BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol Stacks
Wei-Che Kao (Defc Core)
34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Software Security 3: Fuzzing
Overview
This talk introduces BLuEMan, a novel stateful, simulation-based fuzzing framework specifically designed to identify vulnerabilities in open-source Bluetooth Low Energy (BLE) protocol stack implementations for Real-Time Operating Systems (RTOS). Presented by Wei-Che Kao from National Yang Ming Chiao Tung University, the research addresses critical security concerns arising from the widespread adoption of BLE technology. With over 80% of the approximately 4.9 billion Bluetooth devices shipped in 2024 expected to feature BLE, the protocol's security is paramount across diverse applications, from smart home devices and wearables to automotive systems.

Key moments
- 0:00 Introduction to BLuEMan and BLE security concerns
- 2:00 BLE protocol architecture: Controller, Host, HCI
- 3:04 Analyzing limitations of existing BLE fuzzing methods
- 4:15 BLuEMan's design challenges: scalability, seed quality, complexity
- 6:20 Solving runtime scalability with BabelSim simulation platform
- 8:00 Generating high-quality, context-aware seeds via packet interceptor
- 10:00 Handling BLE complexity with combined fuzzing approach
BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol Stacks
Speakers: Wei-Che Kao
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=F6MwvYhJgrs
Overview
This talk introduces BLuEMan, a novel stateful, simulation-based fuzzing framework specifically designed to identify vulnerabilities in open-source Bluetooth Low Energy (BLE) protocol stack implementations for Real-Time Operating Systems (RTOS). Presented by Wei-Che Kao from National Yang Ming Chiao Tung University, the research addresses critical security concerns arising from the widespread adoption of BLE technology. With over 80% of the approximately 4.9 billion Bluetooth devices shipped in 2024 expected to feature BLE, the protocol's security is paramount across diverse applications, from smart home devices and wearables to automotive systems.
The significance of BLuEMan lies in its ability to overcome the limitations of existing BLE fuzzing techniques, which often suffer from slow execution, incomplete stack coverage, low fidelity, or high complexity in managing protocol states. By combining a physical layer simulator (BabelSim) with an innovative "man-in-the-middle" architecture, BLuEMan offers an efficient, high-fidelity, and scalable platform for discovering deep protocol behaviors and vulnerabilities. The framework’s effectiveness is underscored by its discovery of four new vulnerabilities spanning different layers of the BLE stack, demonstrating a substantial leap forward in securing this ubiquitous wireless communication standard.
Background
▶ Watch: Introduction to BLuEMan and BLE security concerns (0:00)
The Bluetooth Low Energy (BLE) protocol stack is a complex system primarily divided into two main components: the controller and the host. The controller manages low-level operations such as the link layer, encryption/decryption, and direct interaction with the radio hardware. The host, on the other hand, handles higher-level functions like connection establishment, pairing, bonding, security management, and the execution of BLE application logic. These two components communicate via the Host Controller Interface (HCI), which can utilize various transport mechanisms like USB or UART. The modular nature of BLE, coupled with its extensive use in low-power, short-range transmission scenarios, makes it a prime target for security research. Past vulnerabilities, such as BlueBorne, BleedingBit, and Frankenstein, highlight the persistent risks associated with insecure BLE implementations, ranging from denial-of-service to remote code execution.
Prior research into Bluetooth fuzzing generally falls into three categories, each with its own advantages and disadvantages:
- Emulation-based full-stack fuzzers (Type A): These frameworks emulate the entire Bluetooth stack, including both host and controller, often using tools like QEMU. While they offer fast execution and easier coverage collection, the emulation of hardware-dependent controllers frequently suffers from low fidelity, potentially missing real-world behaviors or bugs.
- Emulation-based host-stack fuzzers (Type B): These target only the host component at the HCI layer. They are faster and more coverage-friendly than full-stack emulation but provide limited stack completeness as they do not sufficiently cover the controller. Bugs discovered might not be remotely triggerable in a real-world scenario.
- Hardware-based full-stack fuzzers (Type C): These utilize real devices to test the full stack, offering high fidelity. However, they are inherently slow, make coverage collection difficult, and often rely on manual or auto-generated state machines to craft context-aware packets, leading to high complexity.
The BLuEMan project was conceived to address the critical shortcomings of these existing approaches. The researchers identified three primary challenges that needed to be overcome for effective BLE fuzzing:
- Runtime Scalability: The need for a low-cost testing environment that avoids expensive physical devices, easily integrates with state-of-the-art coverage tools and sanitizers, and runs significantly faster than hardware-based solutions while being easy to debug.
