Cortex-M and Cortex-A instruction sets as a resource rather than a problem. EmbedFuzz keeps the firmware's physical address-space layout intact inside a Linux process's virtual memory, copies most code unchanged, rewrites the few semantically different instructions (for example svc becomes a bkpt trap and mrs/msr accesses to the banked stack pointer are mapped to unused floating-point registers), and inserts coverage instrumentation plus branches to HAL peripheral handlers. The runtime then emulates only what cannot be rewritten: Cortex-M exception entry and return, switching between SP_main and SP_process, virtual-clock-based interrupt delivery, and the peripheral handlers reached through high-level modeling. In the paper's evaluation on ten real-world firmware images from the P2IM dataset, this yields up to eightfold higher executions per second than P2IM or Fuzzware, total system power draw of about 47 W versus 197 W, and reproduction of seven distinct bugs, while coverage above the HAL is at least on par in five of ten cases.
Load-bearing premise
The load-bearing premise is that the firmware talks to its hardware through vendor hardware-abstraction libraries (or an embedded OS with a similarly stable interface) whose function boundaries can be located and intercepted; firmware that drives peripherals by writing directly to device memory addresses, or through private libraries, cannot be transplanted by EmbedFuzz.
Editorial extensions
If this is right
- MCU fuzzing campaigns can run on Arm server hardware at native speed, so the number of executions per second, and therefore the input space explored, grows by up to a factor of eight relative to emulation-based fuzzers.
- Because the transplanted firmware is an ordinary Linux process, standard tools such as AFL++, GDB, Valgrind, and fork-based process replication can be used without emulator-specific debugger stubs, simplifying crash triaging and horizontal scaling.
- The measured power draw (about 47 W for the whole Arm system versus 197 W for the x86 system) means large-scale campaigns can be run with at least a fourfold improvement in energy efficiency, reducing infrastructure cost.
- Peripheral handlers are written once per HAL and reused across firmware sharing that HAL (seven of the ten evaluated firmware use the STM32 HAL), so the one-time modeling effort amortizes.
- Interrupts are only delivered after the firmware has configured them, which avoids false-positive bugs caused by premature interrupt delivery that plague some emulators.
Reading between the lines
- If transplantation holds up, the same ISA-overlap argument points toward Cortex-R firmware and other architecture pairs with similar superset relationships, but the paper's throughput gains would need re-measurement on workloads that trap heavily, where kernel context-switch overhead could erode the native-speed advantage.
- The coverage comparison suggests that HAL-level rehosting deliberately trades away visibility below the HAL; an extension that combines transplantation with lightweight MMIO modeling for non-HAL firmware would test whether the speed gain survives outside the HAL-based firmware class.
- Native Linux-process execution could enable sanitizers, hardware performance counters, and differential testing between the transplanted firmware and the original MCU, none of which the paper evaluates but all of which follow directly from the approach.
- The virtual-clock interrupt scheduler is acknowledged as best-effort; a direct comparison of bug-finding and timing fidelity against the same firmware on real hardware would quantify how much fidelity is lost when instruction counts stand in for wall-clock time.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. EmbedFuzz proposes firmware transplantation: a static binary rewriting workflow that converts Arm Cortex-M MCU firmware into a Linux user-space process for Arm Cortex-A hosts, running most instructions natively while a runtime emulates MCU-specific behavior (banked stack pointers, exception entry/return, interrupts) and HAL-level peripherals via high-level modeling. The paper claims up to eight-fold higher fuzzing throughput than P2IM and Fuzzware, at least four-fold energy efficiency, and seven distinct bugs found on the P2IM dataset of ten firmware images. The evaluation uses ten 24-hour trials per system, a public dataset, and open-source code, and the paper includes a case study on FreeRTOS task switching.
