Score
Designs and builds software or hardware systems that replicate the functional and timing behavior of another system so that code, protocols, or workloads can run unchanged; this includes creating emulators, virtual machines, instruction or binary translators, and hardware/firmware simulators. Analyzes and validates emulation fidelity, performance, compatibility, and resource mapping, and implements techniques for accurate state capture, device modeling, synchronization, and correctness testing.
This work addresses the limitations of existing hybrid simulation tools, which often rely on vendor-specific FPGA solutions and lack open-source support, thereby hindering early validation of complex cyber-physical systems requiring efficient and precise timing modeling. The paper presents the first open-source, vendor-agnostic SystemC-FPGA tightly coupled co-simulation framework, seamlessly integrating FPGA hardware acceleration with a SystemC virtual platform via a JTAG interface. A custom synchronization wrapper is introduced to enable cycle-accurate coordination between software and hardware components. Demonstrated on a RISC-V SoC for biosignal processing, the framework achieves a 2,500× speedup over RTL simulation while keeping total simulation time within twice that of pure FPGA-based simulation, effectively balancing speed, timing accuracy, and portability at the full-system level.
QEMU’s cross-architecture emulation suffers severe performance degradation—up to 35× slowdown—due to the overhead of the Tiny Code Generator (TCG) intermediate representation (IR). Method: We propose a novel direct binary translation (DBT) paradigm that bypasses TCG entirely. Our approach introduces a three-tier collaborative engine architecture (KVM/DBT/TCG), implements an IR-free translation prototype, and supports instruction-set mapping across major architectures (RISC-V, x86, ARM) with Linux KVM-aware scheduling. Contribution/Results: We present the first systematic quantification of TCG’s runtime overhead and introduce a configurable “intermediate direct translation layer” enabling dynamic trade-offs between development effort and performance. Evaluation shows up to 35× speedup over standard QEMU TCG, empirically validating the feasibility and effectiveness of IR-free cross-architecture binary translation.
This study addresses whether a programming language can fully simulate its own execution without support from a host interpreter or compiler, arguing that Turing completeness alone is insufficient to faithfully reproduce runtime behaviors such as control flow, exceptions, callbacks, and memory usage. To this end, the paper introduces the notion of “simulation completeness,” distinguishing between source-level and compiled-code-level simulation and defining both weak and strong forms. It establishes a dual framework of requirements from both the language and simulator perspectives. Through conceptual modeling, semantic analysis, and empirical investigation using languages like Erlang, the work develops the first formal classification system and structured terminology in this domain, offering theoretical foundations and practical guidance for language design, secure sandboxing, decompilation, and reflective execution.
This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.
Dynamic security analysis of MCU firmware faces significant challenges in constructing scalable, high-fidelity emulation environments due to the extreme heterogeneity of peripheral hardware. Method: This paper proposes FlexEmu, a novel framework that abstracts MCU peripheral hardware implementations into a set of finite structural primitives and establishes a unified semantic model to capture functional equivalence across peripheral classes, enabling automated peripheral modeling and emulator generation. FlexEmu achieves high-fidelity emulation through structural primitive extraction, semantic-driven configuration parsing, and behavior-aware simulation. Results: Evaluated across 12 peripheral types, 15 MCU platforms, and 90 firmware samples, FlexEmu achieves a unit test pass rate of 98.48%. Integrated with fuzz testing, it discovers 10 previously unknown vulnerabilities across three mainstream RTOSes. FlexEmu substantially enhances both the practicality and scalability of dynamic firmware analysis.
本文通过将Paxos协议的伪代码转化为可执行的DistAlgo语言,解决了分布式系统中复制与共识协议的理解和验证问题。
This study addresses the limitations of existing evaluation datasets for firmware analysis tools and the lack of a holistic understanding of component interactions. To this end, it constructs the first unified automated analysis pipeline, leveraging the large-scale OTACAP and FirmLine datasets to systematically evaluate the collaborative mechanisms and stage-wise output support capabilities of 24 emulation-based analysis tools. By integrating fuzzing, code coverage analysis, and error diagnosis techniques, the investigation reveals that only 34.5% of samples can be successfully fuzzed, with generally low code coverage achieved. These findings expose fundamental deficiencies in current methodologies, providing empirical evidence and actionable directions for optimizing firmware analysis techniques.
This work addresses the long-standing lack of systematic validation for processor specifications, which can lead to distorted program behavior and security vulnerabilities. It presents the first automated differential testing framework tailored for open-source SLEIGH specifications, automatically generating decodable instructions and initial execution states by parsing specification structures, and systematically validating them against multiple hardware reference implementations across architectures. Applied to x86-64 and AArch64, the approach uncovered 38,920 semantic discrepancies, identified 125 unique defects—many of which were subsequently fixed—and significantly improved specification fidelity. Furthermore, it exposed inconsistencies across vendor implementations and led to eight concrete recommendations, establishing a new paradigm for ensuring the reliability of instruction set architecture specifications.
This study addresses the issue of false rejections of valid hardware designs caused by cycle-level matching in design verification. To overcome this, we propose BEAVE, a framework that enables multi-round co-design and verification through behavioral models. The core innovation lies in introducing a Behavior Intermediate Representation (IR) to decouple functionality from timing, thereby constructing a verifiable reinforcement learning reward mechanism without requiring reference RTL. Furthermore, by integrating random sampling with solver-guided search, the framework supports PPA exploration and self-improvement. Experimental results demonstrate that this approach increases the RTL pass@1 rate of Qwen3.8-27B from 55% to 75%, achieving performance comparable to reinforcement learning conducted on large-scale task pools.
This study addresses the inherent challenge in hardware design of balancing complexity management with model accuracy. To this end, it proposes an abstraction-centric methodology that associates discretization techniques with pre-clustered elements, such as transistors. By integrating lumped modeling, value discretization, and time discretization, the approach establishes a well-defined hierarchy of abstractions. The primary contribution of this work is a standardized design methodology that enhances productivity by simplifying model complexity and improving simulation efficiency while defining effective constraints. Consequently, this framework significantly strengthens the capacity to manage complex systems in digital design, thereby advancing overall engineering productivity.