{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:13:34Z","timestamp":1783008814508,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,5,21]],"date-time":"2022-05-21T00:00:00Z","timestamp":1653091200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/4.0\/"}],"funder":[{"name":"Ripple University Blockchain Research Initiative"},{"name":"NSF","award":["IIS-2014552"],"award-info":[{"award-number":["IIS-2014552"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,5,21]]},"DOI":"10.1145\/3510003.3510208","type":"proceedings-article","created":{"date-parts":[[2022,7,5]],"date-time":"2022-07-05T22:42:59Z","timestamp":1657060979000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":28,"title":["\u03bcAFL"],"prefix":"10.1145","author":[{"given":"Wenqiang","family":"Li","sequence":"first","affiliation":[{"name":"UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiameng","family":"Shi","sequence":"additional","affiliation":[{"name":"the University of Georgia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fengjun","family":"Li","sequence":"additional","affiliation":[{"name":"the University of Kansas"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jingqiang","family":"Lin","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, Anhui, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Le","family":"Guan","sequence":"additional","affiliation":[{"name":"the University of Georgia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,7,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"ARM. 2007. Embedded Trace Macrocell Architecture Specification ETMv1.0 to ETMv3.4. https:\/\/developer.arm.com\/documentation\/ihi0014\/latest. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_2_1","unstructured":"ARM. 2010. Cortex-M4 Technical Reference Manual. https:\/\/documentation-service.arm.com\/static\/5f19da2a20b7cf4bc524d99a. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_3_1","unstructured":"ARM. 2011. Cortex-M Debug Connectors. https:\/\/documentation-service.arm.com\/static\/5fce6c49e167456a35b36af1. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_4_1","unstructured":"ARM. 2011. Embedded Trace Macrocell ETMv1.0 to ETMv3.5. http:\/\/infocenter.arm.com\/help\/topic\/com.arm.doc.ihi0014q\/IHI0014Q_etm_architecture_spec.pdf. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_5_1","unstructured":"ARM. 2020. Fault status registers and fault address registers. https:\/\/developer.arm.com\/documentation\/ddi0337\/e\/exceptions\/abort-model\/fault-status-registers-and-fault-address-registers. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_6_1","unstructured":"ARM. 2021. CoreSight Components Technical Reference Manual: AHB-AP. https:\/\/developer.arm.com\/documentation\/ddi0337\/h\/debug\/about-the-ahb-ap. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_7_1","unstructured":"ARM. 2021. CoreSight Components Technical Reference Manual: Debug Access Port. https:\/\/developer.arm.com\/documentation\/ddi0314\/h\/Debug-Access-Port. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_8_1","unstructured":"Austin Appleby. 2011. MurmurHash. https:\/\/sites.google.com\/site\/murmurhash\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_9_1","unstructured":"AZ Defender team. 2021. \"BadAlloc\" - Memory allocation vulnerabilities could affect wide range of IoT and OT devices in industrial medical and enterprise networks. https:\/\/msrc-blog.microsoft.com\/2021\/04\/29\/badalloc-memory-allocation-vulnerabilities-could-affect-wide-range-of-iot-and-ot-devices-in-industrial-medical-and-enterprise-networks\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134760.1220164"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427280"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329828"},{"key":"e_1_3_2_1_13_1","volume-title":"HALucinator: Firmware Re-hosting Through Abstraction Layer Emulation. In 29th USENIX Security Symposium (USENIX Security 20)","author":"Clements Abraham A","year":"2020","unstructured":"Abraham A Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020. HALucinator: Firmware Re-hosting Through Abstraction Layer Emulation. In 29th USENIX Security Symposium (USENIX Security 20). 1201--1218."},{"key":"e_1_3_2_1_14_1","volume-title":"Inception: System-Wide Security Testing of Real-World Embedded Systems Software. In 27th USENIX Security Symposium (USENIX Security 18)","author":"Corteggiani Nassim","year":"2018","unstructured":"Nassim Corteggiani, Giovanni Camurati, and Aur\u00e9lien Francillon. 2018. Inception: System-Wide Security Testing of Real-World Embedded Systems Software. In 27th USENIX Security Symposium (USENIX Security 18). Baltimore, MD, 309--326."},{"key":"e_1_3_2_1_15_1","volume-title":"REPT: Reverse Debugging of Failures in Deployed Software. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18)","author":"Cui Weidong","year":"2018","unstructured":"Weidong Cui, Xinyang Ge, Baris Kasikci, Ben Niu, Upamanyu Sharma, Ruoyu Wang, and Insu Yun. 2018. REPT: Reverse Debugging of Failures in Deployed Software. