Pith. sign in

REVIEW 4 major objections 5 minor 75 references

EmbedFuzz: High Speed Fuzzing Through Transplantation

T0 review · 4 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read By statically rewriting Cortex-M firmware into native Cortex-A Linux processes, EmbedFuzz achieves up to eightfold higher fuzzing throughput than emulation-based rehosting.

desk verdict Genuinely new transplantation technique with a substantial implementation; the headline 8x/4x numbers are muddied by cross-hardware comparison and RQ5's fidelity claim is argued rather than measured, but the core approach is sound and deserves a serious referee. read the letter →

arxiv 2412.12746 v1 pith:5NS6TTTY submitted 2024-12-17 cs.CR

classification cs.CR
keywords firmwaretransplantationrehostingfuzzingArmCortex-Mstaticbinaryrewritinghigh-levelmodelingcoverage-guidedMCU
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

EmbedFuzz sets out to eliminate the emulation tax that dominates fuzzing of low-end microcontroller firmware. Its central proposal, called transplantation, is to statically rewrite a binary Cortex-M firmware image into a Linux user-space process that runs on Arm Cortex-A hardware, so the majority of instructions execute natively at server speed while a small runtime handles the architectural and peripheral differences. The paper reports that transplanted firmware fuzzes up to eight times faster than emulator-based rehosters, consumes at most a quarter of the energy, and still reproduces seven distinct bugs in a ten-firmware benchmark. A sympathetic reader would take the core claim to be that native execution plus careful handling of ISA and peripheral semantics can displace emulation as the default rehosting strategy for HAL-based MCU firmware.

What carries the argument

The central mechanism is the transplantation pipeline itself: a static binary rewriter that preserves the MCU's flat physical address layout in a user-space virtual address space, rewrites or traps the handful of Thumb-2 instructions whose behavior differs between Cortex-M and Cortex-A, instruments basic blocks for coverage, and replaces HAL functions with in-process handler calls; the companion runtime emulates exception entry/return, banked stack-pointer switching using Cortex-A-only floating point registers, and interrupt scheduling on an instruction-counted virtual clock. The key design decision is that only the semantically divergent instructions and peripheral interfaces are emulated, while all other code executes natively, which is what converts the emulation tax into a small runtime surcharge.

What would settle it

A concrete falsifier is a Cortex-M firmware whose peripheral I/O is implemented through direct MMIO with no HAL symbols: EmbedFuzz should still transplant and fuzz it end-to-end, and a failure to do so would show that the claimed general applicability collapses outside HAL-based firmware.

Watch

Extended reading notes

Core claim

Transplantation treats the overlap between the Arm Cortex-M and Cortex-A instruction sets as a resource rather than a problem. EmbedFuzz keeps the firmware's physical address-space layout intact inside a Linux process's virtual memory, copies most code unchanged, rewrites the few semantically different instructions (for example svc becomes a bkpt trap and mrs/msr accesses to the banked stack pointer are mapped to unused floating-point registers), and inserts coverage instrumentation plus branches to HAL peripheral handlers. The runtime then emulates only what cannot be rewritten: Cortex-M exception entry and return, switching between SP_main and SP_process, virtual-clock-based interrupt delivery, and the peripheral handlers reached through high-level modeling. In the paper's evaluation on ten real-world firmware images from the P2IM dataset, this yields up to eightfold higher executions per second than P2IM or Fuzzware, total system power draw of about 47 W versus 197 W, and reproduction of seven distinct bugs, while coverage above the HAL is at least on par in five of ten cases.

Load-bearing premise

The load-bearing premise is that the firmware talks to its hardware through vendor hardware-abstraction libraries (or an embedded OS with a similarly stable interface) whose function boundaries can be located and intercepted; firmware that drives peripherals by writing directly to device memory addresses, or through private libraries, cannot be transplanted by EmbedFuzz.

