{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T17:55:12Z","timestamp":1773510912426,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765086","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:42:02Z","timestamp":1763854922000},"page":"2609-2623","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["<scp>FlexEmu:<\/scp>\n                    Towards Flexible MCU Peripheral Emulation"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-4737-9732","authenticated-orcid":false,"given":"Chongqing","family":"Lei","sequence":"first","affiliation":[{"name":"Southeast University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9691-8702","authenticated-orcid":false,"given":"Zhen","family":"Ling","sequence":"additional","affiliation":[{"name":"Southeast University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1628-906X","authenticated-orcid":false,"given":"Xiangyu","family":"Xu","sequence":"additional","affiliation":[{"name":"Southeast University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1491-4319","authenticated-orcid":false,"given":"Shaofeng","family":"Li","sequence":"additional","affiliation":[{"name":"Southeast University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4588-3196","authenticated-orcid":false,"given":"Guangchi","family":"Liu","sequence":"additional","affiliation":[{"name":"Southeast University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3156-9035","authenticated-orcid":false,"given":"Kai","family":"Dong","sequence":"additional","affiliation":[{"name":"Southeast University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7518-4367","authenticated-orcid":false,"given":"Junzhou","family":"Luo","sequence":"additional","affiliation":[{"name":"Southeast University, Nanjing, Jiangsu, China and Fuyao University of Science and Technology, Fuzhou, Fujian, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of the 2005 USENIX Annual Technical Conference (USENIX ATC).","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard. 2005. QEMU, a Fast and Portable Dynamic Translator. In Proceedings of the 2005 USENIX Annual Technical Conference (USENIX ATC)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427280"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security).","author":"Chesser Michael","unstructured":"Michael Chesser, Surya Nepal, and Damith C. Ranasinghe. 2024. MultiFuzz: A Multi-Stream Fuzzer For Testing Monolithic Firmware. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security).","author":"Clements Abraham A","year":"2020","unstructured":"Abraham A Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020. HALucinator: Firmware Re-hosting Through Abstraction Layer Emulation. In Proceedings of the 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security).","author":"Corteggiani Nassim","year":"2018","unstructured":"Nassim Corteggiani, Giovanni Camurati, and Aur\u00e9lien Francillon. 2018. Inception: System-Wide Security Testing of Real-World Embedded Systems Software. In Proceedings of the 27th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the 22nd USENIX Security Symposium (USENIX Security).","author":"Davidson Drew","year":"2013","unstructured":"Drew Davidson, Benjamin Moench, Thomas Ristenpart, and Somesh Jha. 2013. FIE on Firmware: Finding Vulnerabilities in Embedded Systems Using Symbolic Execution. In Proceedings of the 22nd USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453093"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security).","author":"Feng Bo","year":"2020","unstructured":"Bo Feng, Alejandro Mera, and Long Lu. 2020. P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface Modeling. In Proceedings of the 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560602"},{"key":"e_1_3_2_1_11_1","unstructured":"Dennis Giese. 2018. Having fun with IoT: Reverse Engineering and Hacking of Xiaomi IoT Devices. https:\/\/dontvacuum.me\/talks\/DEFCON26\/DEFCON26-Having_fun_with_IoT-Xiaomi.pdf"},{"key":"e_1_3_2_1_12_1","unstructured":"Google Gemini Team. 2024. Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context. https:\/\/arxiv.org\/abs\/2403.05530"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID).","author":"Gustafson Eric","year":"2019","unstructured":"Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aur\u00e9lien Francillon, Yung Ryn Choe, Christophe Kruegel, and Giovanni Vigna. 2019. Toward the Analysis of Embedded Firmware through Automated Re-hosting. In Proceedings of the 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID)."},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security).","author":"Harrison Lee","year":"2020","unstructured":"Lee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen, and Michael Grace. 