- High-Quality Seeds: The recognition that meaningful initial seeds are crucial for fuzzer performance. These seeds must consist of sequences of context-aware BLE packets, capable of triggering complete protocol flows (e.g., a full pairing process) to increase testing depth and vulnerability discovery chances.
- Complexity of BLE beyond the core specification: The BLE ecosystem includes complex extensions like BLE Mesh, multiple profiles, and vendor-specific additions. Mapping all these specifications into rigid state machines creates a large, hard-to-maintain system. A flexible design that can easily evolve with the BLE protocol is therefore essential.
Key Findings
▶ Watch: Analyzing limitations of existing BLE fuzzing methods (3:04)
BLuEMan presents a novel stateful simulation-based fuzzing framework that significantly advances the state-of-the-art in BLE protocol stack security testing. Its key findings and contributions include:
- A Novel Architecture for Scalable and High-Fidelity Fuzzing: By integrating BabelSim, an open-source physical layer simulator, BLuEMan achieves unprecedented speed and fidelity. It runs simulated BLE devices as ELF executables on a single Linux host, eliminating the need for physical development boards and enabling easy integration with advanced coverage instrumentation tools like AFL++. This approach yields a transmission speed approximately 100 times faster than physical devices or Root Canal, and 162.3 times faster than Swi, and 18 times faster than BTFuzz.
- Automated Context-Aware Seed Generation: BLuEMan introduces a packet interceptor at BabelSim's physical layer to automatically collect high-quality, context-aware packet sequences. These sequences accurately reflect real protocol interactions across multiple layers (Link, L2CAP, ATT, GATT, OTS), ensuring that generated test cases maintain crucial inter-layer dependencies and can trigger deep logic paths.
- Stackable Mutation Architecture without Complex State Machines: The framework utilizes a unique stackable mutation architecture that combines the packet interceptor for seeds, code coverage feedback for guidance, and a modular mutation engine. This design eliminates the need for complex, hand-crafted state machines by leveraging code coverage to reflect protocol state evolution. Each protocol layer has a dedicated plugin for precise mutation, making the system extensible and adaptable to new or custom protocols.
- Significant Coverage and Vulnerability Discovery: In comparative evaluations, BLuEMan demonstrated substantial improvements in code coverage. It achieved between 6.14% and 256.49% higher coverage than a simple byte-only mutator. Against the state-of-the-art Blacktooth fuzzer, BLuEMan achieved 1.44 to 1.69 times higher coverage within the same testing period, with Blacktooth's coverage growth often stopping after just 40 seconds. Crucially, BLuEMan successfully uncovered four new vulnerabilities spanning different layers of the BLE stack, unequivocally demonstrating its effectiveness in identifying critical security issues.
Technical Deep Dive
▶ Watch: BLuEMan's design challenges: scalability, seed quality, complexity (4:15)
BLuEMan's innovative design is built upon three core solutions addressing the previously identified challenges: runtime scalability, high-quality seed generation, and managing the complexity of the BLE protocol beyond its core specification.
Runtime Scalability through BabelSim
To achieve runtime scalability, BLuEMan leverages BabelSim, an open-source physical layer simulator. BabelSim is conceptually divided into simulated devices and a shared media. Each simulated device runs its BLE protocol stack on top of a modem emulated by BabelSim. When a BLE application initiates a request, it traverses the protocol stack, and the emulated modem transmits the packet to the shared media. This shared media can connect multiple modems, enabling communication between various simulated devices using the BLE protocol.
A key advantage is that these simulated devices run as standard ELF executables rather than embedded firmware images. This allows BLuEMan to execute both the fuzzer and multiple target BLE applications directly on a single Linux host, eliminating the need for expensive development boards. This setup not only reduces the cost of building test environments but also dramatically increases BLE packet transmission speed, running approximately 100 times faster than real development boards or HCI-based testing. Furthermore, because the applications compile into ELF executables, BLuEMan can easily integrate with state-of-the-art coverage instrumentation tools like AFL++, facilitating precise code coverage collection to guide the fuzzing process effectively.
High-Quality Seed Generation with Packet Interceptors
The problem of generating high-quality seeds is addressed by an ingenious packet interceptor mechanism. Before fuzzing begins, a target BLE application is executed in a controlled environment. BLuEMan inserts its packet interceptor code at BabelSim's physical layer, specifically within the packet receiving code. All packets passing through this interceptor are recorded. This recording continues until the observed code coverage within the target application stabilizes, indicating that a significant portion of its initial behaviors has been exercised.
These recorded packets are then organized into context-aware packet sequences, which serve as the initial seeds for fuzzing. For instance, when testing an Over-The-Air Software Update (OTS) profile, BLuEMan captures a complete sequence spanning multiple protocol layers. This includes:
- Link Layer packets for low-level communication management.