Significance. If the central claims hold, transplantation is a genuinely new point in the MCU rehosting design space: it avoids the emulation tax by exploiting the Thumb-2 overlap between Cortex-M and Cortex-A, and it enables standard user-space tooling (e.g., GDB, AFL++) on firmware binaries. The paper reports substantial engineering: a custom static rewriter, trap-and-emulate for special instructions, exception entry/return emulation, and both C and Python HAL handlers, with the implementation released as open source. The evaluation is more thorough than typical for the area (ten 24-hour trials per campaign, public P2IM benchmark, explicit seed policy). However, the headline throughput and energy claims are confounded by running the compared systems on different hardware, and the evaluation does not validate the interrupt/timing model against real MCU execution, so the confidence in the quantitative claims is currently limited.
major comments (4)
- [§6.1, §6.2, §6.5] The 'up to eight-fold throughput' and 'at least four-fold energy efficiency' claims are not cleanly attributable to transplantation, because EmbedFuzz ran on an NXP LX2160A (Arm Cortex-A72, 30W TDP) while P2IM and Fuzzware ran on an Intel Xeon Gold 5218 (125W TDP). The throughput difference could reflect CPU generation, microarchitecture, or clock behavior rather than native execution, and the energy difference is dominated by the platforms' respective TDPs and idle power draws (29.9W vs 84.0W in Table 3). To support the stated claims, the authors should run the emulation-based baselines on the same LX2160A hardware (or EmbedFuzz's qemu-user mode on the Xeon) and report throughput and energy per execution on a common platform.
- [§4.3, §7, §6.4] The paper's functional-equivalence claim rests on an interrupt model that the authors themselves concede is approximate: Section 4.3 delivers interrupts on an instruction-count-based virtual clock, and Section 7 states that this 'may not accurately match the time executed in real firmware' and 'cannot simulate a real interrupt-based system's behavior with 100% accuracy.' RQ5 (§6.7) is argued qualitatively, without measuring execution against real MCU hardware. Moreover, Table 2's classification of Fuzzware findings as false positives (IDs 20, 25, 26) uses EmbedFuzz's own interrupt configuration semantics as ground truth. An external fidelity check, such as a differential test against a real Cortex-M board or against an established emulator on the same input corpus, is needed before the equivalence claim can be accepted.
- [§6.3, Fig. 3] The coverage comparison in Figure 3 is not apples-to-apples: EmbedFuzz redirects control at HAL entries, making HAL implementations unreachable, whereas Fuzzware and P2IM execute those blocks. The authors subtract a statically determined lower bound of HAL-only basic blocks from Fuzzware's coverage, but this does not fully correct for the different code populations, and the statement that 'EmbedFuzz outperforms P2IM in all ten cases' is misleading if total coverage, including HAL code, is considered. The RQ2 conclusion should be restricted to a common, method-independent set of application-level basic blocks, or the comparison should be presented as coverage above the HAL only.
- [§4.1, §7] The end-to-end applicability claimed in the abstract and introduction is narrower than stated because the method requires HAL libraries (or an embedded OS with a similar stable interface). Section 4.1 states 'we assume that HAL libraries are available to the analyst,' and Section 7 concedes that without such libraries 'EmbedFuzz cannot handle peripheral accesses triggered by the targeted firmware.' For firmware using direct MMIO or private peripheral libraries, the transplantation workflow as described cannot model interactions, so the supported firmware class should be stated in the abstract and used as a selection criterion for the dataset, rather than implying general coverage of MCU firmware binaries.
minor comments (5)
- [§6.5 and §6.1] The processor name is inconsistent: Section 6.1 says 'Intel Xeon Gold 5218' while Section 6.5 and Table 3 say 'Intel Xeon Gold 5128'.
- [§4.1 or §4.2] The bulleted list in Section 4 has typographical errors: 'i))' and 'ii))' instead of '(i)' and '(ii)'.
- [§6.7] There is a typo in 'high-performance dynamic analysis of embedded firmare' — should be 'firmware'.
- [§6.2] The qemu-user comparison used to motivate native execution should state explicitly which host hardware was used for that comparison, since the same-platform concern may apply there as well.
