{"id":"https://openalex.org/W4414198185","doi":"https://doi.org/10.1109/dac63849.2025.11133085","title":"BPUFuzzer: Effective Fuzz Testing for Branching Transient Execution Vulnerabilities of RISC-V CPU","display_name":"BPUFuzzer: Effective Fuzz Testing for Branching Transient Execution Vulnerabilities of RISC-V CPU","publication_year":2025,"publication_date":"2025-06-22","ids":{"openalex":"https://openalex.org/W4414198185","doi":"https://doi.org/10.1109/dac63849.2025.11133085"},"language":"en","primary_location":{"id":"doi:10.1109/dac63849.2025.11133085","is_oa":false,"landing_page_url":"https://doi.org/10.1109/dac63849.2025.11133085","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 62nd ACM/IEEE Design Automation Conference (DAC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101634932","display_name":"Rihui Sun","orcid":"https://orcid.org/0000-0002-9948-8653"},"institutions":[{"id":"https://openalex.org/I204983213","display_name":"Harbin Institute of Technology","ror":"https://ror.org/01yqg2h08","country_code":"CN","type":"education","lineage":["https://openalex.org/I204983213"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Rihui Sun","raw_affiliation_strings":["Harbin Institute of Technology,Harbin,Heilongjiang,China"],"affiliations":[{"raw_affiliation_string":"Harbin Institute of Technology,Harbin,Heilongjiang,China","institution_ids":["https://openalex.org/I204983213"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020622873","display_name":"Jin Wu","orcid":"https://orcid.org/0009-0002-7674-421X"},"institutions":[{"id":"https://openalex.org/I204983213","display_name":"Harbin Institute of Technology","ror":"https://ror.org/01yqg2h08","country_code":"CN","type":"education","lineage":["https://openalex.org/I204983213"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jin Wu","raw_affiliation_strings":["Harbin Institute of Technology,Harbin,Heilongjiang,China"],"affiliations":[{"raw_affiliation_string":"Harbin Institute of Technology,Harbin,Heilongjiang,China","institution_ids":["https://openalex.org/I204983213"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077144125","display_name":"Haoliang Liu","orcid":"https://orcid.org/0000-0002-1606-1858"},"institutions":[{"id":"https://openalex.org/I204983213","display_name":"Harbin Institute of Technology","ror":"https://ror.org/01yqg2h08","country_code":"CN","type":"education","lineage":["https://openalex.org/I204983213"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hanyin Liu","raw_affiliation_strings":["Harbin Institute of Technology,Harbin,Heilongjiang,China"],"affiliations":[{"raw_affiliation_string":"Harbin Institute of Technology,Harbin,Heilongjiang,China","institution_ids":["https://openalex.org/I204983213"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109655538","display_name":"Zikang Tao","orcid":null},"institutions":[{"id":"https://openalex.org/I204983213","display_name":"Harbin Institute of Technology","ror":"https://ror.org/01yqg2h08","country_code":"CN","type":"education","lineage":["https://openalex.org/I204983213"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zikang Tao","raw_affiliation_strings":["Harbin Institute of Technology,Harbin,Heilongjiang,China"],"affiliations":[{"raw_affiliation_string":"Harbin Institute of Technology,Harbin,Heilongjiang,China","institution_ids":["https://openalex.org/I204983213"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012474783","display_name":"Gang Qu","orcid":"https://orcid.org/0000-0001-6759-8949"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gang Qu","raw_affiliation_strings":["University of Maryland,College Park,MD,US"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,US","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100450579","display_name":"Dongsheng Wang","orcid":"https://orcid.org/0000-0001-7341-2776"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dongsheng Wang","raw_affiliation_strings":["Tsinghua University,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University,Beijing,China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071514960","display_name":"Yongqiang Lyu","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yongqiang Lyu","raw_affiliation_strings":["Tsinghua University,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University,Beijing,China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5063004428","display_name":"Jian Dong","orcid":"https://orcid.org/0000-0002-2980-9431"},"institutions":[{"id":"https://openalex.org/I204983213","display_name":"Harbin Institute of Technology","ror":"https://ror.org/01yqg2h08","country_code":"CN","type":"education","lineage":["https://openalex.org/I204983213"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jian Dong","raw_affiliation_strings":["Harbin Institute of Technology,Harbin,Heilongjiang,China"],"affiliations":[{"raw_affiliation_string":"Harbin Institute of Technology,Harbin,Heilongjiang,China","institution_ids":["https://openalex.org/I204983213"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5101634932"],"corresponding_institution_ids":["https://openalex.org/I204983213"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.23429233,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11032","display_name":"VLSI and Analog Circuit