Score
Designs, configures, and operates hardware emulation platforms and environments to prototype, validate, and verify hardware designs; this includes creating emulation workflows, performing emulation bring-up, debugging emulated behavior, and integrating emulators with other hardware and software testbeds. Develops emulation methodology, conducts emulation validation and verification, and uses emulation to prototype and analyze system behavior prior to or in place of physical hardware.
Traditional simulation and formal verification struggle to effectively uncover security vulnerabilities in system-on-chip (SoC) designs under realistic hardware-software interactions and adversarial scenarios. This work proposes the first security-oriented hardware emulation validation framework, integrating assertion checking, coverage-driven exploration, adversarial testing, information flow tracking, fault injection, and side-channel analysis, while introducing security-aware coverage metrics. The established workflow encompasses instrumentation, stimulus generation, runtime monitoring, and forensic analysis, positioning hardware emulation as a foundational pre-silicon methodology for addressing security challenges in heterogeneous SoCs and third-party intellectual property. The paper further outlines forward-looking directions, including AI-assisted emulation, digital security twins, and chiplet-level security exploration.
QEMU’s cross-architecture emulation suffers severe performance degradation—up to 35× slowdown—due to the overhead of the Tiny Code Generator (TCG) intermediate representation (IR). Method: We propose a novel direct binary translation (DBT) paradigm that bypasses TCG entirely. Our approach introduces a three-tier collaborative engine architecture (KVM/DBT/TCG), implements an IR-free translation prototype, and supports instruction-set mapping across major architectures (RISC-V, x86, ARM) with Linux KVM-aware scheduling. Contribution/Results: We present the first systematic quantification of TCG’s runtime overhead and introduce a configurable “intermediate direct translation layer” enabling dynamic trade-offs between development effort and performance. Evaluation shows up to 35× speedup over standard QEMU TCG, empirically validating the feasibility and effectiveness of IR-free cross-architecture binary translation.
To address critical challenges in SoC design—including ambiguous system-level modeling semantics, poor interoperability across heterogeneous computational models (e.g., dataflow and neural networks), and the decoupling of design-space exploration from verification—this paper proposes a co-communication mechanism ensuring semantic consistency across multiple models. The approach establishes an integrated toolchain supporting system-level modeling, simulation-driven verification, hardware-software co-design space exploration, and joint power-performance analysis. Innovatively, it unifies dataflow modeling with system-level abstractions to enable functional correctness verification and quantitative energy-efficiency evaluation for representative applications such as video processing and AI acceleration. Experimental results demonstrate that the methodology significantly improves early-stage SoC design iteration efficiency and enhances the reliability of architectural decision-making.
This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.
To address the challenges of heterogeneity, fragmented resources, and inefficient collaboration in embedded-system virtual-prototype simulation tools, this paper proposes SUNRISE—a scalable infrastructure for distributed simulation. SUNRISE introduces the Simulation Adapter Abstraction Layer (SAAL), a novel abstraction enabling plug-and-play integration of seven major commercial and open-source simulators. It leverages lightweight containerization (Docker/Kubernetes) and a RESTful microservice architecture to dynamically orchestrate simulation tasks across decentralized computing resources. An open API gateway is designed to facilitate cross-organizational collaboration. Experimental evaluation demonstrates that SUNRISE reduces simulation-task deployment latency by 62%, improves cross-organizational collaboration efficiency by 3×, and achieves a 99.8% API call success rate.
This study addresses the inherent challenge in hardware design of balancing complexity management with model accuracy. To this end, it proposes an abstraction-centric methodology that associates discretization techniques with pre-clustered elements, such as transistors. By integrating lumped modeling, value discretization, and time discretization, the approach establishes a well-defined hierarchy of abstractions. The primary contribution of this work is a standardized design methodology that enhances productivity by simplifying model complexity and improving simulation efficiency while defining effective constraints. Consequently, this framework significantly strengthens the capacity to manage complex systems in digital design, thereby advancing overall engineering productivity.
This study addresses the limitations of existing evaluation datasets for firmware analysis tools and the lack of a holistic understanding of component interactions. To this end, it constructs the first unified automated analysis pipeline, leveraging the large-scale OTACAP and FirmLine datasets to systematically evaluate the collaborative mechanisms and stage-wise output support capabilities of 24 emulation-based analysis tools. By integrating fuzzing, code coverage analysis, and error diagnosis techniques, the investigation reveals that only 34.5% of samples can be successfully fuzzed, with generally low code coverage achieved. These findings expose fundamental deficiencies in current methodologies, providing empirical evidence and actionable directions for optimizing firmware analysis techniques.
为解决DevOps程序测试耗时、不安全和成本高的问题,本文提出CloudEmu,通过神经符号代码合成自动生成云模拟器。
本文提出了一种基于大型语言模型的行为驱动硬件开发流程,通过定义形式验证Gherkin场景来减少自然语言规范的模糊性,提高硬件设计的形式验证效果。
Dynamic analysis of Android applications at the application layer has long been constrained by reliance on physical devices, suffering from poor scalability and limited reproducibility. This work proposes a systematic rehosting approach that migrates Android framework components and preinstalled vendor binaries from real-world firmware into a fully emulated environment. By employing tailored extraction and injection strategies, these components are seamlessly integrated into the AOSP build system to produce bootable emulator images that preserve system integrity and runtime compatibility. The method enables, for the first time, large-scale rehosting of vendor-customized Android firmware in QEMU across multiple SDK versions (31–33). Evaluation on 184 firmware samples demonstrates high success rates in both image construction and booting, with only a few failures attributable to missing dependencies or emulator limitations, thereby validating the feasibility and effectiveness of this approach for scalable and reproducible dynamic analysis.