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18). Carlsbad, CA, 17--32."},{"key":"e_1_3_2_1_16_1","volume-title":"HART: Hardware-Assisted Kernel Module Tracing on Arm. In European Symposium on Research in Computer Security. Springer, 316--337","author":"Du Yunlan","year":"2020","unstructured":"Yunlan Du, Zhenyu Ning, Jun Xu, Zhilong Wang, Yueh-Hsun Lin, Fengwei Zhang, Xinyu Xing, and Bing Mao. 2020. HART: Hardware-Assisted Kernel Module Tracing on Arm. In European Symposium on Research in Computer Security. Springer, 316--337."},{"key":"e_1_3_2_1_17_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Feng Bo","year":"2020","unstructured":"Bo Feng, Alejandro Mera, and Long Lu. 2020. P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface Modeling. In 29th USENIX Security Symposium (USENIX Security 20). 1237--1254."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3093336.3037716"},{"key":"e_1_3_2_1_19_1","volume-title":"Christophe Kruegel, and Giovanni Vigna.","author":"Gustafson Eric","year":"2019","unstructured":"Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aur\u00e9lien Francillon, Yung Ryn Choe, Christophe Kruegel, and Giovanni Vigna. 2019. Toward the Analysis of Embedded Firmware through Automated Re-hosting. In RAID 2019. 135--150."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134050"},{"key":"e_1_3_2_1_21_1","unstructured":"Intel. 2016. Intel 64 and IA-32 Architectures Software Developer's Manual. https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/manuals\/64-ia-32-architectures-software-developer-vol-3c-part-3-manual.pdf. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_22_1","volume-title":"Jetset: Targeted Firmware Rehosting for Embedded Systems. In 30th USENIX Security Symposium.","author":"Johnson Evan","year":"2021","unstructured":"Evan Johnson, Maxwell Bland, YiFei Zhu, Joshua Mason, Stephen Checkoway, Stefan Savage, and Kirill Levchenko. 2021. Jetset: Targeted Firmware Rehosting for Embedded Systems. In 30th USENIX Security Symposium."},{"key":"e_1_3_2_1_23_1","unstructured":"Kate Temkin Mikaela Szekely. 2020. Facedancer. https:\/\/github.com\/usb-tools\/Facedancer. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_24_1","volume-title":"SURROGATES: Enabling Near-Real-Time Dynamic Analyses of Embedded Systems. In 9th USENIX Workshop on Offensive Technologies (WOOT'15)","author":"Koscher Karl","year":"2015","unstructured":"Karl Koscher, Tadayoshi Kohno, and David Molnar. 2015. SURROGATES: Enabling Near-Real-Time Dynamic Analyses of Embedded Systems. In 9th USENIX Workshop on Offensive Technologies (WOOT'15). Washington, D.C."},{"key":"e_1_3_2_1_25_1","first-page":"1","article-title":"Using CoreSight PTM to Integrate CRA Monitoring IPs in an ARM-Based SoC","volume":"22","author":"Lee Yongje","year":"2017","unstructured":"Yongje Lee, Jinyong Lee, Ingoo Heo, Dongil Hwang, and Yunheung Paek. 2017. Using CoreSight PTM to Integrate CRA Monitoring IPs in an ARM-Based SoC. ACM Transactions on Design Automation of Electronic Systems (TODAES) 22, 3 (2017), 1--25.","journal-title":"ACM Transactions on Design Automation of Electronic Systems (TODAES)"},{"key":"e_1_3_2_1_26_1","unstructured":"MarketWatch Inc. 2022. IoT Microcontroller (MCU) Market Size 2021 Global Trend Top Manufacturers Regions Analysis and Leading 20 Countries and Forecast by 2027. https:\/\/www.marketwatch.com\/press-release\/iot-microcontroller-mcu-market-in-2022-113-cagr-with-top-countries-data-what-would-be-the-size-of-iot-microcontroller-mcu-industry-in-2027-latest-126-pages-report-2022-01-16. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_27_1","volume-title":"DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis. In 2021 IEEE Symposium on Security and Privacy (SP)","author":"Mera A.","unstructured":"A. Mera, B. Feng, L. Lu, and E. Kirda. 2021. DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis. In 2021 IEEE Symposium on Security and Privacy (SP). Los Alamitos, CA, USA, 302--318."},{"key":"e_1_3_2_1_28_1","unstructured":"Michal Zalewski. 2021. Technical \"whitepaper\" for afl-fuzz. https:\/\/lcamtuf.coredump.cx\/afl\/technical_details.txt. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_29_1","volume-title":"Linux Symposium.","author":"Milenkovic Milena","year":"2008","unstructured":"Milena Milenkovic, Scott Jones, Frank Levine, and Enio Pineda. 2008. Performance inspector tools with instruction tracing and per-thread\/function profiling. In Linux Symposium."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2018.23017"},{"key":"e_1_3_2_1_31_1","unstructured":"Nguyen Anh Quynh. 2021. Capstone Engine. https:\/\/github.com\/aquynh\/capstone. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_32_1","volume-title":"Ninja: Towards Transparent Tracing and Debugging on ARM. In 26th USENIX Security Symposium (USENIX Security 17)","author":"Ning Zhenyu","year":"2017","unstructured":"Zhenyu Ning and Fengwei Zhang. 