Testing","score":0.9879000186920166,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9764999747276306,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.671999990940094},{"id":"https://openalex.org/keywords/control-flow","display_name":"Control flow","score":0.6043000221252441},{"id":"https://openalex.org/keywords/transient","display_name":"Transient (computer programming)","score":0.5103999972343445},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.46140000224113464},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.38749998807907104},{"id":"https://openalex.org/keywords/cover","display_name":"Cover (algebra)","score":0.3774999976158142},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.3643999993801117},{"id":"https://openalex.org/keywords/scan-chain","display_name":"Scan chain","score":0.353300005197525}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.671999990940094},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6270999908447266},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.6043000221252441},{"id":"https://openalex.org/C2780799671","wikidata":"https://www.wikidata.org/wiki/Q17087362","display_name":"Transient (computer programming)","level":2,"score":0.5103999972343445},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.46140000224113464},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.38749998807907104},{"id":"https://openalex.org/C2780428219","wikidata":"https://www.wikidata.org/wiki/Q16952335","display_name":"Cover (algebra)","level":2,"score":0.3774999976158142},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.3643999993801117},{"id":"https://openalex.org/C150012182","wikidata":"https://www.wikidata.org/wiki/Q225990","display_name":"Scan chain","level":3,"score":0.353300005197525},{"id":"https://openalex.org/C206175624","wikidata":"https://www.wikidata.org/wiki/Q595731","display_name":"Branching (polymer chemistry)","level":2,"score":0.34279999136924744},{"id":"https://openalex.org/C141441539","wikidata":"https://www.wikidata.org/wiki/Q1970908","display_name":"Boom","level":2,"score":0.3312000036239624},{"id":"https://openalex.org/C88468194","wikidata":"https://www.wikidata.org/wiki/Q1172416","display_name":"Data-flow analysis","level":3,"score":0.2964000105857849},{"id":"https://openalex.org/C489000","wikidata":"https://www.wikidata.org/wiki/Q747385","display_name":"Data flow diagram","level":2,"score":0.2872999906539917},{"id":"https://openalex.org/C2779639559","wikidata":"https://www.wikidata.org/wiki/Q7661178","display_name":"Symbolic execution","level":3,"score":0.28529998660087585},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.28459998965263367},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2745000123977661},{"id":"https://openalex.org/C96147967","wikidata":"https://www.wikidata.org/wiki/Q190686","display_name":"Subroutine","level":2,"score":0.27079999446868896},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.2696000039577484},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.26260000467300415},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.25589999556541443},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.25440001487731934},{"id":"https://openalex.org/C2776836416","wikidata":"https://www.wikidata.org/wiki/Q1364844","display_name":"False alarm","level":2,"score":0.2517000138759613}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/dac63849.2025.11133085","is_oa":false,"landing_page_url":"https://doi.org/10.1109/dac63849.2025.11133085","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 62nd ACM/IEEE Design Automation Conference (DAC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W2884163605","https://openalex.org/W2954241526","https://openalex.org/W2962986039","https://openalex.org/W2963311060","https://openalex.org/W2972627426","https://openalex.org/W2976763854","https://openalex.org/W3007037833","https://openalex.org/W3015844221","https://openalex.org/W3027968530","https://openalex.org/W3154674654","https://openalex.org/W3191114843","https://openalex.org/W4308643131","https://openalex.org/W4379116144","https://openalex.org/W4395106389"],"related_works":[],"abstract_inverted_index":{"This":[0],"paper":[1],"presents":[2],"BPUFuzzer,":[3],"a":[4,43,93],"fuzz":[5],"testing":[6],"tool":[7],"for":[8],"detecting":[9],"branching":[10],"transient":[11,74],"execution":[12,75],"vulnerabilities":[13,76],"in":[14],"CPU":[15],"RTL":[16],"design.":[17],"BPUFuzzer":[18,59,84],"addresses":[19],"two":[20],"key":[21],"challenges:":[22],"generating":[23],"testcases":[24,62,71],"that":[25,63],"capture":[26],"complex":[27],"control":[28,44],"flows,":[29],"and":[30,53,56,68],"extracting":[31],"essential":[32],"data":[33],"from":[34],"vast":[35],"hardware":[36],"states":[37],"to":[38,72],"guide":[39],"testcase":[40,47],"selection.":[41],"Utilizing":[42],"flow":[45],"graph-based":[46],"generation":[48],"strategy":[49],"with":[50],"anomaly":[51],"detection":[52],"employing":[54],"fitness":[55],"coverage":[57],"metrics,":[58],"works":[60],"on":[61,80],"cover":[64],"broader":[65],"program":[66],"flows":[67],"deliberately":[69],"selects":[70],"discover":[73],"effectively.":[77],"When":[78],"applied":[79],"RISC-V":[81],"Boom":[82],"v3,":[83],"uncovered":[85],"more":[86],"Spectre":[87],"types":[88],"than":[89],"the":[90],"state-of-the-arts,":[91],"including":[92],"previously":[94],"unidentified":[95],"variant,":[96],"named":[97],"Spectre-LOOP.":[98]},"counts_by_year":[],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
