Instruction-Level Exploratory Testing Framework for ARMv8-A Processors | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Instruction-Level Exploratory Testing Framework for ARMv8-A Processors Xinzhe Yang, Song Chai, Xi Chen, Ming Gong, Guo Li This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-8542085/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Instruction-level testing of modern processors is increasingly challenged by the presence of undocumented and weakly specified behaviors. This paper presents an instruction-level testing framework designed to expose and characterize these undocumented behaviors on ARMv8-A processors. The framework systematically generates instruction streams, executes them in isolation, and observes their effects through multiple weak oracles , including register state differences and performance monitoring events. To rigorously verify control-flow integrity, the method employs a sentinel-guarded memory layout combined with trap-based fall-through verification, utilizing signal contexts to quantify program counter deviations. Implemented on the RK3399 platform, the method exhaustively screened over 1.2 billion architecturally undefined encodings. Experimental results categorize the observed behaviors into distinct functional classes. While primarily designed for testing and characterization, the observed behaviors provide insights for improving processor reliability and architectural documentation. ARMv8-A Instruction-level testing Exploratory testing Weak oracles Functional characterization Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-8542085","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":612858004,"identity":"fa153022-5b05-4430-9062-469ab82a01d1","order_by":0,"name":"Xinzhe Yang","email":"","orcid":"","institution":"Southwest Minzu University","correspondingAuthor":false,"prefix":"","firstName":"Xinzhe","middleName":"","lastName":"Yang","suffix":""},{"id":612858017,"identity":"11c3bf40-9e45-4e3c-a303-57bc07fdf4ea","order_by":1,"name":"Song Chai","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA2ElEQVRIie3POwrCQBCA4QkDazOQNjFirrASCFZ6FSFglZxA0diMjXoWS8vA4tp4ADuLXEAQhDTiq7NYt7TYv1qW+WAGwOX617wSyMfq9Qw6FvP4ISGP3oSsCUj9JvCbxKWvLs1u0Ek06vZp2idoqf3WRGSFIlwfM0q1yJJcPxej8fhkJIACPUZKz6tenYsnCSg1krhEvHo8p4RJqvxuQaBCiDxWJAX16oItiFSYhms+UPC6pdgEJH7dEi8X9aXhydBn1FF+m3X9ltLmxfD7QxjHXS6Xy2XVA+ubO6w778DBAAAAAElFTkSuQmCC","orcid":"","institution":"Southwest Minzu University","correspondingAuthor":true,"prefix":"","firstName":"Song","middleName":"","lastName":"Chai","suffix":""},{"id":612858020,"identity":"4e641d76-bf1f-4f41-bc37-1cd266de209b","order_by":2,"name":"Xi Chen","email":"","orcid":"","institution":"Southwest Minzu University","correspondingAuthor":false,"prefix":"","firstName":"Xi","middleName":"","lastName":"Chen","suffix":""},{"id":612858036,"identity":"690b04c6-be5e-4ee0-8e54-d2c0731879c1","order_by":3,"name":"Ming Gong","email":"","orcid":"","institution":"Southwest Minzu University","correspondingAuthor":false,"prefix":"","firstName":"Ming","middleName":"","lastName":"Gong","suffix":""},{"id":612858037,"identity":"8a3ec215-6f2d-4307-840a-3c52c299e5e2","order_by":4,"name":"Guo Li","email":"","orcid":"","institution":"University of Electronic Science and Technology of China","correspondingAuthor":false,"prefix":"","firstName":"Guo","middleName":"","lastName":"Li","suffix":""}],"badges":[],"createdAt":"2026-01-07 13:38:12","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-8542085/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-8542085/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":105904161,"identity":"6a1c8613-1d88-422e-9b37-98fb4133b60d","added_by":"auto","created_at":"2026-04-01 10:05:32","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1882688,"visible":true,"origin":"","legend":"","description":"","filename":"InstructionLevelExploratoryTestingFrameworkforARMv8AProcessors.pdf","url":"https://assets-eu.researchsquare.com/files/rs-8542085/v1_covered_33b040f2-a810-4393-a3f6-df7f446faddd.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Instruction-Level Exploratory Testing Framework for ARMv8-A Processors","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"ARMv8-A, Instruction-level testing, Exploratory testing, Weak oracles, Functional characterization","lastPublishedDoi":"10.21203/rs.3.rs-8542085/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-8542085/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eInstruction-level testing of modern processors is increasingly challenged by the presence of undocumented and weakly specified behaviors. This paper presents an instruction-level testing framework designed to expose and characterize these undocumented behaviors on ARMv8-A processors. The framework systematically generates instruction streams, executes them in isolation, and observes their effects through multiple \u003cem\u003eweak oracles\u003c/em\u003e, including register state differences and performance monitoring events. To rigorously verify control-flow integrity, the method employs a sentinel-guarded memory layout combined with trap-based fall-through verification, utilizing signal contexts to quantify program counter deviations. Implemented on the RK3399 platform, the method exhaustively screened over 1.2 billion architecturally undefined encodings. Experimental results categorize the observed behaviors into distinct functional classes. While primarily designed for testing and characterization, the observed behaviors provide insights for improving processor reliability and architectural documentation.\u003c/p\u003e","manuscriptTitle":"Instruction-Level Exploratory Testing Framework for ARMv8-A Processors","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-03-30 17:45:21","doi":"10.21203/rs.3.rs-8542085/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"edf75b07-8a6e-4526-a4ad-729fdf6e4969","owner":[],"postedDate":"March 30th, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2026-03-30T17:45:21+00:00","versionOfRecord":[],"versionCreatedAt":"2026-03-30 17:45:21","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-8542085","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-8542085","identity":"rs-8542085","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.