2020. PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation. In Proceedings of the 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS).","author":"Hernandez Grant","unstructured":"Grant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz, and Kevin R. B. Butler. 2017. FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic Execution. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 29th Annual Network and Distributed System Security Symposium (NDSS).","author":"Hernandez Grant","unstructured":"Grant Hernandez, Marius Muench, Dominik Maier, Alyssa Milburn, Shinjo Park, Tobias Scharnowski, Tyler Tucker, Patrick Traynor, and Kevin R. B. Butler. 2022. FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware. In Proceedings of the 29th Annual Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2024.23011"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484753"},{"key":"e_1_3_2_1_19_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security).","author":"Johnson Evan","year":"2021","unstructured":"Evan Johnson, Maxwell Bland, YiFei Zhu, Joshua Mason, Stephen Checkoway, Stefan Savage, and Kirill Levchenko. 2021. Jetset: Targeted Firmware Rehosting for Embedded Systems. In Proceedings of the 30th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_20_1","volume-title":"FirmAE: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis. In In Proceedings of the 36th Annual Computer Security Applications Conference (ACSAC).","author":"Kim Mingeun","year":"2020","unstructured":"Mingeun Kim, Dongkwan Kim, Eunsoo Kim, Suryeon Kim, Yeongjin Jang, and Yongdae Kim. 2020. FirmAE: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis. In In Proceedings of the 36th Annual Computer Security Applications Conference (ACSAC)."},{"key":"e_1_3_2_1_21_1","unstructured":"Kitware. [n.d.]. CMake: A Powerful software build system. https:\/\/cmake.org"},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the 2021 BlackHat USA (BHUSA).","author":"Komaromy Daniel","year":"2021","unstructured":"Daniel Komaromy and Lorant Szabo. 2021. How To Tame Your Unicorn - Exploring and Exploiting Zero-Click Remote Interfaces of Modern Huawei Smartphones. In Proceedings of the 2021 BlackHat USA (BHUSA)."},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 9th USENIX Workshop on Offensive Technologies (WOOT).","author":"Koscher Karl","year":"2015","unstructured":"Karl Koscher, Tadayoshi Kohno, and David Molnar. 2015. SURROGATES: Enabling Near-Real-Time Dynamic Analyses of Embedded Systems. In Proceedings of the 9th USENIX Workshop on Offensive Technologies (WOOT)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2004.1281665"},{"key":"e_1_3_2_1_25_1","unstructured":"Chongqing Lei Zhen Ling Xiangyu Xu Shaofeng Li Guangchi Liu Kai Dong and Junzhou Luo. 2025. FlexEmu: Towards Flexible MCU Peripheral Emulation (Extended Version). https:\/\/arxiv.org\/abs\/2509.07615"},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security).","author":"Lei Chongqing","year":"2024","unstructured":"Chongqing Lei, Zhen Ling, Yue Zhang, Yan Yang, Junzhou Luo, and Xinwen Fu. 2024. A Friend's Eye is A Good Mirror: Synthesizing MCU Peripheral Models from Peripheral Drivers. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.818"},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 28th Network and Distributed System Security Symposium (NDSS).","author":"Li Wenqiang","year":"2021","unstructured":"Wenqiang Li, Le Guan, Jingqiang Lin, Jiameng Shi, and Fengjun Li. 2021. From Library Portability to Para-rehosting: Natively Executing Open-source Microcontroller OSs on Commodity Hardware. In Proceedings of the 28th Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510208"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2707465"},{"key":"e_1_3_2_1_31_1","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security).","author":"Liu Changming","year":"2024","unstructured":"Changming Liu, Alejandro Mera, Engin Kirda, Meng Xu, and Long Lu. 2024. CO3: Concolic Co-execution for Firmware. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678653"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395351.3399360"},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of the 42nd IEEE Symposium on Security and Privacy (S&P).","author":"Mera Alejandro","year":"2020","unstructured":"Alejandro Mera, Bo Feng, Long Lu, and Engin Kirda. 2020. DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis. In Proceedings of the 42nd IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security).","author":"Mera Alejandro","year":"2024","unstructured":"Alejandro Mera, Changming Liu, Ruimin Sun, Engin Kirda, and Long Lu. 2024. SHiFT: Semi-hosted Fuzz Testing for Embedded Applications. