{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T20:00:00Z","timestamp":1785441600638,"version":"3.56.0"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Industry Collaboration Project","award":["D5120260216"],"award-info":[{"award-number":["D5120260216"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/access.2026.3716080","type":"journal-article","created":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T19:18:14Z","timestamp":1784747894000},"page":"113531-113547","source":"Crossref","is-referenced-by-count":0,"title":["DMA-Enhanced Firmware Analysis (DEFA): Dual-Mode DMA Tracking for ARM Cortex-M Firmware"],"prefix":"10.1109","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-9098-2076","authenticated-orcid":false,"given":"Peng","family":"Zhang","sequence":"first","affiliation":[{"name":"Northwestern Polytechnical University","place":["Xi\u2019an, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2854-729X","authenticated-orcid":false,"given":"Shengbing","family":"Zhang","sequence":"additional","affiliation":[{"name":"Northwestern Polytechnical University","place":["Xi\u2019an, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoping","family":"Huang","sequence":"additional","affiliation":[{"name":"Northwestern Polytechnical University","place":["Xi\u2019an, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/sp40000.2020.00009"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/sp40001.2021.00109"},{"key":"ref3","first-page":"1683","article-title":"Breaking through binaries: Compiler-quality instrumentation for binary-only fuzzing","volume-title":"Proc. USENIX Secur. Symp. (USENIX Security)","author":"Nagy"},{"key":"ref4","first-page":"41","article-title":"QEMU, a fast and portable dynamic translator","volume-title":"Proc. USENIX Annu. Tech. Conf. (USENIX ATC)","author":"Bellard"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427294"},{"key":"ref7","volume-title":"State of IoT 2025: IoT Market Continues Strong Growth With 21.1 Billion Connected Devices","year":"2025"},{"key":"ref8","first-page":"1201","article-title":"HALucinator: Firmware re-hosting through abstraction layer emulation","volume-title":"Proc. USENIX Secur. Symp. (USENIX Security)","author":"Clements"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/sp40001.2021.00018"},{"key":"ref10","volume-title":"2023 Embedded Market Study","year":"2023"},{"key":"ref11","volume-title":"Description STM32F4xx HAL Low-Layer Drivers","year":"2017"},{"key":"ref12","volume-title":"LPC800 Series User Manual","year":"2022"},{"key":"ref13","volume-title":"SAM E70 Ser. Datasheet: Extended DMA Controller (XDMAC)","year":"2021"},{"key":"ref14","volume-title":"Procedure Call Standard for the ARM Architecture","year":"2023"},{"key":"ref15","volume-title":"American Fuzzy Lop","author":"Zalewski","year":"2017"},{"key":"ref16","volume-title":"Unicorn\u2014The Ultimate CPU Emulator Framework","year":"2015"},{"key":"ref17","volume-title":"STM32F405xx\/07xx, STM32F415xx\/17xx, STM32F42xxx STM32F43xxx Reference Manual","year":"2023"},{"key":"ref18","volume-title":"STM32F103xx Reference Manual","year":"2021"},{"key":"ref19","volume-title":"NRF52840 Product Specification","year":"2019"},{"key":"ref20","volume-title":"ARM Cortex-M3 Processor Tech. Reference Manual","year":"2012"},{"key":"ref21","volume-title":"ARM Cortex-M4 Processor Tech. Reference Manual","year":"2012"},{"key":"ref22","volume-title":"ARM Cortex-M0 Processor Tech. Reference Manual","year":"2012"},{"key":"ref23","volume-title":"ChibiOS\/RT Real-Time Operating System"},{"key":"ref24","volume-title":"FreeRTOS-Open Source Real-Time Operating System"},{"key":"ref25","first-page":"268","article-title":"Malware detection by eating a whole EXE","volume-title":"Proc. AAAI Workshop Artif. Intell. Cyber Security (AICS)","author":"Raff"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.3390\/app151810093"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/access.2020.2986578"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"key":"ref29","volume-title":"Angr: The Next-Generation Binary Analysis Platform","author":"Shoshitaishvili","year":"2016"},{"key":"ref30","volume-title":"Binwalk: Firmware Analysis Tool","author":"Heffner","year":"2010"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134018"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"},{"key":"ref33","first-page":"1","article-title":"SURROGATES: Enabling near-real-time dynamic analyses of embedded systems","volume-title":"Proc. USENIX Workshop Offensive Technol. (WOOT)","author":"Koscher"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2018.23017"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/2843859.2843867"},{"key":"ref36","first-page":"291","article-title":"Charm: Facilitating dynamic analysis of device drivers of mobile systems","volume-title":"Proc. USENIX Secur. Symp.","author":"Talebi"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590301"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"ref39","first-page":"1099","article-title":"FIRM-AFL: high-throughput greybox fuzzing of IoT firmware via augmented process emulation","volume-title":"Proc. USENIX Secur. Symp. (USENIX Security)","author":"Zheng"},{"key":"ref40","first-page":"1237","article-title":"P2IM: Scalable and hardware-independent firmware testing via automatic peripheral interface modeling","volume-title":"Proc. USENIX Secur. Symp. (USENIX Security)","author":"Feng"},{"key":"ref41","first-page":"135","article-title":"Toward the analysis of embedded firmware through automated re-hosting","volume-title":"Proc. Int. Symp. Res. Attacks Intrusions Defenses (RAID)","author":"Gustafson"},{"key":"ref42","first-page":"1239","article-title":"Fuzzware: Using precise MMIO modeling for effective firmware fuzzing","volume-title":"Proc. USENIX Secur. Symp. (USENIX Security)","author":"Scharnowski"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427280"},{"key":"ref44","first-page":"309","article-title":"Inception: System-wide security testing of real-world embedded systems software","volume-title":"Proc. USENIX Secur. Symp. (USENIX Security)","author":"Corteggiani"},{"key":"ref45","first-page":"1","article-title":"Automatic firmware emulation through invalidity-guided knowledge inference","volume-title":"Proc. USENIX Secur. Symp. (USENIX Security)","author":"Zhou"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/1950365.1950396"},{"key":"ref47","volume-title":"DICE: DMA-Induced Concurrency Error Detection Framework","year":"2021"},{"key":"ref48","volume-title":"Hal-Fuzz: Firmware Fuzzing Component of HALucinator","author":"Clements","year":"2020"},{"key":"ref49","volume-title":"MCUXpresso SDK: Software Development Kit for Microcontrollers","year":"2024"},{"key":"ref50","volume-title":"MPLAB X Integrated Development Environment","year":"2024"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6287639\/11323511\/11618505.pdf?arnumber=11618505","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T19:09:15Z","timestamp":1785438555000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11618505\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":50,"URL":"https:\/\/doi.org\/10.1109\/access.2026.3716080","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}