Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
Learn about a groundbreaking framework for evaluating CPU fuzzer effectiveness through automatic bug injection in this conference presentation from USENIX Security '25. Discover how researchers from ETH Zurich developed Encarsia, an innovative system that addresses the challenge of comparing different hardware fuzzers by creating a standardized corpus of automatically injectable bugs. Explore the comprehensive analysis of 177 software-observable bugs in open-source RISC-V CPU designs that revealed how CPU bugs can be modeled through manipulation of conditional statements or signal drivers. Understand how Encarsia transforms intermediate representations of CPU designs to inject equivalent bugs at the HDL level, while using formal methods to prove architectural deviations. Examine the evaluation results from testing three open-source RISC-V CPUs with recently-proposed CPU fuzzers, which exposed critical limitations in existing hardware fuzzing approaches including inadequate design coverage, ineffective coverage metrics, and unreliable bug detection mechanisms that produce false positives or miss actual bugs. Gain insights into why current hardware fuzzing methodologies need fundamental reassessment and how this research contributes to improving CPU security validation techniques.