- [§6.3] The text says 'EmbedFuzz outperforms P2IM in all ten cases' immediately after noting that Fuzzware/P2IM 'can reach many more basic blocks'; clarifying which coverage metric (above-HAL vs total) is being used would avoid a misleading reading.
Circularity Check
No significant circularity: results are measured against external baselines; HALucinator reuse is acknowledged, separate, and not load-bearing.
full rationale
EmbedFuzz's central claims—native execution throughput, coverage, bug findings, and energy efficiency—are established by direct measurement against external baselines (P2IM, Fuzzware) on the public P2IM firmware dataset, not derived from an assumed conclusion. The transplantation machinery is a constructive engineering contribution, and the design choices (ISA rewriting, HLM interception, interrupt scheduling) are stated as assumptions or implementation decisions rather than as predictions obtained from fitted parameters. The only author-overlap citation is HALucinator [17], whose HLM principle and Python handlers are reused with acknowledgment; however, HALucinator is a separate, peer-reviewed, publicly available system, and EmbedFuzz's novel native-execution claim is not bootstrapped from it. The paper's Section 7 concession that interrupt simulation 'may not accurately match the time executed in real firmware' is a fidelity caveat, not a circular step: it weakens the functional-equivalence claim without deriving that claim from its own assumptions. The classification of Fuzzware bugs 20/25/26 as false positives relies on EmbedFuzz's own interrupt-triggering model as ground truth, which is an interpretive validity concern rather than a circular derivation. No equation or fitted parameter is renamed as a prediction, no uniqueness theorem is imported from the authors' prior work, and no load-bearing self-citation is present. Accordingly, no circularity is found.
Assumptions & free parameters
free parameters (2)
- Interrupt delivery interval (virtual clock) =
not reported
- Uninstrumented basic block threshold =
~10% of basic blocks ignored
assumptions (5)
- domain assumption Arm Cortex-A Thumb-2 instruction set is a behavioral superset of the Cortex-M Thumb-2 instructions used in the target firmware.
- domain assumption Firmware uses vendor HAL libraries whose functions can be located and intercepted without changing application semantics.
- domain assumption The Vendor_SYS memory region (0xE0100000-0xFFFFFFFF) is unused in the target firmware and can host inserted runtime code.
- ad hoc to paper Instruction-count-based virtual time with round-robin interrupt delivery is a sufficient model of MCU time for fuzzing.
- ad hoc to paper A branch-to-self infinite loop indicates pure interrupt-driven waiting and can be replaced with a trap without changing behavior.
Cite this review
Pith. "Pith review of EmbedFuzz: High Speed Fuzzing Through Transplantation." pith.science (2026). https://pith.science/paper/5NS6TTTY
@misc{pith2026241212746,
author = {Pith},
title = {Pith review of: EmbedFuzz: High Speed Fuzzing Through Transplantation},
year = {2026},
howpublished = {\url{https://pith.science/paper/5NS6TTTY}},
note = {Machine review of arXiv:2412.12746}
}
read the original abstract
Dynamic analysis and especially fuzzing are challenging tasks for embedded firmware running on modern low-end Microcontroller Units (MCUs) due to performance overheads from instruction emulation, the difficulty of emulating the vast space of available peripherals, and low availability of open-source embedded firmware. Consequently, efficient security testing of MCU firmware has proved to be a resource- and engineering-heavy endeavor. EmbedFuzz introduces an efficient end-to-end fuzzing framework for MCU firmware. Our novel firmware transplantation technique converts binary MCU firmware to a functionally equivalent and fuzzing-enhanced version of the firmware which executes on a compatible high-end device at native performance. Besides the performance gains, our system enables advanced introspection capabilities based on tooling for typical Linux user space processes, thus simplifying analysis of crashes and bug triaging. In our evaluation against state-of-the-art MCU fuzzers, EmbedFuzz exhibits up to eight-fold fuzzing throughput while consuming at most a fourth of the energy thanks to its native execution.