Editorial extensions

If this is right

  • MCU fuzzing campaigns can run on Arm server hardware at native speed, so the number of executions per second, and therefore the input space explored, grows by up to a factor of eight relative to emulation-based fuzzers.
  • Because the transplanted firmware is an ordinary Linux process, standard tools such as AFL++, GDB, Valgrind, and fork-based process replication can be used without emulator-specific debugger stubs, simplifying crash triaging and horizontal scaling.
  • The measured power draw (about 47 W for the whole Arm system versus 197 W for the x86 system) means large-scale campaigns can be run with at least a fourfold improvement in energy efficiency, reducing infrastructure cost.
  • Peripheral handlers are written once per HAL and reused across firmware sharing that HAL (seven of the ten evaluated firmware use the STM32 HAL), so the one-time modeling effort amortizes.
  • Interrupts are only delivered after the firmware has configured them, which avoids false-positive bugs caused by premature interrupt delivery that plague some emulators.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If transplantation holds up, the same ISA-overlap argument points toward Cortex-R firmware and other architecture pairs with similar superset relationships, but the paper's throughput gains would need re-measurement on workloads that trap heavily, where kernel context-switch overhead could erode the native-speed advantage.
  • The coverage comparison suggests that HAL-level rehosting deliberately trades away visibility below the HAL; an extension that combines transplantation with lightweight MMIO modeling for non-HAL firmware would test whether the speed gain survives outside the HAL-based firmware class.
  • Native Linux-process execution could enable sanitizers, hardware performance counters, and differential testing between the transplanted firmware and the original MCU, none of which the paper evaluates but all of which follow directly from the approach.
  • The virtual-clock interrupt scheduler is acknowledged as best-effort; a direct comparison of bug-finding and timing fidelity against the same firmware on real hardware would quantify how much fidelity is lost when instruction counts stand in for wall-clock time.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. EmbedFuzz proposes firmware transplantation: a static binary rewriting workflow that converts Arm Cortex-M MCU firmware into a Linux user-space process for Arm Cortex-A hosts, running most instructions natively while a runtime emulates MCU-specific behavior (banked stack pointers, exception entry/return, interrupts) and HAL-level peripherals via high-level modeling. The paper claims up to eight-fold higher fuzzing throughput than P2IM and Fuzzware, at least four-fold energy efficiency, and seven distinct bugs found on the P2IM dataset of ten firmware images. The evaluation uses ten 24-hour trials per system, a public dataset, and open-source code, and the paper includes a case study on FreeRTOS task switching.

Significance. If the central claims hold, transplantation is a genuinely new point in the MCU rehosting design space: it avoids the emulation tax by exploiting the Thumb-2 overlap between Cortex-M and Cortex-A, and it enables standard user-space tooling (e.g., GDB, AFL++) on firmware binaries. The paper reports substantial engineering: a custom static rewriter, trap-and-emulate for special instructions, exception entry/return emulation, and both C and Python HAL handlers, with the implementation released as open source. The evaluation is more thorough than typical for the area (ten 24-hour trials per campaign, public P2IM benchmark, explicit seed policy). However, the headline throughput and energy claims are confounded by running the compared systems on different hardware, and the evaluation does not validate the interrupt/timing model against real MCU execution, so the confidence in the quantitative claims is currently limited.

major comments (4)
  1. [§6.1, §6.2, §6.5] The 'up to eight-fold throughput' and 'at least four-fold energy efficiency' claims are not cleanly attributable to transplantation, because EmbedFuzz ran on an NXP LX2160A (Arm Cortex-A72, 30W TDP) while P2IM and Fuzzware ran on an Intel Xeon Gold 5218 (125W TDP). The throughput difference could reflect CPU generation, microarchitecture, or clock behavior rather than native execution, and the energy difference is dominated by the platforms' respective TDPs and idle power draws (29.9W vs 84.0W in Table 3). To support the stated claims, the authors should run the emulation-based baselines on the same LX2160A hardware (or EmbedFuzz's qemu-user mode on the Xeon) and report throughput and energy per execution on a common platform.
  2. [§4.3, §7, §6.4] The paper's functional-equivalence claim rests on an interrupt model that the authors themselves concede is approximate: Section 4.3 delivers interrupts on an instruction-count-based virtual clock, and Section 7 states that this 'may not accurately match the time executed in real firmware' and 'cannot simulate a real interrupt-based system's behavior with 100% accuracy.' RQ5 (§6.7) is argued qualitatively, without measuring execution against real MCU hardware. Moreover, Table 2's classification of Fuzzware findings as false positives (IDs 20, 25, 26) uses EmbedFuzz's own interrupt configuration semantics as ground truth. An external fidelity check, such as a differential test against a real Cortex-M board or against an established emulator on the same input corpus, is needed before the equivalence claim can be accepted.
  3. [§6.3, Fig. 3] The coverage comparison in Figure 3 is not apples-to-apples: EmbedFuzz redirects control at HAL entries, making HAL implementations unreachable, whereas Fuzzware and P2IM execute those blocks. The authors subtract a statically determined lower bound of HAL-only basic blocks from Fuzzware's coverage, but this does not fully correct for the different code populations, and the statement that 'EmbedFuzz outperforms P2IM in all ten cases' is misleading if total coverage, including HAL code, is considered. The RQ2 conclusion should be restricted to a common, method-independent set of application-level basic blocks, or the comparison should be presented as coverage above the HAL only.
  4. [§4.1, §7] The end-to-end applicability claimed in the abstract and introduction is narrower than stated because the method requires HAL libraries (or an embedded OS with a similar stable interface). Section 4.1 states 'we assume that HAL libraries are available to the analyst,' and Section 7 concedes that without such libraries 'EmbedFuzz cannot handle peripheral accesses triggered by the targeted firmware.' For firmware using direct MMIO or private peripheral libraries, the transplantation workflow as described cannot model interactions, so the supported firmware class should be stated in the abstract and used as a selection criterion for the dataset, rather than implying general coverage of MCU firmware binaries.
minor comments (5)
  1. [§6.5 and §6.1] The processor name is inconsistent: Section 6.1 says 'Intel Xeon Gold 5218' while Section 6.5 and Table 3 say 'Intel Xeon Gold 5128'.
  2. [§4.1 or §4.2] The bulleted list in Section 4 has typographical errors: 'i))' and 'ii))' instead of '(i)' and '(ii)'.
  3. [§6.7] There is a typo in 'high-performance dynamic analysis of embedded firmare' — should be 'firmware'.
  4. [§6.2] The qemu-user comparison used to motivate native execution should state explicitly which host hardware was used for that comparison, since the same-platform concern may apply there as well.
  5. [§6.3] The text says 'EmbedFuzz outperforms P2IM in all ten cases' immediately after noting that Fuzzware/P2IM 'can reach many more basic blocks'; clarifying which coverage metric (above-HAL vs total) is being used would avoid a misleading reading.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: results are measured against external baselines; HALucinator reuse is acknowledged, separate, and not load-bearing.

