Skip to content
Review Open access

Firmware Reverse Engineering: A Comprehensive Review and Directions

Aug 2026 · Electronics · 0 citations · 50 references

TL;DR

This review synthesises 118 works published from 2014 to 2026 covering the full firmware reverse engineering pipeline and identifies ten structural gaps, including the absence of unified evaluation benchmarks, fragmented peripheral modelling, the scalability–fidelity trade-off in re-hosting, and insufficient grounding of LLM tools in firmware-specific realities.

Abstract

Firmware forms the persistent software layer controlling embedded and Internet-of-Things (IoT) devices, industrial controllers, automotive systems, and cyber-physical infrastructure. Vulnerabilities in firmware enable remote compromise, supply-chain attacks, and long-lived implants that survive operating-system reinstallation. This review synthesises 118 works published from 2014 to 2026—comprising 78 primary research studies; 23 surveys and systematisations of knowledge; and 17 benchmarks, tools, and background references—covering the full firmware reverse engineering (FRE) pipeline: physical acquisition (including fault injection and side-channel extraction), format analysis and unpacking, static analysis (binary code similarity detection, protocol reverse engineering, and patch diffing), dynamic analysis and hardware emulation, fuzzing-based vulnerability discovery, and artificial intelligence (AI) and large language model (LLM)-assisted analysis. Three additional dimensions are surveyed: digital twin-assisted firmware security testing; secure boot, trusted execution environment (TEE), and over-the-air (OTA) update security; and firmware rootkit and implant detection. Coverage spans two axes—the firmware class (Linux-based IoT, microcontroller-unit bare-metal, RTOS, UEFI/BIOS, PLC/ICS, and automotive ECU) and analysis depth (surface scanning to exploit-validated vulnerability chains). We identify ten structural gaps, including the absence of unified evaluation benchmarks, fragmented peripheral modelling, the scalability–fidelity trade-off in re-hosting, and insufficient grounding of LLM tools in firmware-specific realities. We conclude with six research directions for trustworthy, scalable, and infrastructure-aware firmware analysis.

Read PDF

Similar papers

Preprint Aug 2026

BullsEye: Directed Firmware Fuzzing

BULLSEYE is presented, the first DGF framework to schedule closed-source Linux-based firmware fuzzing by basic-block-level distance to user-specified targets, and introduces novel DGF heuristics that address limitations of traditional approaches.

Lorenzo Ralli, Emilio Coppa · 0 citations
Open access Jul 2026

Compositional Design Principles for Hardware-Backed Platform Security

Seven compositional design principles for platform security architects and OEM integration engineers are developed, bringing up hardware roots of trust (HRoT), ARM TrustZone-based trusted execution environments (TEEs), TPM 2.0, and integrated security processors such as Microsoft Pluton.

Madhav Narayan Bhat · 0 citations
Review Open access Sep 2026

SoK: From Silicon to Netlist and Beyond

Hardware serves as the root of trust in modern computing systems, making Hardware Reverse Engineering (HRE) essential for security assurance—from design verification and supply-chain integrity to vulnerability discovery. We scope HRE to netlist recovery and its subsequent analysis, spanning the three subdomains of Inte...

Zehra Karadağ, Simon Klix, René Walendy et al. · 0 citations
Open access Jul 2026

Improvement for Embedded Firmware Emulation Applying FirmAE

Experimental results on real-world firmware images collected from multiple vendors and architectures demonstrate that the proposed approach improves emulation robustness and enhances the ability to successfully execute previously failing firmware instances, supporting more reliable IoT firmware security analysis.

Jong-Yih Kuo, Yu-Quan Wang, Tí-Feng Hsieh et al. · 0 citations
Review

SoK: From Silicon to Netlist and Beyond Two

Stakeholder-specific recommendations for academia, industry, and government to transition HRE from isolated research silos toward a collaborative discipline capable of assuring increasingly complex, global hardware supply chains are derived.

Zehra Karadağ, Simon Klix, René Walendy et al. · 0 citations
Aug 2026

A Post-Compilation Side-Channel Attack Countermeasure Framework for STM32

The prolific deployment of embedded systems across critical infrastructure has made hardware security a pressing concern. For example, inexpensive microcontrollers, such as the STM32 series, are frequently deployed with cryptographic firmware that is vulnerable to Side-Channel Attack (SCA), such as Correlation Power An...

Sartaj Jamal Chowdhury, Ahmed Nabil Hammad, John Dragos et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.