PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 4, 20260 citationsOpen Access

RV-Sec5: Enhancing RISC-V Security Evaluation via Targeted ISA-Level Instrumentation using gem5

View Full Paper
MAMuhammad AwaisTélécom ParisMMMaria MushtaqLNLirida NavinerTélécom Paris

Key Points

  • The aim is to establish a framework for enhanced security evaluation of RISC-V architectures at the ISA level.
  • Developed RV-Sec5 framework for ISA-level security evaluation using gem5 simulator
  • Mapped high-level security invariants to cycle-accurate instrumentation points
  • Focused on detecting privilege escalation and monitoring microarchitectural anomalies
  • Utilized case study of unauthorized CSR modifications for demonstration
  • RV-Sec5 successfully detects privilege escalation attempts during execution
  • Monitors critical microarchitectural anomalies such as TLB flushes
  • Captures cache state changes in real-time throughout execution

Abstract

The modularity of the RISC-V Instruction Set Architecture (ISA) has accelerated its adoption in security-critical domains, yet it introduces significant challenges for pre-silicon security validation. Current evaluation methods often rely on high-level emulation that overlooks microarchitectural side effects or post-silicon testing that identifies vulnerabilities too late in the design cycle. This paper presents RV-Sec5, a systematic framework for ISA-level security evaluation that leverages the gem5 simulator. Unlike standard simulators, RV-Sec5 introduces a methodology to map high-level security invariants-such as privilege isolation and memory protection-directly to automated, cycle-accurate instrumentation points within the ISA decoder. This approach bridges the semantic gap between abstract security policies and low-level hardware execution. We demonstrate the framework's efficacy through a case study involving unauthorized Control and Status Register (CSR) modifications, showing how RV-Sec5 detects privilege escalation attempts and monitors microarchitectural anomalies, such as TLB flushes and cache state changes, in real-time. The modularity of the RISC-V Instruction Set Architecture (ISA) has accelerated its adoption in security-critical domains, yet it introduces significant challenges for pre-silicon security validation. Current evaluation methods often rely on high-level emulation that overlooks microarchitectural side effects or post-silicon testing that identifies vulnerabilities too late in the design cycle. This paper presents RV-Sec5, a systematic framework for ISA-level security evaluation that leverages the gem5 simulator. Unlike standard simulators, RV-Sec5 introduces a methodology to map high-level security invariants-such as privilege isolation and memory protection-directly to automated, cycle-accurate instrumentation points within the ISA decoder. This approach bridges the semantic gap between abstract security policies and low-level hardware execution. We demonstrate the framework's efficacy through a case study involving unauthorized Control and Status Register (CSR) modifications, showing how RV-Sec5 detects privilege escalation attempts and monitors microarchitectural anomalies, such as TLB flushes and cache state changes, in real-time.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Awais et al. (2026) studied this question.

synapsesocial.com/papers/69a7cd9dd48f933b5eeda146https://doi.org/10.1145/3793638.3793640
Ask AI
Helpful
Bookmark
Share
View Full Paper