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_36_1","unstructured":"Mynewt. 2025. Apache Mynewt. https:\/\/mynewt.apache.org"},{"key":"e_1_3_2_1_37_1","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security).","author":"Nino Nicolas","year":"2024","unstructured":"Nicolas Nino, Wei Zhou, Kyu Hyung Lee, Ziming Zhao, and Le Guan. 2024. Unveiling IoT Security in Reality: A Firmware-Centric Journey. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_38_1","unstructured":"NuttX. 2025. Apache NuttX. https:\/\/nuttx.apache.org"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 2012 USENIX conference on Annual Technical Conference (ATC).","author":"Bruening Derek","year":"2012","unstructured":"onstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitry Vyukov. 2012. AddressSanitizer: A Fast Address Sanity Checker. In Proceedings of the 2012 USENIX conference on Annual Technical Conference (ATC)."},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the 2015 BlackHat USA (BHUSA).","author":"Quynh Nguyen Anh","year":"2015","unstructured":"Nguyen Anh Quynh and Dang Hoang Vu. 2015. Unicorn: Next Generation CPU Emulator Framework. In Proceedings of the 2015 BlackHat USA (BHUSA)."},{"key":"e_1_3_2_1_41_1","volume-title":"KARONTE: Detecting Insecure Multi-binary Interactions in Embedded Firmware. In In Proceedings of the 41st IEEE Symposium on Security and Privacy (S&P).","author":"Redini Nilo","year":"2020","unstructured":"Nilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky, Andrea Continella, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2020. KARONTE: Detecting Insecure Multi-binary Interactions in Embedded Firmware. In In Proceedings of the 41st IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_42_1","unstructured":"rizsotto. 2025. Bear. https:\/\/github.com\/rizsotto\/Bear"},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security).","author":"Ruge Jan","year":"2020","unstructured":"Jan Ruge, Jiska Classen, Francesco Gringoli, and Matthias Hollick. 2020. Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets. In Proceedings of the 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_44_1","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security).","author":"Scharnowski Tobias","year":"2022","unstructured":"Tobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson, Marius Muench, Giovanni Vigna, Christopher Kruegel, Thorsten Holz, and Ali Abbasi. 2022. Fuzzware: Using Precise MMIO Modeling for Effective Firmware Fuzzing. In Proceedings of the 31st USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the 32nd USENIX Security Symposium (USENIX Security).","author":"Scharnowski Tobias","year":"2023","unstructured":"Tobias Scharnowski, Simon W\u00f6rner, Felix Buchmann, Nils Bars, Moritz Schloegel, and Thorsten Holz. 2023. HOEDUR: Embedded firmware fuzzing using multi-stream inputs. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620400"},{"key":"e_1_3_2_1_47_1","unstructured":"Philips Semiconductors. 2025. I2C MANUAL. https:\/\/www.nxp.com\/docs\/en\/application-note\/AN10216.pdf"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23116"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23294"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3437532"},{"key":"e_1_3_2_1_51_1","unstructured":"The Clang Team. 2025. JSON Compilation Database Format Specification. https:\/\/clang.llvm.org\/docs\/JSONCompilationDatabase.html"},{"key":"e_1_3_2_1_52_1","unstructured":"The Clang Team. 2025. LibTooling. https:\/\/clang.llvm.org\/docs\/LibTooling.html"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"},{"key":"e_1_3_2_1_54_1","unstructured":"Zephyr. 2025. Zephyr Project. https:\/\/www.zephyrproject.org"},{"key":"e_1_3_2_1_55_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security).","author":"Zhou Wei","year":"2021","unstructured":"Wei Zhou, Le Guan, Peng Liu, and Yuqing Zhang. 2021. Automatic Firmware Emulation through Invalidity-guided Knowledge Inference. In Proceedings of the 30th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi17010019"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559386"}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765086","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:30:22Z","timestamp":1766442622000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765086"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":57,"alternative-id":["10.1145\/3719027.3765086","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765086","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}