2017. Ninja: Towards Transparent Tracing and Debugging on ARM. In 26th USENIX Security Symposium (USENIX Security 17). 33--49."},{"key":"e_1_3_2_1_33_1","volume-title":"CAUAP: Crypto Acceleration Unit","author":"Semiconductors NXP","year":"2021","unstructured":"NXP Semiconductors. 2021. CAUAP: Crypto Acceleration Unit (CAU) and MmCAU Software Library. https:\/\/www.nxp.com\/design\/development-boards\/tower-development-boards\/mcu-and-processor-modules\/kinetis-modules\/crypto-acceleration-unit-cau-and-mmcau-software-library:CAUAP. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_34_1","unstructured":"NXP Semiconductors. 2021. NXP Semiconductors Official Site. https:\/\/www.nxp.com\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_35_1","unstructured":"ONE Tech. 2020. WiFi Vulnerabilities on ESP32\/ESP8266 IoT Devices. https:\/\/www.onetech.ai\/en\/blog\/wifi-vulnerabilities-on-esp32-esp8266-iot-devices. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_36_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Peng Hui","year":"2020","unstructured":"Hui Peng and Mathias Payer. 2020. USBFuzz: A Framework for Fuzzing USB Drivers by Device Emulation. In 29th USENIX Security Symposium (USENIX Security 20). 2559--2575."},{"key":"e_1_3_2_1_37_1","unstructured":"SEGGER. 2021. J-Link RTT - Real Time Transfer. https:\/\/www.segger.com\/products\/debug-probes\/j-link\/technology\/about-real-time-transfer\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_38_1","unstructured":"SEGGER Microcontroller. 2022. J-Link SDK - Integrate J-Link Support into Applications. https:\/\/www.segger.com\/products\/debug-probes\/j-link\/technology\/j-link-sdk\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_39_1","unstructured":"SEGGER Microcontroller. 2022. J-Trace PRO --- The leading trace solution. https:\/\/www.segger.com\/products\/debug-probes\/j-trace\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_40_1","volume-title":"2012 USENIX Annual Technical Conference (USENIX ATC 12)","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In 2012 USENIX Annual Technical Conference (USENIX ATC 12). 309--318."},{"key":"e_1_3_2_1_41_1","unstructured":"SFUPTOWNMAKER. 2022. PCB Basics. https:\/\/learn.sparkfun.com\/tutorials\/pcb-basics\/all. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_42_1","unstructured":"STMicroelectronics. 2021. STMicroelectronics: Home. https:\/\/www.st.com\/content\/st_com\/en.html. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_43_1","volume-title":"Jiameng Shi and Fengjun Li","author":"Li Wenqiang","year":"2021","unstructured":"Wenqiang Li, Le Guan, Jingqiang Lin, Jiameng Shi and Fengjun Li. 2021. From Library Portability to Para-rehosting: Natively Executing Open-source Microcontroller OSs on Commodity Hardware. In NDSS 2021."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01351925"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"},{"key":"e_1_3_2_1_46_1","unstructured":"Michal Zalewski. 2010. American Fuzzy Lop. http:\/\/lcamtuf.coredump.cx\/afl\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_47_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Zhou Wei","year":"2021","unstructured":"Wei Zhou, Le Guan, Peng Liu, and Yuqing Zhang. 2021. Automatic Firmware Emulation through Invalidity-guided Knowledge Inference. In 30th USENIX Security Symposium (USENIX Security 21)."},{"key":"e_1_3_2_1_48_1","unstructured":"ZIMPERIUM. 2018. FreeRTOS TCP\/IP Stack Vulnerabilities Put A Wide Range of Devices at Risk of Compromise: From Smart Homes to Critical Infrastructure Systems. https:\/\/blog.zimperium.com\/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems\/. (Retrieved: 2022-01-24)."},{"key":"e_1_3_2_1_49_1","unstructured":"ZIMPERIUM. 2018. FreeRTOS TCP\/IP Stack Vulnerabilities - The Details. https:\/\/blog.zimperium.com\/freertos-tcpip-stack-vulnerabilities-details\/. (Retrieved: 2022-01-24)."}],"event":{"name":"ICSE '22: 44th International Conference on Software Engineering","location":"Pittsburgh Pennsylvania","acronym":"ICSE '22","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS"]},"container-title":["Proceedings of the 44th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3510003.3510208","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3510003.3510208","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3510003.3510208","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:12:24Z","timestamp":1750191144000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3510003.3510208"}},"subtitle":["non-intrusive feedback-driven fuzzing for microcontroller firmware"],"short-title":[],"issued":{"date-parts":[[2022,5,21]]},"references-count":49,"alternative-id":["10.1145\/3510003.3510208","10.1145\/3510003"],"URL":"https:\/\/doi.org\/10.1145\/3510003.3510208","relation":{},"subject":[],"published":{"date-parts":[[2022,5,21]]},"assertion":[{"value":"2022-07-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}