POZZER: A Power Side Channel-guided Fuzzer for Black-Box Embedded Systems

📅 2026-09-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
POZZER利用功耗侧信道指导黑盒嵌入式系统的模糊测试,通过构建执行图识别新行为,无需固件知识或克隆设备,有效发现漏洞。
📝 Abstract
Firmware fuzzing is an effective technique for discovering vulnerabilities in embedded systems. However, existing coverage-guided firmware fuzzers typically obtain feedback through firmware instrumentation, hardware debug interfaces, or firmware rehosting, which requires access to the firmware source code or binary image. Such requirements are often infeasible for off-the-shelf embedded devices, where firmware binaries are inaccessible, unrehostable, immodifiable, or undebuggable, necessitating fuzzing under black-box conditions. In this paper, we present POZZER, a power side-channel-guided fuzzer for black-box embedded systems. POZZER uses power traces as feedback to identify previously unseen behavior via an incrementally constructed graph-based representation of observed executions, guiding the fuzzer toward unexplored execution paths. Its non-profiling design requires neither prior firmware knowledge nor a clone device, extracting meaningful feedback from a single power trace per execution while remaining robust to measurement noise. We evaluate POZZER on 15 firmware targets across two platforms and two real-world commercial embedded devices. Across the resulting target-platform combinations, POZZER outperforms a blind fuzzer under the same time budget in 26 out of 30 target-platform combinations. Furthermore, POZZER discovers two previously unknown vulnerabilities in one of the commercial devices, both confirmed by the vendor, demonstrating its potential for identifying vulnerabilities in black-box embedded systems.
Problem

Research questions and friction points this paper is trying to address.

black-box embedded systems
firmware fuzzing
power side channel
Innovation

Methods, ideas, or system contributions that make the work stand out.

power side-channel
black-box embedded systems
graph-based representation
non-profiling design
vulnerability discovery
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Pouya Narimani
Pouya Narimani
CISPA Helmholtz Center for Information Security
K
Kseniia Rogova
CISPA Helmholtz Center for Information Security
A
Addison Crump
CISPA Helmholtz Center for Information Security
M
Martin Mohl
CISPA Helmholtz Center for Information Security
M
Meng Wang
CISPA Helmholtz Center for Information Security
U
Ulysse Planta
CISPA Helmholtz Center for Information Security
P
Pansilu Pitigalaarachchi
CISPA Helmholtz Center for Information Security
Ali Abbasi
Ali Abbasi
Faculty, CISPA Helmholtz Center for Information Security
Embedded SecurityFirmware SecuritySpace Cybersecurity