Figures
Reference graph
Works this paper leans on
-
[1]
Clements, Saurabh Bagchi, and Mathias Payer
Naif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, and Mathias Payer. 2020. 𝜇RAI: Securing Embedded Systems with Return Address Integrity. In Proceedings 2020 Network and Distributed System Security Symposium . Internet Society, San Diego, CA. https://doi.org/10.14722/ndss.2020.24016
-
[2]
Amazon Web Services, Inc. [n. d.]. FreeRTOS. https://www.freertos.org/ Accessed: July 2022
work page 2022
-
[3]
Nadav Amit, Dan Tsafrir, Assaf Schuster, Ahmad Ayoub, and Eran Shlomo. 2015. Virtual CPU Validation. InProceedings of the 25th Symposium on Operating Systems Principles . ACM, Monterey California, 311–327. https://doi.org/10.1145/ 2815400.2815420
arXiv 2015
-
[4]
Ampere Computing. 2022. Ampere ® Altra®. https://amperecomputing.com/processors/ampere-altra/
work page 2022
-
[5]
Apple Inc. 2022. Mac – Apple. https://www.apple.com/mac/ Accessed: July 2022
work page 2022
-
[6]
Arm Limited. 2021. Armv7-M Architecture Reference Manual . Technical Report. https://developer.arm.com/ documentation/ddi0403/ee/?lang=en
work page 2021
-
[7]
Arm Limited. 2022. Arm Architecture Reference Manual for A-profile Architecture. Technical Report. https://developer. arm.com/documentation/ddi0487/ia/?lang=en
work page 2022
-
[8]
Arm Limited. 2022. Mbed — Rapid IoT Device Development. https://os.mbed.com/ Accessed: January 2022
work page 2022
Show all 75 references
-
[9]
Arm Limited. 2022. Procedure Call Standard for the Arm ® Architecture. Technical Report. https://github.com/ARM- software/abi-aa
2022
-
[10]
Fabrice Bellard. 2005. QEMU, a Fast and Portable Dynamic Translator. In Proceedings of the Annual Conference on USENIX Annual Technical Conference (ATEC ’05). USENIX Association, USA, 41. , Vol. 1, No. 1, Article . Publication date: December 2024. EmbedFuzz: High Speed Fuzzing...
2005
-
[11]
Alexander Bulekov, Bandan Das, Stefan Hajnoczi, and Manuel Egele. 2022. Morphuzz: Bending (Input) Space to Fuzz Virtual Devices. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022 , Kevin R. B. Butler and Kurt Thomas (Eds.). USENIX Ass...
2022
-
[13]
Sang Kil Cha, Thanassis Avgerinos, Alexandre Rebert, and David Brumley. 2012. Unleashing Mayhem on Binary Code. In 2012 IEEE Symposium on Security and Privacy . IEEE, 380–394
2012
-
[14]
Chen, Manuel Egele, Maverick Woo, and David Brumley
Daming D. Chen, Manuel Egele, Maverick Woo, and David Brumley. 2016. Towards Automated Dynamic Analysis for Linux-based Embedded Firmware. In Proceedings 2016 Network and Distributed System Security Symposium . Internet Society, San Diego, CA. https://doi.org/10.14722/ndss.2016.23415
2016
-
[15]
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin, XiaoFeng Wang, Wing Cheong Lau, Menghan Sun, Ronghai Yang, and Kehuan Zhang. 2018. IoTFuzzer: Discovering Memory Corruptions in IoT through App-Based Fuzzing. In 25th Annual Network and Distributed System S...
2018
-
[16]
Clements, Logan Carpenter, William A
Abraham A. Clements, Logan Carpenter, William A. Moeglein, and Christopher Wright. 2021. Is Your Firmware Real or Re-Hosted? A Case Study in Re-Hosting VxWorks Control System Firmware. In Proceedings 2021 Workshop on Binary Analysis Research. Internet Society, Virtual. https:/...
