CWEEP: A Lexical Static Analysis Framework for CWE Early Prevention
Bryan Kwan, Benjamin Tan
cs.CR
Submitted: 2026-07-31
Comments: 12 pages, 9 figures
Code: https://github.com/bryan-kwan/cweep
License: http://creativecommons.org/licenses/by-sa/4.0/
The gist: As the hardware layer becomes a focus point for attackers, the need for improved hardware security verification techniques is more important than ever.
Terminology
Abstract
As the hardware layer becomes a focus point for attackers, the need for improved hardware security verification techniques is more important than ever. State-of-the-art security verification techniques require significant manual effort from individuals with security expertise. Furthermore, there is no standard method to locate where the fault lies within the register transfer level (RTL) code. This paper presents CWEEP, a static analysis framework for detecting security weaknesses in RTL. CWEEP does not require a detailed security specification, so it can be used in the early stages of RTL development while properties are still under construction. Furthermore, CWEEP can identify the exact location in the RTL where the potential vulnerability resides and supports automatic code repair suggestions when applicable. Using datasets from the literature, we evaluate the performance of CWEEP on a set of two SoC designs with manually inserted bugs and on a large language model generated dataset, consisting of 3874 buggy modules. We find that CWEEP issues a correct warning up to 60.8% of the time. In contrast, the tool from a previous work issued a correct warning 17.5% of the time for the same dataset.
Sources
- Meltdown
- Wit-HW: Bug Localization in Hardware Design Code via Witness Test Case Generation
- LAsset: An LLM-assisted Security Asset Identification Framework for System-on-Chip (SoC) Verification
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs