Systematic exploration beyond attack-template microarchitectural fuzzing

Develop systematic approaches for exploring the microarchitectural state space beyond template-based fuzzing centered on known side-channel and transient-execution attacks, with the goal of uncovering entirely new microarchitectural failure modes.

Background

The paper observes that existing microarchitectural fuzzers are predominantly attack-driven: they are designed around known Spectre- and Meltdown-style templates and therefore tend to discover variants within established vulnerability classes. The authors identify the limited reach of this strategy as a barrier to finding novel classes of microarchitectural failures.

The unresolved problem is to move from template-based testing toward systematic exploration of the broader microarchitectural state space, despite the limited observability of black-box commodity processors and the difficulty of defining suitable feedback and reference models.

References

Moving beyond template-based approaches toward systematic exploration of the $ itectural state space remains an open challenge.

SoK: ARCUS: On the Efficiency and Efficacy of Hardware Fuzzing  (2608.23933 - Murali et al., 25 Aug 2026) in Section 6, “Cross-cutting Insights and Opportunities,” subsection “Attack-Driven $ itectural Fuzzing”