2021
-
[17]
Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer
Abraham A. Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020. HALucinator: Firmware Re-hosting Through Abstraction Layer Emulation. In 29th USENIX Security Symposium, USENIX Secu...
2020
-
[18]
Nassim Corteggiani, Giovanni Camurati, and Aurélien Francillon. 2018. Inception: System-Wide Security Testing of Real-World Embedded Systems Software. In 27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 15-17, 2018 , William Enck and Adrienne Po...
2018
-
[19]
Andrei Costin, Apostolis Zarras, and Aurélien Francillon. 2016. Automated Dynamic Firmware Analysis at Scale: A Case Study on Embedded Web Interfaces. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security, AsiaCCS 2016, Xi’an, China, May 30 ...
2016
-
[20]
Digi-Key. 2013. MCUs in Industrial Automation. https://www.digikey.com/en/articles/mcus-in-industrial-automation
2013
-
[21]
Electronics Sourcing. 2017. Reversal of Fortune for Chip Buyers: Average Prices for Microcontrollers Will Rise. https: //electronics-sourcing.com/2017/05/09/reversal-fortune-chip-buyers-average-prices-microcontrollers-will-rise/ Ac- cessed: January 2022
2017
-
[22]
Andrew Fasano, Tiemoko Ballo, Marius Muench, Tim Leek, Alexander Bulekov, Brendan Dolan-Gavitt, Manuel Egele, Aurélien Francillon, Long Lu, Nick Gregory, Davide Balzarotti, and William Robertson. 2021. SoK: Enabling Security Analyses of Embedded Systems via Rehosting. In Proce...
2021
-
[23]
Bo Feng, Alejandro Mera, and Long Lu. 2020. P2IM: Scalable and Hardware-Independent Firmware Testing via Automatic Peripheral Interface Modeling. In 29th USENIX Security Symposium, USENIX Security 2020, August 12- 14, 2020, Srdjan Capkun and Franziska Roesner (Eds.). USENIX As...
2020
-
[24]
Andrea Fioraldi, Dominik Maier, Heiko Eißfeldt, and Marc Heuse. 2020. AFL++: Combining Incremental Steps of Fuzzing Research. In 14th USENIX Workshop on Offensive Technologies, WOOT 2020, August 11, 2020 , Yuval Yarom and Sarah Zennou (Eds.). USENIX Association. https://www.us...
2020
-
[25]
November Five. 2017. Withings Body Cardio Teardown. https://www.ifixit.com/Teardown/Withings+Body+Cardio+ Teardown/74987 Accessed: January 2022
2017
-
[27]
Ghidra Contributors. 2022. Ghidra Software Reverse Engineering Framework. National Security Agency. https: //github.com/NationalSecurityAgency/ghidra , Vol. 1, No. 1, Article . Publication date: December 2024. 24 Hofhammer et al
2022
-
[28]
Patrice Godefroid. 2020. Fuzzing: Hack, Art, and Science. Commun. ACM 63, 2 (Jan. 2020), 70–76. https://doi.org/10. 1145/3363824
2020
-
[29]
Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aurélien Francillon, Yung Ryn Choe, Christopher Kruegel, and Giovanni Vigna. 2019. Toward the Analysis of Embedded Firmware Through Automated Re-Hosting. In 22nd I...
2019
-
[30]
Halfhill
Tom R. Halfhill. 2017. LX2160A Is NXP’s Biggest Multicore. (Oct. 2017). https://www.nxp.com/docs/en/supporting- information/LX2160A-NXP-Biggest-Multicore.pdf Accessed: January 2022
2017
-
[31]
Jason Harris. 2016. Grbl STM32F4. https://github.com/deadsy/grbl_stm32f4 Accessed: January 2022
2016
-
[32]
Lee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen, and Michael Grace. 2020. PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation. In 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020 , Srdjan Capkun and Franzis...
2020
-
[33]
Grant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz, and Kevin R. B. Butler. 2017. FirmUSB: Vetting USB Device Firmware Using Domain Informed Symbolic Execution. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, Dallas...