full rationale

EmbedFuzz's central claims—native execution throughput, coverage, bug findings, and energy efficiency—are established by direct measurement against external baselines (P2IM, Fuzzware) on the public P2IM firmware dataset, not derived from an assumed conclusion. The transplantation machinery is a constructive engineering contribution, and the design choices (ISA rewriting, HLM interception, interrupt scheduling) are stated as assumptions or implementation decisions rather than as predictions obtained from fitted parameters. The only author-overlap citation is HALucinator [17], whose HLM principle and Python handlers are reused with acknowledgment; however, HALucinator is a separate, peer-reviewed, publicly available system, and EmbedFuzz's novel native-execution claim is not bootstrapped from it. The paper's Section 7 concession that interrupt simulation 'may not accurately match the time executed in real firmware' is a fidelity caveat, not a circular step: it weakens the functional-equivalence claim without deriving that claim from its own assumptions. The classification of Fuzzware bugs 20/25/26 as false positives relies on EmbedFuzz's own interrupt-triggering model as ground truth, which is an interpretive validity concern rather than a circular derivation. No equation or fitted parameter is renamed as a prediction, no uniqueness theorem is imported from the authors' prior work, and no load-bearing self-citation is present. Accordingly, no circularity is found.

Assumptions & free parameters 2 free parameters · 5 assumptions · 0 invented entities

EmbedFuzz introduces no fitted parameters; the reported numbers come from measurements. The hand-chosen design decisions (interrupt delivery interval, uninstrumented-block threshold) and the domain assumptions above are the uncharged inputs the claims rest on. The paper itself acknowledges the HAL dependency and the approximate interrupt model in Section 7. No new physical entities are postulated; the new artifacts are software components that are implemented and open-sourced, giving them independent evidence through the repository.

free parameters (2)
  • Interrupt delivery interval (virtual clock) = not reported
    The runtime delivers interrupts at a fixed interval based on instruction counts (Section 4.3). The interval is a hand-chosen configuration affecting timing-dependent paths; no sensitivity analysis is provided.
  • Uninstrumented basic block threshold = ~10% of basic blocks ignored
    Basic blocks too small for a 4-byte branch trampoline are skipped to keep the binary small and fast (Section 5). This threshold affects coverage fidelity and is a design choice.
assumptions (5)
  • domain assumption Arm Cortex-A Thumb-2 instruction set is a behavioral superset of the Cortex-M Thumb-2 instructions used in the target firmware.
    The strategy executes most instructions natively without modification; only svc, cps, mrs/msr, and coprocessor instructions are rewritten (Sections 4.2, 5, Appendix A). The authors validated syntactic overlap by disassembling all 2/4-byte opcodes, but semantic equivalence of the remaining instructions is assumed.
  • domain assumption Firmware uses vendor HAL libraries whose functions can be located and intercepted without changing application semantics.
    HLM identifies HAL calls via symbols or LibMatch and replaces them with C/Python handlers (Sections 4.1, 5). The paper concedes in Section 7 that firmware without this interface is out of scope.
  • domain assumption The Vendor_SYS memory region (0xE0100000-0xFFFFFFFF) is unused in the target firmware and can host inserted runtime code.
    Inserted code is placed in this region per the Arm manual; observed in the 10 benchmark firmware, but not guaranteed for all hardware (Section 5).
  • ad hoc to paper Instruction-count-based virtual time with round-robin interrupt delivery is a sufficient model of MCU time for fuzzing.
    Interrupts are scheduled via a virtual clock (Section 4.3), and Section 7 states this is a best-effort approximation that cannot simulate real interrupt behavior with 100% accuracy.
  • ad hoc to paper A branch-to-self infinite loop indicates pure interrupt-driven waiting and can be replaced with a trap without changing behavior.
    The system replaces self-loops with bkpt to fast-forward the virtual clock (Sections 4.3 and 5). This is only valid if the loop carries no load-bearing side effects, which is not guaranteed for arbitrary firmware.

