arXiv論文メモ
新着一覧
cs.CR / cs.AR · 査読状況未確認

ハードウェアのファジングで何を検出できるかを整理

SoK: You Find What You Seek: Rethinking Oracles, Guidance, and Input Generation in Hardware Fuzzing

G Abarajithan, Zhenghua Ma, Cristian Tirelli, Andres Meza, Francesco Restuccia, Cynthia Sturton, Ryan Kastner

この論文をやさしく読む

ひとことで言うと

52のハードウェア向けファザーを整理し、試験が到達・認識できる失敗の範囲を評価する枠組みを示した。

何に役立つ?

ハードウェア検証の手法を選ぶ際に、目標、判定基準、入力、予算と報告内容を照らし合わせる材料になる。

この研究の面白いところ

ファジングを「予算内の探索」と捉え、網羅率を高める役割と脅威に沿って狙う役割を分ける。

どこまで分かった?

52手法を分析した整理研究であり、要旨は個々の手法の実験成績を提示していない。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

ハードウェアのファジングはセキュリティ検証研究で活発な分野だが、産業での採用はまだ初期段階にある。この知識体系の整理(SoK)は、ソフトウェアのファジングから何を引き継げるか、どこに固有の方法が必要かを調べる。RTL/IP、CPU、NoC、SoC設計にまたがる52のファザーを分析し、検証を予算に制約された探索として捉える分析枠組みを導入する。この探索は、目標、判定基準、誘導、入力生成、対象の抽象化、予算で定義される。したがって試験活動が発見できるのは、資源が尽きる前に効果的に到達し、認識し、優先できる失敗だけである。ハードウェアファジングの役割を、フィードバックに導かれる網羅率で制約付きランダム検証(CRV)を補強することと、脅威モデルおよびセキュリティ仕様に基づく方向を定めた敵対的テストの二つに分ける。枠組みを通して各活動が何を観測し、何を生成できるかを明らかにし、報告結果を裏付ける証拠の評価基盤を与える。分析は、普及には再利用可能なインターフェース、対象固有の検証資産、再現可能な評価、費用と利用者の作業量の透明な報告が必要であることを示唆する。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-23(UTC)
最新改訂
2026-09-23 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Hardware fuzzing is an active area in security verification research, yet its industrial adoption remains in its early stages. This SoK examines which lessons from software fuzzing carry over to hardware and where unique approaches are needed. By analyzing 52 fuzzers across RTL/IP, CPU, NoC, and SoC designs, we introduce an analytical framework that frames verification as a bounded search. This search is defined by its objective, oracle, guidance, input generation, target abstraction, and budget. Consequently, a campaign only uncovers failures it can effectively reach, recognize, and prioritize before exhausting its resources. We distinguish two roles for hardware fuzzing: (1) augmenting constrained-random verification (CRV) via feedback-guided coverage and (2) directed adversarial testing based on threat models and security specifications. Through our framework, we identify what each campaign can observe and generate, providing a basis for assessing the evidence behind reported results. Our analysis suggests that mainstream adoption of hardware fuzzing will require reusable interfaces, target-specific verification assets, reproducible evaluations, and transparent reporting of cost and user effort.

著者のコメント

13 pages

arXiv ID: 2609.27300 / 要約の誤りについて