2017 doi
-
[34]
Marc Heuse, Heiko Eißfeldt, Andrea Fioraldi, Dominik Maier, and Jana Aydinbas. 2022. The AFL++ Fuzzing Framework. https://aflplus.plus/ Accessed: July 2022
2022
-
[35]
IBM. 2022. IBM Power10: Engineered for Agility. https://www.ibm.com/it-infrastructure/power/power10 Accessed: January 2022
2022
-
[36]
Intel Corporation. 2017. Intel ® Xeon® Gold 5218 Processor Product Specification. https://ark.intel.com/content/ www/us/en/ark/products/192444/intel-xeon-gold-5218-processor-22m-cache-2-30-ghz.html Accessed: January 2022
2017
-
[37]
IronOS contributors. 2023. IronOS – Flexible Soldering Iron Control Firmware. https://github.com/Ralim/IronOS/
2023
-
[38]
Muhui Jiang, Lin Ma, Yajin Zhou, Qiang Liu, Cen Zhang, Zhi Wang, Xiapu Luo, Lei Wu, and Kui Ren. 2021. ECMO: Peripheral Transplantation to Rehost Embedded Linux Kernels. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . ACM, Virtual Eve...
2021
-
[39]
Ashu Joshi. 2013. Philips Hue: Setup and Teardown. https://allthingscc.wordpress.com/2013/01/21/philips-hue-setup- and-teardown/ Accessed: January 2022
2013
-
[40]
Markus Kammerstetter, Daniel Burian, and Wolfgang Kastner. 2016. Embedded Security Testing with Peripheral Device Caching and Runtime Program State Approximation. In 10th International Conference on Emerging Security Information, Systems and Technologies (SECUW ARE)
2016
-
[41]
Markus Kammerstetter, Christian Platzer, and Wolfgang Kastner. 2014. Prospect: Peripheral Proxying Supported Embedded Code Testing. In Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security. ACM, Kyoto Japan, 329–340. https://doi.org/10.1145/...
2014
-
[42]
Chung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu, Byoungyoung Lee, Xiangyu Zhang, and Dongyan Xu
-
[43]
Mingeun Kim, Dongkwan Kim, Eunsoo Kim, Suryeon Kim, Yeongjin Jang, and Yongdae Kim. 2020. FirmAE: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis. In ACSAC ’20: Annual Computer Security Applications Conference, Virtual Event / Austin, TX, USA, 7-11 December,...
2020
-
[44]
George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, and Michael Hicks. 2018. Evaluating Fuzz Testing. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . ACM, Toronto Canada, 2123–2138. https://doi.org/10.1145/3243734.3243804
2018
-
[45]
Karl Koscher, Tadayoshi Kohno, and David Molnar. 2015. SURROGATES: Enabling near-Real-Time Dynamic Analyses of Embedded Systems. In 9th USENIX Workshop on Offensive Technologies, WOOT ’15, Washington, DC, USA, August 10-11, 2015, Aurélien Francillon and Thomas Ptacek (Eds.). U...
2015
-
[46]
Wenqiang Li, Le Guan, Jingqiang Lin, Jiameng Shi, and Fengjun Li. 2021. From Library Portability to Para-rehosting: Natively Executing Microcontroller Software on Commodity Hardware. In Proceedings 2021 Network and Distributed System Security Symposium. Internet Society, Virtu...
2021
-
[47]
Qiang Liu, Flavio Toffalini, Yajin Zhou, and Mathias Payer. 2023. ViDeZZo: Dependency-aware Virtual Device Fuzzing. In 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, May 21-25, 2023 . IEEE, 3228–3245. https://doi.org/10.1109/SP46215.2023.10179354
2023
-
[48]
Dominik Maier, Lukas Seidel, and Shinjo Park. 2020. BaseSAFE: Baseband Sanitized Fuzzing through Emulation. In WiSec ’20: 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks, Linz, Austria, July 8-10, 2020 , René Mayrhofer and Michael Roland (Eds.). ACM...
