Encarsia: Evaluating CPU Fuzzers via Automatic Bug Injection

Matej Bölcskei, Flavien Solt, Katharina Ceesay-Seitz, Kaveh Razavi

34th USENIX Security Symposium · Day 1

The research presented in "Encarsia: Evaluating CPU Fuzzers via Automatic Bug Injection" addresses a critical challenge in hardware security: the lack of a standardized and effective methodology for evaluating the performance of hardware fuzzers. As new hardware, particularly RISC-V CPU designs, are developed at an unprecedented pace, hardware fuzzing has emerged as a scalable and effective tool for identifying bugs. However, existing fuzzer evaluations often rely on inconsistent metrics like code coverage or the discovery of new "natural" bugs, neither of which provides a reliable basis for comparison or understanding fuzzer strengths and weaknesses. The increasing maturity of designs also makes finding new bugs progressively harder, skewing evaluation results.

AI review

Solid systems security research that finally gives the hardware fuzzing community a principled way to measure themselves. The bug survey is useful, the injection framework is clean, and the formal observability check is the right call. The fuzzer teardown is brutal but earned.