This review synthesises 118 works published from 2014 to 2026 covering the full firmware reverse engineering pipeline and identifies ten structural gaps, including the absence of unified evaluation benchmarks, fragmented peripheral modelling, the scalability–fidelity trade-off in re-hosting, and insufficient grounding of LLM tools in firmware-specific realities.
Abstract
Firmware forms the persistent software layer controlling embedded and Internet-of-Things (IoT) devices, industrial controllers, automotive systems, and cyber-physical infrastructure. Vulnerabilities in firmware enable remote compromise, supply-chain attacks, and long-lived implants that survive operating-system reinstallation. This review synthesises 118 works published from 2014 to 2026—comprising 78 primary research studies; 23 surveys and systematisations of knowledge; and 17 benchmarks, tools, and background references—covering the full firmware reverse engineering (FRE) pipeline: physical acquisition (including fault injection and side-channel extraction), format analysis and unpacking, static analysis (binary code similarity detection, protocol reverse engineering, and patch diffing), dynamic analysis and hardware emulation, fuzzing-based vulnerability discovery, and artificial intelligence (AI) and large language model (LLM)-assisted analysis. Three additional dimensions are surveyed: digital twin-assisted firmware security testing; secure boot, trusted execution environment (TEE), and over-the-air (OTA) update security; and firmware rootkit and implant detection. Coverage spans two axes—the firmware class (Linux-based IoT, microcontroller-unit bare-metal, RTOS, UEFI/BIOS, PLC/ICS, and automotive ECU) and analysis depth (surface scanning to exploit-validated vulnerability chains). We identify ten structural gaps, including the absence of unified evaluation benchmarks, fragmented peripheral modelling, the scalability–fidelity trade-off in re-hosting, and insufficient grounding of LLM tools in firmware-specific realities. We conclude with six research directions for trustworthy, scalable, and infrastructure-aware firmware analysis.
BULLSEYE is presented, the first DGF framework to schedule closed-source Linux-based firmware fuzzing by basic-block-level distance to user-specified targets, and introduces novel DGF heuristics that address limitations of traditional approaches.
Seven compositional design principles for platform security architects and OEM integration engineers are developed, bringing up hardware roots of trust (HRoT), ARM TrustZone-based trusted execution environments (TEEs), TPM 2.0, and integrated security processors such as Microsoft Pluton.
Madhav Narayan Bhat· International journal of com...· 0 citations
Hardware serves as the root of trust in modern computing systems, making Hardware Reverse Engineering (HRE) essential for security assurance—from design verification and supply-chain integrity to vulnerability discovery. We scope HRE to netlist recovery and its subsequent analysis, spanning the three subdomains of Inte...
Zehra Karadağ, Simon Klix, René Walendy et al.· IACR Transactions on Cryptog...· 0 citations
Experimental results on real-world firmware images collected from multiple vendors and architectures demonstrate that the proposed approach improves emulation robustness and enhances the ability to successfully execute previously failing firmware instances, supporting more reliable IoT firmware security analysis.
Jong-Yih Kuo, Yu-Quan Wang, Tí-Feng Hsieh et al.· Sensors and materials· 0 citations
Stakeholder-specific recommendations for academia, industry, and government to transition HRE from isolated research silos toward a collaborative discipline capable of assuring increasingly complex, global hardware supply chains are derived.
Zehra Karadağ, Simon Klix, René Walendy et al.· 0 citations
The prolific deployment of embedded systems across critical infrastructure has made hardware security a pressing concern. For example, inexpensive microcontrollers, such as the STM32 series, are frequently deployed with cryptographic firmware that is vulnerable to Side-Channel Attack (SCA), such as Correlation Power An...
Sartaj Jamal Chowdhury, Ahmed Nabil Hammad, John Dragos et al.· Midwest Symposium on Circuit...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.