{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T06:06:53Z","timestamp":1784182013319,"version":"3.55.0"},"reference-count":53,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T00:00:00Z","timestamp":1777852800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T00:00:00Z","timestamp":1777852800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,4]]},"DOI":"10.1109\/host68814.2026.11604975","type":"proceedings-article","created":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T20:02:14Z","timestamp":1784145734000},"page":"174-185","source":"Crossref","is-referenced-by-count":0,"title":["Fuzz'EMup: Leveraging EM Side-Channel Emanation to Guide Black-Box Embedded Firmware Fuzzing"],"prefix":"10.1109","author":[{"given":"Fatemeh","family":"Moradihaghighi","sequence":"first","affiliation":[{"name":"School of Computing, Clemson University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zihao","family":"Zhan","sequence":"additional","affiliation":[{"name":"Texas Tech University,Department of Computer Science"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanan","family":"Guo","sequence":"additional","affiliation":[{"name":"University of Rochester,Department of Computer Science"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ziming","family":"Zhao","sequence":"additional","affiliation":[{"name":"Khoury College of Computer Sciences, Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mashrur","family":"Chowdhury","sequence":"additional","affiliation":[{"name":"Clemson University,Department of Civil Engineering"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenkai","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computing, Clemson University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23166"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3512345"},{"key":"ref3","article-title":"Fuzzing: brute force vulnerability discovery","author":"Sutton","year":"2007","journal-title":"Pearson Education"},{"key":"ref4","volume-title":"American fuzzy lop (afl)","author":"Zalewski","year":"2013"},{"key":"ref5","first-page":"5323","article-title":"SHiFT: Semihosted fuzz testing for embedded applications","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Mera"},{"key":"ref6","first-page":"1201","article-title":"HALucinator: Firmware re-hosting through abstraction layer emulation","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Clements"},{"key":"ref7","article-title":"Toward the analysis of embedded firmware through automated re-hosting","volume-title":"in 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Gustafson","year":"2019"},{"key":"ref8","article-title":"Unicorefuzz: On the viability of emulation for kernelspace fuzzing","author":"Maier","year":"2019","journal-title":"in 13th USENIX workshop on offensive technologies (WOOT 19)"},{"key":"ref9","first-page":"3","article-title":"Dynamic taint analysis for automatic detection, analysis, and signaturegeneration of exploits on commodity software","volume":"5","author":"Newsome","year":"2005","journal-title":"in NDSS"},{"key":"ref10","first-page":"1","article-title":"Iot security: An end-to-end view and case study","volume-title":"2017 IEEE Global Communications Conference (GLOBECOM). IEEE","author":"Ling"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3038228.3038233"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23404"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-018-0002-y"},{"key":"ref15","article-title":"AFL++: Combining incremental steps of fuzzing research","author":"Fioraldi","year":"2020","journal-title":"in 14th USENIX workshop on offensive technologies (WOOT 20)"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978428"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-61638-0_14"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23176"},{"key":"ref19","first-page":"807","article-title":"PHMon: A programmable hardware monitor and its security use cases","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Delshadtehrani"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CoolChips.2015.7158659"},{"key":"ref21","first-page":"1237","article-title":"\\{P2IM\\}: Scalable and hardwareindependent firmware testing via automatic peripheral interface modeling","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Feng"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00018"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"ref24","first-page":"1099","article-title":"FIRM-AFL: High-Throughput greybox fuzzing of IoT firmware via augmented process emulation","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Zheng"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TEMC.2014.2300139"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134081"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2931037.2931065"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.7873\/DATE.2015.0639"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-29485-8_13"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978353"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2014.39"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/2872887.2750394"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080223"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2019.2945767"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TASSP.1978.1163055"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19074-2_8"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00040"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1201\/chmonstaapp"},{"key":"ref40","first-page":"2307","article-title":"EcoFuzz: Adaptive Energy-Saving greybox fuzzing as a variant of the adversarial Multi-Armed bandit","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Yue"},{"key":"ref41","first-page":"10","article-title":"Qemu, a fast and portable dynamic translator","volume-title":"USENIX annual technical conference, FREENIX Track","volume":"41","author":"Bellard"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560602"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"},{"key":"ref44","first-page":"2007","article-title":"Automatic firmware emulation through invalidity-guided knowledge inference","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Zhou"},{"key":"ref45","first-page":"1239","article-title":"Fuzzware: Using precise MMIO modeling for effective firmware fuzzing","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Scharnowski"},{"key":"ref46","author":"Scharnowski","year":"2023","journal-title":"Hoedur: Embedded firmware fuzzing using multistream inputs."},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23294"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00036"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2015.274"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_13"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CSR54599.2022.9850299"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00034"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3597188"}],"event":{"name":"2026 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","location":"Washington, DC, USA","start":{"date-parts":[[2026,5,4]]},"end":{"date-parts":[[2026,5,7]]}},"container-title":["2026 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11604575\/11604182\/11604975.pdf?arnumber=11604975","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T05:25:48Z","timestamp":1784179548000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11604975\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,4]]},"references-count":53,"URL":"https:\/\/doi.org\/10.1109\/host68814.2026.11604975","relation":{},"subject":[],"published":{"date-parts":[[2026,5,4]]}}}