how reviews work

0 comments
Cite this review

Pith. "Pith review of EmbedFuzz: High Speed Fuzzing Through Transplantation." pith.science (2026). https://pith.science/paper/5NS6TTTY

@misc{pith2026241212746,
  author       = {Pith},
  title        = {Pith review of: EmbedFuzz: High Speed Fuzzing Through Transplantation},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/5NS6TTTY}},
  note         = {Machine review of arXiv:2412.12746}
}
read the original abstract

Dynamic analysis and especially fuzzing are challenging tasks for embedded firmware running on modern low-end Microcontroller Units (MCUs) due to performance overheads from instruction emulation, the difficulty of emulating the vast space of available peripherals, and low availability of open-source embedded firmware. Consequently, efficient security testing of MCU firmware has proved to be a resource- and engineering-heavy endeavor. EmbedFuzz introduces an efficient end-to-end fuzzing framework for MCU firmware. Our novel firmware transplantation technique converts binary MCU firmware to a functionally equivalent and fuzzing-enhanced version of the firmware which executes on a compatible high-end device at native performance. Besides the performance gains, our system enables advanced introspection capabilities based on tooling for typical Linux user space processes, thus simplifying analysis of crashes and bug triaging. In our evaluation against state-of-the-art MCU fuzzers, EmbedFuzz exhibits up to eight-fold fuzzing throughput while consuming at most a fourth of the energy thanks to its native execution.

Figures

Figures reproduced from arXiv: 2412.12746 by the authors.

Figure 1
Figure 1. The overview of EmbedFuzz’s approach to MCU firmware fuzzing. Our contributions are shown in gray. firmware suffer from low execution speeds. The former requires an expensive architectural trans￾lation layer, while the latter experiences the low clock speeds of MCUs. Second, the significant overlap between MCU and CPU ISAs, and careful handling of the remaining differences provides EmbedFuzz with a means to replicat… view at source ↗
Figure 2
Figure 2. Box plot of fuzzing executions per second (i.e., throughput) on real-world firmware binaries across ten [PITH_FULL_IMAGE:figures/full_fig_p014_2.png] view at source ↗
Figure 3
Figure 3. Code coverage over time for real-world firmware binaries across ten 24 hour trials. The median [PITH_FULL_IMAGE:figures/full_fig_p015_3.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

75 extracted references · 58 canonical work pages

  1. [1]

    Clements, Saurabh Bagchi, and Mathias Payer

    Naif Saleh Almakhdhub, Abraham A. Clements, Saurabh Bagchi, and Mathias Payer. 2020. 𝜇RAI: Securing Embedded Systems with Return Address Integrity. In Proceedings 2020 Network and Distributed System Security Symposium . Internet Society, San Diego, CA. https://doi.org/10.14722/ndss.2020.24016

  2. [2]

    Amazon Web Services, Inc. [n. d.]. FreeRTOS. https://www.freertos.org/ Accessed: July 2022

  3. [3]

    Nadav Amit, Dan Tsafrir, Assaf Schuster, Ahmad Ayoub, and Eran Shlomo. 2015. Virtual CPU Validation. InProceedings of the 25th Symposium on Operating Systems Principles . ACM, Monterey California, 311–327. https://doi.org/10.1145/ 2815400.2815420

  4. [4]

    Ampere Computing. 2022. Ampere ® Altra®. https://amperecomputing.com/processors/ampere-altra/

  5. [5]

    Apple Inc. 2022. Mac – Apple. https://www.apple.com/mac/ Accessed: July 2022

  6. [6]

