Andy Kai Zheng
MIT EECS | Analog Devices Undergraduate Research and Innovation Scholar
Developing a CPU Vulnerability Bug-Printing Machine
2026–2027
Electrical Engineering and Computer Science; Mathematics
- Computer Architecture
Mengjia Yan
CPU’s provide isolation mechanisms such as virtualization and privilege levels to protect software. However, these mechanisms often overlook microarchitectural side channels, introducing vulnerabilities and bugs. These bugs can have devastating consequences and can be exploited to leak data across security boundaries. Current approaches for uncovering CPU bugs do exist, but they have significant limitations. Some are painfully manual and error-prone, relying on researchers to handcraft ad-hoc microarchitectural patches and reason theoretically about whether mitigations are complete. Other approaches typically operate only within a single security domain and cannot detect vulnerabilities exploitable in real-world isolation boundaries. Recent work demonstrates that the detection of CPU vulnerabilities can be automated by extending model-based relational testing across security domains.
This SuperUROP project will build on and extend this automated methodology, while addressing some of its limitations. While prior work can detect leaks across security domains, it still relies on an a priori hardware-software contract to define expected leakage. Our approach instead aims to test a kernel and processor in conjunction, to determine whether the kernel provides its promised security guarantees under potentially unknown CPU optimizations and vulnerabilities. The focus is to combine ideas from program synthesis and microarchitectural attacks to develop an end-to-end framework for discovering CPU vulnerabilities exploitable in realistic configurations.
I am excited to delve deeper into the field of Hardware Security, as it allows me to work with both hardware and software at a very low level. Through the SuperUROP program, I hope to grow as a researcher and learn more about my peers’ research along the way.