2020
-
[49]
Valentin J. M. Manes, HyungSeok Han, Choongwoo Han, Sang Kil Cha, Manuel Egele, Edward J. Schwartz, and Maverick Woo. 2021. The Art, Science, and Engineering of Fuzzing: A Survey. IEEE Trans. Software Eng. 47, 11 (2021), 2312–2331. https://doi.org/10.1109/TSE.2019.2946563 arXi...
2021
-
[50]
Lorenzo Martignoni, Stephen McCamant, Pongsin Poosankam, Dawn Song, and Petros Maniatis. 2012. Path-Exploration Lifting: Hi-Fi Tests for Lo-Fi Emulators. In Proceedings of the Seventeenth International Conference on Architectural Support for Programming Languages and Operating...
2012
-
[51]
Alejandro Mera, Bo Feng, Long Lu, and Engin Kirda. 2021. DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis. In 42nd IEEE Symposium on Security and Privacy, SP 2021, San Francisco, CA, USA, 24-27 May 2021. IEEE, 1938–1954. https://doi.org/10.1109/SP4...
2021
-
[52]
Marius Muench, Dario Nisi, Aurélien Francillon, and Davide Balzarotti. 2018. Avatar 2: A Multi-Target Orchestration Platform. In Proceedings 2018 Workshop on Binary Analysis Research , Vol. 18. Internet Society, San Diego, CA. https: //doi.org/10.14722/bar.2018.23017
2018
-
[53]
Nicholas Nethercote and Julian Seward. 2007. Valgrind: A Framework for Heavyweight Dynamic Binary Instrumenta- tion. In Proceedings of the 2007 ACM SIGPLAN Conference on Programming Language Design and Implementation - PLDI ’07. ACM Press, San Diego, California, USA, 89. https...
2007
-
[54]
NXP Semiconductors. 2020. NXP Layerscape LX2160A, LX2120A, LX2080A Data Sheet. https: //www.nxp.com/products/processors-and-microcontrollers/arm-processors/layerscape-processors/layerscape- lx2160a-lx2120a-lx2080a-processors:LX2160A Accessed: January 2022
2020
-
[55]
NXP Semiconductors. 2022. MPC5xxx Microcontrollers. https://www.nxp.com/products/processors-and- microcontrollers/power-architecture/mpc5xxx-microcontrollers:POWER_ARCH_5XXX Accessed: January 2022
2022
-
[56]
Hui Peng, Yan Shoshitaishvili, and Mathias Payer. 2018. T-Fuzz: Fuzzing by Program Transformation. In2018 IEEE Symposium on Security and Privacy, SP 2018, Proceedings, 21-23 May 2018, San Francisco, California, USA . IEEE Computer Society, 697–710. https://doi.org/10.1109/SP.2...
2018
-
[57]
Qualcomm Technologies, Inc. 2022. Smartphone Technology | Processor, CPU & GPU Data. https://www.qualcomm. com/products/application/smartphones Accessed: July 2022
2022
-
[58]
Nguyen Anh Quynh and Dang Hoang Vu. 2015. Unicorn: Next Generation Cpu Emulator Framework. BlackHat USA 476 (2015). https://www.unicorn-engine.org
2015
-
[59]
Majid Salehi, Danny Hughes, and Bruno Crispo. 2019. Microguard: Securing Bare-Metal Microcontrollers Against Code-Reuse Attacks. In 2019 IEEE Conference on Dependable and Secure Computing, DSC 2019, Hangzhou, China, November 18-20, 2019. IEEE, 1–8. https://doi.org/10.1109/DSC4...
2019
-
[60]
Tobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson, Marius Muench, Giovanni Vigna, Christopher Kruegel, Thorsten Holz, and Ali Abbasi. 2022. Fuzzware: Using Precise MMIO Modeling for Effective Firmware Fuzzing. In 31st USENIX Security Symposium (USENIX Security 22...