    Arm Limited. 2021. Armv7-M Architecture Reference Manual . Technical Report. https://developer.arm.com/ documentation/ddi0403/ee/?lang=en

  7. [7]

    Arm Limited. 2022. Arm Architecture Reference Manual for A-profile Architecture. Technical Report. https://developer. arm.com/documentation/ddi0487/ia/?lang=en

  8. [8]

    Arm Limited. 2022. Mbed — Rapid IoT Device Development. https://os.mbed.com/ Accessed: January 2022

Show all 75 references
  1. [9]

    Arm Limited. 2022. Procedure Call Standard for the Arm ® Architecture. Technical Report. https://github.com/ARM- software/abi-aa

  2. [10]

    Fabrice Bellard. 2005. QEMU, a Fast and Portable Dynamic Translator. In Proceedings of the Annual Conference on USENIX Annual Technical Conference (ATEC ’05). USENIX Association, USA, 41. , Vol. 1, No. 1, Article . Publication date: December 2024. EmbedFuzz: High Speed Fuzzing...

  3. [11]

    Alexander Bulekov, Bandan Das, Stefan Hajnoczi, and Manuel Egele. 2022. Morphuzz: Bending (Input) Space to Fuzz Virtual Devices. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022 , Kevin R. B. Butler and Kurt Thomas (Eds.). USENIX Ass...

  4. [13]

    Sang Kil Cha, Thanassis Avgerinos, Alexandre Rebert, and David Brumley. 2012. Unleashing Mayhem on Binary Code. In 2012 IEEE Symposium on Security and Privacy . IEEE, 380–394

  5. [14]

    Chen, Manuel Egele, Maverick Woo, and David Brumley

    Daming D. Chen, Manuel Egele, Maverick Woo, and David Brumley. 2016. Towards Automated Dynamic Analysis for Linux-based Embedded Firmware. In Proceedings 2016 Network and Distributed System Security Symposium . Internet Society, San Diego, CA. https://doi.org/10.14722/ndss.2016.23415

  6. [15]

    Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin, XiaoFeng Wang, Wing Cheong Lau, Menghan Sun, Ronghai Yang, and Kehuan Zhang. 2018. IoTFuzzer: Discovering Memory Corruptions in IoT through App-Based Fuzzing. In 25th Annual Network and Distributed System S...

  7. [16]

    Clements, Logan Carpenter, William A

    Abraham A. Clements, Logan Carpenter, William A. Moeglein, and Christopher Wright. 2021. Is Your Firmware Real or Re-Hosted? A Case Study in Re-Hosting VxWorks Control System Firmware. In Proceedings 2021 Workshop on Binary Analysis Research. Internet Society, Virtual. https:/...

  8. [17]

    Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer

    Abraham A. Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020. HALucinator: Firmware Re-hosting Through Abstraction Layer Emulation. In 29th USENIX Security Symposium, USENIX Secu...

  9. [18]

    Nassim Corteggiani, Giovanni Camurati, and Aurélien Francillon. 2018. Inception: System-Wide Security Testing of Real-World Embedded Systems Software. In 27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 15-17, 2018 , William Enck and Adrienne Po...

  10. [19]

    Andrei Costin, Apostolis Zarras, and Aurélien Francillon. 2016. Automated Dynamic Firmware Analysis at Scale: A Case Study on Embedded Web Interfaces. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security, AsiaCCS 2016, Xi’an, China, May 30 ...

  11. [20]

    Digi-Key. 2013. MCUs in Industrial Automation. https://www.digikey.com/en/articles/mcus-in-industrial-automation

  12. [21]

    Electronics Sourcing. 2017. Reversal of Fortune for Chip Buyers: Average Prices for Microcontrollers Will Rise. https: //electronics-sourcing.com/2017/05/09/reversal-fortune-chip-buyers-average-prices-microcontrollers-will-rise/ Ac- cessed: January 2022

  13. [22]

    Andrew Fasano, Tiemoko Ballo, Marius Muench, Tim Leek, Alexander Bulekov, Brendan Dolan-Gavitt, Manuel Egele, Aurélien Francillon, Long Lu, Nick Gregory, Davide Balzarotti, and William Robertson. 2021. SoK: Enabling Security Analyses of Embedded Systems via Rehosting. In Proce...

  14. [23]

    Bo Feng, Alejandro Mera, and Long Lu. 2020. P2IM: Scalable and Hardware-Independent Firmware Testing via Automatic Peripheral Interface Modeling. In 29th USENIX Security Symposium, USENIX Security 2020, August 12- 14, 2020, Srdjan Capkun and Franziska Roesner (Eds.). USENIX As...

