{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:02:11Z","timestamp":1782975731071,"version":"3.54.5"},"reference-count":49,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100010663","name":"European Research Council","doi-asserted-by":"publisher","award":["RS3 (101045669)"],"award-info":[{"award-number":["RS3 (101045669)"]}],"id":[{"id":"10.13039\/100010663","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["EXC 2092 CASA - 390781972"],"award-info":[{"award-number":["EXC 2092 CASA - 390781972"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00011","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"3702-3719","source":"Crossref","is-referenced-by-count":0,"title":["SmuFuzz: Enable Deep System Management Mode Fuzzing in Fully Featured UEFI Runtime Environment"],"prefix":"10.1109","author":[{"given":"Jianqiang","family":"Wang","sequence":"first","affiliation":[{"name":"CISPA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yi","family":"Xiang","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meng","family":"Wang","sequence":"additional","affiliation":[{"name":"CISPA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qinying","family":"Wang","sequence":"additional","affiliation":[{"name":"EPFL"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ali","family":"Abbasi","sequence":"additional","affiliation":[{"name":"CISPA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thorsten","family":"Holz","sequence":"additional","affiliation":[{"name":"Max Planck Institute for Security &#x0026; Privacy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Hunting for UEFI Firmware Vulnerabilities at Scale with Automated Static Analysis","author":"Matrosov","year":"2020"},{"key":"ref2","volume-title":"Static analysis-based recovery of service function calls in UEFI firmware","author":"Matrosov","year":"2020"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23371"},{"key":"ref4","article-title":"Symbolic execution for {BIOS security","volume-title":"USENIX Workshop on Offensive Technologies (WOOT)","author":"Bazhaniuk","year":"2015"},{"key":"ref5","volume-title":"[BRLY-2022\u2013003] SMM memory corruption vulnerability in SMM driver on Intel platforms","year":"2022"},{"key":"ref6","volume-title":"[BRLY-2021\u2013019] SMM callout vulnerability in combined DXE\/SMM on Fujitsu device (SMM arbitrary code execution)","year":"2021"},{"key":"ref7","volume-title":"[BRLY-2022\u2013022] SMM callout vulnerability in SMM driver (SMM arbitrary code execution)","year":"2022"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24688"},{"key":"ref9","volume-title":"Multiple race conditions due to toctou flaws in various uefi implementations","year":"2024"},{"key":"ref10","article-title":"Multifuzz: A multi-stream fuzzer for testing monolithic firmware","volume-title":"USENIX Security Symposium","author":"Chesser","year":"2024"},{"key":"ref11","article-title":"HALucinator: Firmware re-hosting through abstraction layer emulation","volume-title":"USENIX Security Symposium","author":"Clements","year":"2020"},{"key":"ref12","article-title":"SGXFuzz: Efficiently synthesizing nested structures for SGX enclave fuzzing","volume-title":"USENIX Security Symposium","author":"Cloosters","year":"2022"},{"key":"ref13","volume-title":"EDK II","year":"2023"},{"key":"ref14","article-title":"P2IM: Scalable and hardware-independent firmware testing via automatic peripheral interface modeling","volume-title":"USENIX Security Symposium","author":"Feng","year":"2020"},{"key":"ref15","volume-title":"fiano: Go-based tools for modifying UEFI firmware","year":"2024"},{"key":"ref16","article-title":"AFL++: Combining incremental steps of fuzzing research","volume-title":"USENIX Workshop on Offensive Technologies (WOOT)","author":"Fioraldi","year":"2020"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560602"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.240400"},{"key":"ref19","volume-title":"syzkaller, Linux syscall fuzzer"},{"key":"ref20","volume-title":"Using host-based firmware analysis to improve platform resiliency","year":"2019"},{"key":"ref21","volume-title":"Intel\u00ae Simics\u00ae Simulator Public Release","year":"2023"},{"key":"ref22","volume-title":"Intel\u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual Combined Volumes 3A, 3B, 3C, and 3D: System Programming Guide","year":"2024"},{"key":"ref23","volume-title":"CHIPSEC: Platform Security Assessment Framework","year":"2025"},{"key":"ref24","volume-title":"Gnu-efi","year":"2024"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"ref26","volume-title":"System Management Mode (SMM) BIOS Vulnerability","year":"2016"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2024.23007"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00018"},{"key":"ref29","article-title":"SHiFT: Semi-hosted Fuzz Testing for Embedded Applications","volume-title":"USENIX Security Symposium","author":"Mera","year":"2024"},{"key":"ref30","volume-title":"american fuzzy lop","author":"Zalewski"},{"key":"ref31","volume-title":"Smis are eeeevil (part 1)","year":"2005"},{"key":"ref32","volume-title":"A race to report a toctou: Analysis of a bug collision in intel smm","year":"2023"},{"key":"ref33","volume-title":"Qiling Framework","year":"2023"},{"key":"ref34","volume-title":"Intel TSFFS - Target Software Fuzzer For Simics","author":"Hart","year":"2024"},{"key":"ref35","article-title":"Fuzzware: Using Precise MMIO Modeling for Effective Firmware Fuzzing","volume-title":"USENIX Security Symposium","author":"Scharnowski","year":"2022"},{"key":"ref36","article-title":"Hoedur: Embedded firmware fuzzing using multi-stream inputs","volume-title":"USENIX Security Symposium","author":"Scharnowski","year":"2023"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00137"},{"key":"ref38","volume-title":"kafl:hardware-assisted feedback fuzzing for os kernels. In USENIX Security Symposium","author":"Schumilo","year":"2017"},{"key":"ref39","article-title":"Forming Faster Firmware Fuzzers","volume-title":"USENIX Security Symposium","author":"Seidel","year":"2023"},{"key":"ref40","doi-asserted-by":"crossref","DOI":"10.1145\/3691620.3695543","article-title":"Stase: Static analysis guided symbolic execution for uefi vulnerability signature generation","volume-title":"ACM\/IEEE International Conference on Automated Software Engineering (ASE)","author":"Shafiuzzaman","year":"2024"},{"key":"ref41","volume-title":"Open virtual machine firmware","year":"2017"},{"key":"ref42","volume-title":"Unified Extensible Firmware Interface (UEFI) Specification","year":"2024"},{"key":"ref43","volume-title":"UEFITool: UEFI firmware image viewer and editor","year":"2024"},{"key":"ref44","article-title":"Aidfuzzer: Adaptive interrupt-driven firmware fuzzing via run-time state recognition","volume-title":"USENIX Security Symposium","author":"Wang","year":"2025"},{"key":"ref45","volume-title":"Universally unique identifier","year":"2025"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218694"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179421"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833723"},{"key":"ref49","article-title":"Automatic firmware emulation through invalidity-guided knowledge inference","volume-title":"USENIX Security Symposium","author":"Zhou","year":"2021"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573420.pdf?arnumber=11573420","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:35:33Z","timestamp":1782970533000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573420\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":49,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00011","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}