2022
-
[61]
Sergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner, and Thorsten Holz. 2021. Nyx: Greybox Hypervisor Fuzzing Using Fast Snapshots and Affine Types. In 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021, Michael Bailey and Rachel Greenstadt (E...
2021
-
[62]
Lukas Seidel, Dominik Maier, and Marius Muench. 2023. Forming Faster Firmware Fuzzers. In USENIX Security. https://www.usenix.org/conference/usenixsecurity23/presentation/seidel
2023
-
[63]
Yan Shoshitaishvili, Ruoyu Wang, Christophe Hauser, Christopher Kruegel, and Giovanni Vigna. 2015. Firmalice - Automatic Detection of Authentication Bypass Vulnerabilities in Binary Firmware. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015, San Dieg...
2015
-
[64]
Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016. Driller: Augmenting Fuzzing through Selective Symbolic Execution. In 23rd Annual Network and Distributed System Secur...
2016
-
[65]
STMicroelectronics. 2022. STM32 Arm Cortex MCUs - 32-Bit Microcontrollers. https://www.st.com/en/ microcontrollers-microprocessors/stm32-32-bit-arm-cortex-mcus.html
2022
-
[66]
STMicroelectronics. 2022. STM32Cube Development Software. https://www.st.com/en/ecosystems/stm32cube.html Accessed: July 2022
2022
-
[67]
Michael Sutton, Adam Greene, and Pedram Amini. 2007. Fuzzing: Brute Force Vulnerability Discovery . Pearson Education
2007
-
[68]
Seyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang, Zheng Zhang, Ardalan Amiri Sani, and Zhiyun Qian. 2018. Charm: Facilitating Dynamic Analysis of Device Drivers of Mobile Systems. In 27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 1...
2018
-
[69]
Dmitry Vyukov and Andrey Konovalov. 2022. Syzbot. https://syzkaller.appspot.com/upstream/fixed Accessed: July 2022
2022
-
[70]
Dmitry Vyukov and Andrey Konovalov. 2022. Syzkaller: An Unsupervised Coverage-Guided Kernel Fuzzer. https: //github.com/google/syzkaller/ Accessed: July 2022
2022
-
[71]
Stacy Wegne. 2018. Fitbit Charge 3 Teardown. https://www.techinsights.com/blog/fitbit-charge-3-teardown Accessed: January 2022
2018
-
[72]
Moeglein, Saurabh Bagchi, Milind Kulkarni, and Abraham A
Christopher Wright, William A. Moeglein, Saurabh Bagchi, Milind Kulkarni, and Abraham A. Clements. 2021. Challenges in Firmware Re-Hosting, Emulation, and Analysis. ACM Comput. Surv. 54, 1 (2021), 5:1–5:36. https: //doi.org/10.1145/3423167
2021 doi
-
[73]
Jonas Zaddach, Luca Bruno, Aurélien Francillon, and Davide Balzarotti. 2014. AVATAR: A Framework to Support Dynamic Security Analysis of Embedded Systems’ Firmwares. In 21st Annual Network and Distributed System Security Symposium, NDSS 2014, San Diego, California, USA, Februa...
2014
-
[74]
Michal Zalewski. 2017. American Fuzzy Lop (AFL) Fuzzer. http://lcamtuf.coredump.cx/afl/ Accessed: January 2022
2017
-
[75]
Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019. FIRM-AFL: High- throughput Greybox Fuzzing of IoT Firmware via Augmented Process Emulation. In 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA, August 14-16, 2019 ...
2019
-
[76]
Wei Zhou, Le Guan, Peng Liu, and Yuqing Zhang. 2021. Automatic Firmware Emulation through Invalidity-Guided Knowledge Inference. In 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021 , Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 2007–...
2021
-
[2018]
In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018
Securing Real-Time Microcontroller Systems through Customized Memory View Switching. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018 . The Internet Society. http://wp.internetsociety.org/ndss/wp-cont...
2018
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.