  15. [24]

    Andrea Fioraldi, Dominik Maier, Heiko Eißfeldt, and Marc Heuse. 2020. AFL++: Combining Incremental Steps of Fuzzing Research. In 14th USENIX Workshop on Offensive Technologies, WOOT 2020, August 11, 2020 , Yuval Yarom and Sarah Zennou (Eds.). USENIX Association. https://www.us...

  16. [25]

    November Five. 2017. Withings Body Cardio Teardown. https://www.ifixit.com/Teardown/Withings+Body+Cardio+ Teardown/74987 Accessed: January 2022

  17. [27]

    Ghidra Contributors. 2022. Ghidra Software Reverse Engineering Framework. National Security Agency. https: //github.com/NationalSecurityAgency/ghidra , Vol. 1, No. 1, Article . Publication date: December 2024. 24 Hofhammer et al

  18. [28]

    Patrice Godefroid. 2020. Fuzzing: Hack, Art, and Science. Commun. ACM 63, 2 (Jan. 2020), 70–76. https://doi.org/10. 1145/3363824

  19. [29]

    Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aurélien Francillon, Yung Ryn Choe, Christopher Kruegel, and Giovanni Vigna. 2019. Toward the Analysis of Embedded Firmware Through Automated Re-Hosting. In 22nd I...

  20. [30]

    Halfhill

    Tom R. Halfhill. 2017. LX2160A Is NXP’s Biggest Multicore. (Oct. 2017). https://www.nxp.com/docs/en/supporting- information/LX2160A-NXP-Biggest-Multicore.pdf Accessed: January 2022

  21. [31]

    Jason Harris. 2016. Grbl STM32F4. https://github.com/deadsy/grbl_stm32f4 Accessed: January 2022

  22. [32]

    Lee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen, and Michael Grace. 2020. PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation. In 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020 , Srdjan Capkun and Franzis...

  23. [33]

    Grant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz, and Kevin R. B. Butler. 2017. FirmUSB: Vetting USB Device Firmware Using Domain Informed Symbolic Execution. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, Dallas...

  24. [34]

    Marc Heuse, Heiko Eißfeldt, Andrea Fioraldi, Dominik Maier, and Jana Aydinbas. 2022. The AFL++ Fuzzing Framework. https://aflplus.plus/ Accessed: July 2022

  25. [35]

    IBM. 2022. IBM Power10: Engineered for Agility. https://www.ibm.com/it-infrastructure/power/power10 Accessed: January 2022

  26. [36]

    Intel Corporation. 2017. Intel ® Xeon® Gold 5218 Processor Product Specification. https://ark.intel.com/content/ www/us/en/ark/products/192444/intel-xeon-gold-5218-processor-22m-cache-2-30-ghz.html Accessed: January 2022

  27. [37]

    IronOS contributors. 2023. IronOS – Flexible Soldering Iron Control Firmware. https://github.com/Ralim/IronOS/

  28. [38]

    Muhui Jiang, Lin Ma, Yajin Zhou, Qiang Liu, Cen Zhang, Zhi Wang, Xiapu Luo, Lei Wu, and Kui Ren. 2021. ECMO: Peripheral Transplantation to Rehost Embedded Linux Kernels. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . ACM, Virtual Eve...

  29. [39]

    Ashu Joshi. 2013. Philips Hue: Setup and Teardown. https://allthingscc.wordpress.com/2013/01/21/philips-hue-setup- and-teardown/ Accessed: January 2022

  30. [40]

    Markus Kammerstetter, Daniel Burian, and Wolfgang Kastner. 2016. Embedded Security Testing with Peripheral Device Caching and Runtime Program State Approximation. In 10th International Conference on Emerging Security Information, Systems and Technologies (SECUW ARE)

  31. [41]

    Markus Kammerstetter, Christian Platzer, and Wolfgang Kastner. 2014. Prospect: Peripheral Proxying Supported Embedded Code Testing. In Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security. ACM, Kyoto Japan, 329–340. https://doi.org/10.1145/...

  32. [42]

    Chung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu, Byoungyoung Lee, Xiangyu Zhang, and Dongyan Xu

  33. [43]

    Mingeun Kim, Dongkwan Kim, Eunsoo Kim, Suryeon Kim, Yeongjin Jang, and Yongdae Kim. 2020. FirmAE: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis. In ACSAC ’20: Annual Computer Security Applications Conference, Virtual Event / Austin, TX, USA, 7-11 December,...

