A Novel Mutation Based Method for Detecting FPGA Logic Synthesis Tool Bugs

📅 2025-08-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
FPGA logic synthesis tools harbor latent vulnerabilities, yet existing testing approaches suffer from low vulnerability detection rates due to insufficient semantic richness and logical complexity in test programs. This paper proposes VERMEI, an automated vulnerability mining framework targeting synthesis tools. Its core innovation lies in (1) introducing “zombie logic regions” as equivalence-preserving mutation sources, and (2) leveraging Bayesian sampling over historical designs to extract highly reusable logic fragments, enabling generation of test variants with intricate control flow and rich semantics. VERMEI then identifies zombie logic via simulation and localizes vulnerabilities via differential comparison of synthesis outputs. Evaluated on Yosys, Vivado, and Quartus, VERMEI discovered 15 vulnerabilities within five months—nine confirmed by vendors as previously unknown—demonstrating substantial improvement over state-of-the-art methods.

Technology Category

Application Category

📝 Abstract
FPGA (Field-Programmable Gate Array) logic synthesis tools are key components in the EDA (Electronic Design Automation) toolchain. They convert hardware designs written in description languages such as Verilog into gate-level representations for FPGAs. However, defects in these tools may lead to unexpected behaviors and pose security risks. Therefore, it is crucial to harden these tools through testing. Although several methods have been proposed to automatically test FPGA logic synthesis tools, the challenge remains of insufficient semantic and logical complexity in test programs. In this paper, we propose VERMEI, a new method for testing FPGA logic synthesis tools. VERMEI consists of three modules: preprocessing, equivalent mutation, and bug identification. The preprocessing module identifies zombie logic (inactive code with no impact on the circuit output) in seed programs through simulation and coverage analysis. The equivalent mutation module generates equivalent variants of seed programs by pruning or inserting logic fragments in zombie areas. It uses Bayesian sampling to extract logic fragments from historical Verilog designs, making the generated variants have complex control flows and structures. The bug identification module, based on differential testing, compares the synthesized outputs of seed and variant programs to identify bugs. Experiments on Yosys, Vivado, and Quartus demonstrate that VERMEI outperforms the state-of-the-art methods. Within five months, VERMEI reported 15 bugs to vendors, 9 of which were confirmed as new.
Problem

Research questions and friction points this paper is trying to address.

Detects bugs in FPGA logic synthesis tools
Addresses insufficient semantic complexity in test programs
Identifies tool defects through equivalent mutation generation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Mutation-based testing with Bayesian sampling
Zombie logic identification via simulation analysis
Differential testing for bug identification
🔎 Similar Papers
No similar papers found.
Y
Yi Zhang
School of Computer Science, Beijing Institute of Technology, Beijing 100081, China
H
He Jiang
School of Computer Science, Beijing Institute of Technology, Beijing 100081, China, and also with the School of Software, Dalian University of Technology, Dalian 116024, China
X
Xiaochen Li
School of Software, Dalian University of Technology, Dalian 116024, China, and also with the Key Laboratory for Ubiquitous Network and Service Software of Liaoning Province, Dalian 116024, China
Shikai Guo
Shikai Guo
Associate Professor, Dalian Maritime University
AI for EDAFPGA Logical SynthesisPlacement & RoutingCompile OptimizationSoftware Engineering
P
Peiyu Zou
School of Software, Dalian University of Technology, Dalian 116024, China, and also with the Key Laboratory for Ubiquitous Network and Service Software of Liaoning Province, Dalian 116024, China
Z
Zun Wang
School of Software, Dalian University of Technology, Dalian 116024, China, and also with the Key Laboratory for Ubiquitous Network and Service Software of Liaoning Province, Dalian 116024, China