  34. [44]

    George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, and Michael Hicks. 2018. Evaluating Fuzz Testing. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . ACM, Toronto Canada, 2123–2138. https://doi.org/10.1145/3243734.3243804

  35. [45]

    Karl Koscher, Tadayoshi Kohno, and David Molnar. 2015. SURROGATES: Enabling near-Real-Time Dynamic Analyses of Embedded Systems. In 9th USENIX Workshop on Offensive Technologies, WOOT ’15, Washington, DC, USA, August 10-11, 2015, Aurélien Francillon and Thomas Ptacek (Eds.). U...

  36. [46]

    Wenqiang Li, Le Guan, Jingqiang Lin, Jiameng Shi, and Fengjun Li. 2021. From Library Portability to Para-rehosting: Natively Executing Microcontroller Software on Commodity Hardware. In Proceedings 2021 Network and Distributed System Security Symposium. Internet Society, Virtu...

  37. [47]

    Qiang Liu, Flavio Toffalini, Yajin Zhou, and Mathias Payer. 2023. ViDeZZo: Dependency-aware Virtual Device Fuzzing. In 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, May 21-25, 2023 . IEEE, 3228–3245. https://doi.org/10.1109/SP46215.2023.10179354

  38. [48]

    Dominik Maier, Lukas Seidel, and Shinjo Park. 2020. BaseSAFE: Baseband Sanitized Fuzzing through Emulation. In WiSec ’20: 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks, Linz, Austria, July 8-10, 2020 , René Mayrhofer and Michael Roland (Eds.). ACM...

  39. [49]

    Valentin J. M. Manes, HyungSeok Han, Choongwoo Han, Sang Kil Cha, Manuel Egele, Edward J. Schwartz, and Maverick Woo. 2021. The Art, Science, and Engineering of Fuzzing: A Survey. IEEE Trans. Software Eng. 47, 11 (2021), 2312–2331. https://doi.org/10.1109/TSE.2019.2946563 arXi...

  40. [50]

    Lorenzo Martignoni, Stephen McCamant, Pongsin Poosankam, Dawn Song, and Petros Maniatis. 2012. Path-Exploration Lifting: Hi-Fi Tests for Lo-Fi Emulators. In Proceedings of the Seventeenth International Conference on Architectural Support for Programming Languages and Operating...

  41. [51]

    Alejandro Mera, Bo Feng, Long Lu, and Engin Kirda. 2021. DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis. In 42nd IEEE Symposium on Security and Privacy, SP 2021, San Francisco, CA, USA, 24-27 May 2021. IEEE, 1938–1954. https://doi.org/10.1109/SP4...

  42. [52]

    Marius Muench, Dario Nisi, Aurélien Francillon, and Davide Balzarotti. 2018. Avatar 2: A Multi-Target Orchestration Platform. In Proceedings 2018 Workshop on Binary Analysis Research , Vol. 18. Internet Society, San Diego, CA. https: //doi.org/10.14722/bar.2018.23017

  43. [53]

    Nicholas Nethercote and Julian Seward. 2007. Valgrind: A Framework for Heavyweight Dynamic Binary Instrumenta- tion. In Proceedings of the 2007 ACM SIGPLAN Conference on Programming Language Design and Implementation - PLDI ’07. ACM Press, San Diego, California, USA, 89. https...

  44. [54]

    NXP Semiconductors. 2020. NXP Layerscape LX2160A, LX2120A, LX2080A Data Sheet. https: //www.nxp.com/products/processors-and-microcontrollers/arm-processors/layerscape-processors/layerscape- lx2160a-lx2120a-lx2080a-processors:LX2160A Accessed: January 2022

  45. [55]

    NXP Semiconductors. 2022. MPC5xxx Microcontrollers. https://www.nxp.com/products/processors-and- microcontrollers/power-architecture/mpc5xxx-microcontrollers:POWER_ARCH_5XXX Accessed: January 2022

  46. [56]

    Hui Peng, Yan Shoshitaishvili, and Mathias Payer. 2018. T-Fuzz: Fuzzing by Program Transformation. In2018 IEEE Symposium on Security and Privacy, SP 2018, Proceedings, 21-23 May 2018, San Francisco, California, USA . IEEE Computer Society, 697–710. https://doi.org/10.1109/SP.2...

  47. [57]

    Qualcomm Technologies, Inc. 2022. Smartphone Technology | Processor, CPU & GPU Data. https://www.qualcomm. com/products/application/smartphones Accessed: July 2022

  48. [58]

    Nguyen Anh Quynh and Dang Hoang Vu. 2015. Unicorn: Next Generation Cpu Emulator Framework. BlackHat USA 476 (2015). https://www.unicorn-engine.org

  49. [59]

    Majid Salehi, Danny Hughes, and Bruno Crispo. 2019. Microguard: Securing Bare-Metal Microcontrollers Against Code-Reuse Attacks. In 2019 IEEE Conference on Dependable and Secure Computing, DSC 2019, Hangzhou, China, November 18-20, 2019. IEEE, 1–8. https://doi.org/10.1109/DSC4...

  50. [60]

    Tobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson, Marius Muench, Giovanni Vigna, Christopher Kruegel, Thorsten Holz, and Ali Abbasi. 2022. Fuzzware: Using Precise MMIO Modeling for Effective Firmware Fuzzing. In 31st USENIX Security Symposium (USENIX Security 22...

  51. [61]

    Sergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner, and Thorsten Holz. 2021. Nyx: Greybox Hypervisor Fuzzing Using Fast Snapshots and Affine Types. In 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021, Michael Bailey and Rachel Greenstadt (E...

  52. [62]

    Lukas Seidel, Dominik Maier, and Marius Muench. 2023. Forming Faster Firmware Fuzzers. In USENIX Security. https://www.usenix.org/conference/usenixsecurity23/presentation/seidel

  53. [63]

    Yan Shoshitaishvili, Ruoyu Wang, Christophe Hauser, Christopher Kruegel, and Giovanni Vigna. 2015. Firmalice - Automatic Detection of Authentication Bypass Vulnerabilities in Binary Firmware. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015, San Dieg...

  54. [64]

    Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016. Driller: Augmenting Fuzzing through Selective Symbolic Execution. In 23rd Annual Network and Distributed System Secur...

  55. [65]

    STMicroelectronics. 2022. STM32 Arm Cortex MCUs - 32-Bit Microcontrollers. https://www.st.com/en/ microcontrollers-microprocessors/stm32-32-bit-arm-cortex-mcus.html

  56. [66]

    STMicroelectronics. 2022. STM32Cube Development Software. https://www.st.com/en/ecosystems/stm32cube.html Accessed: July 2022

  57. [67]

    Michael Sutton, Adam Greene, and Pedram Amini. 2007. Fuzzing: Brute Force Vulnerability Discovery . Pearson Education

  58. [68]

    Seyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang, Zheng Zhang, Ardalan Amiri Sani, and Zhiyun Qian. 2018. Charm: Facilitating Dynamic Analysis of Device Drivers of Mobile Systems. In 27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 1...

  59. [69]

    Dmitry Vyukov and Andrey Konovalov. 2022. Syzbot. https://syzkaller.appspot.com/upstream/fixed Accessed: July 2022

  60. [70]

    Dmitry Vyukov and Andrey Konovalov. 2022. Syzkaller: An Unsupervised Coverage-Guided Kernel Fuzzer. https: //github.com/google/syzkaller/ Accessed: July 2022

  61. [71]

    Stacy Wegne. 2018. Fitbit Charge 3 Teardown. https://www.techinsights.com/blog/fitbit-charge-3-teardown Accessed: January 2022

  62. [72]

    Moeglein, Saurabh Bagchi, Milind Kulkarni, and Abraham A

    Christopher Wright, William A. Moeglein, Saurabh Bagchi, Milind Kulkarni, and Abraham A. Clements. 2021. Challenges in Firmware Re-Hosting, Emulation, and Analysis. ACM Comput. Surv. 54, 1 (2021), 5:1–5:36. https: //doi.org/10.1145/3423167

  63. [73]

    Jonas Zaddach, Luca Bruno, Aurélien Francillon, and Davide Balzarotti. 2014. AVATAR: A Framework to Support Dynamic Security Analysis of Embedded Systems’ Firmwares. In 21st Annual Network and Distributed System Security Symposium, NDSS 2014, San Diego, California, USA, Februa...

  64. [74]

    Michal Zalewski. 2017. American Fuzzy Lop (AFL) Fuzzer. http://lcamtuf.coredump.cx/afl/ Accessed: January 2022

  65. [75]

    Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019. FIRM-AFL: High- throughput Greybox Fuzzing of IoT Firmware via Augmented Process Emulation. In 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA, August 14-16, 2019 ...

  66. [76]

    Wei Zhou, Le Guan, Peng Liu, and Yuqing Zhang. 2021. Automatic Firmware Emulation through Invalidity-Guided Knowledge Inference. In 30th USENIX Security Symposium, USENIX Security 2021, August 11-13, 2021 , Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 2007–...

  67. [2018]

    In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018

    Securing Real-Time Microcontroller Systems through Customized Memory View Switching. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018 . The Internet Society. http://wp.internetsociety.org/ndss/wp-cont...

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.