- L2CAP Layer packets for managing logical channels.
- ATT Layer packets for attribute access.
- GATT Layer packets defining the service framework.
- Finally, the OTS protocol packets themselves.
By capturing the entire sequence across these interdependent layers, BLuEMan ensures that the generated test cases accurately reflect real protocol interactions and maintain crucial dependencies between layers. This context awareness is vital for triggering deep logic paths within the target stack that would otherwise be missed if individual packets were considered in isolation.
Addressing BLE Complexity with Stackable Mutation Architecture
The third challenge, the inherent complexity of BLE beyond its core specification, is tackled by combining three core components: the packet interceptor (reusing meaningful seeds), code coverage (feedback for program state), and a novel stackable mutation algorithm. This approach allows BLuEMan to explore deep protocol behaviors without relying on complex, hard-to-maintain state machines.
- Packet Interceptor for Seeds: As described, the interceptor captures real, context-aware packet sequences, which are then reused as high-quality initial seeds.
- Code Coverage as State Feedback: Code coverage serves as the primary feedback mechanism, guiding the fuzzer toward unexplored execution paths. Crucially, because code coverage naturally reflects different states as the BLE protocol evolves, BLuEMan does not need to build or maintain a complex, explicit state machine. This significantly reduces system complexity and maintenance overhead.
- Stackable Mutation Architecture: This is the core of BLuEMan's flexibility. It's designed to be extensible for fuzzing across multiple BLE protocol layers, providing precise control over where mutations are applied while maintaining protocol validity. The architecture comprises a series of plugins, with each plugin responsible for a specific protocol layer. Each plugin includes:
- A recognition function to detect the presence of its corresponding layer within a packet.
- A custom mutation function capable of precisely targeting headers or payloads specific to that layer.
- A sampling mechanism to decide which layer should be mutated at runtime.
By stacking these plugins in sequence, the framework can scan packets layer by layer, enabling a flexible and adaptable fuzzing process. This modular design is critical, as it allows researchers to easily extend support for new or custom protocols as the BLE ecosystem evolves.
On top of this architecture, three additional constraints and adjustments are applied during mutation to preserve packet semantics and minimize unnecessary rejections by the target, thereby maximizing fuzzing effectiveness:
- Limited Bitwise Mutations: Bitwise mutations are primarily limited to the link layer, where low-level variations are most effective and less likely to immediately break higher-level protocol semantics.
- Preserving Upper Layer Semantics: Upper layer protocol fields (e.g., L2CAP or ATT) are largely kept unchanged to avoid breaking higher-level semantics, which would otherwise lead to premature packet rejection.
- Length Field Adjustment: When the payload size of a packet changes due to mutation, BLuEMan automatically adjusts related length fields within the packet structure to ensure it remains structurally consistent and valid.
These design choices collectively allow BLuEMan to efficiently explore deep protocol behaviors with context-aware, coverage-guided feedback and controlled mutations, all without the burden of a complex, hand-crafted state machine.
Demo / Proof of Concept
▶ Watch: Generating high-quality, context-aware seeds via packet interceptor (8:00)
While the talk did not feature a live, interactive demonstration, the researchers provided extensive evaluation results that served as a compelling proof of concept for BLuEMan's capabilities and effectiveness. These evaluations focused on comparing BLuEMan's performance, speed, and coverage against existing fuzzing platforms and methodologies.
The first aspect of the evaluation involved selecting an optimal fuzzing medium. The team compared the performance of BabelSim with Root Canal and actual physical devices. The findings clearly indicated that while Root Canal and physical devices exhibited similar average speeds, physical devices were highly unstable due to signal interference. In stark contrast, BabelSim demonstrated a remarkable speed advantage, running approximately 100 times faster than the other two mediums. This validated BabelSim as the superior foundation for BLuEMan's high-speed fuzzing.
Further speed comparisons highlighted BLuEMan's efficiency against other established BLE fuzzers:
- BLuEMan achieved approximately 162.3 times faster transmission speed than Swi, a fuzzer that also sends BLE packets directly to the controller.
- It was about 18 times faster than BTFuzz, although it's important to note that BTFuzz primarily tests the host by sending HCI packets, whereas BLuEMan performs full-stack fuzzing by interacting with the controller via BLE packets.
The talk also presented a crucial comparison of BLuEMan's stackable mutation architecture against a simple byte-only mutator. This evaluation revealed significant improvements in code coverage, with BLuEMan achieving between 6.14% and 256.49% higher coverage. The researchers did note that for BLE Mesh benchmarks, where most packets are encrypted, all mutation methods showed only small differences and relatively slow coverage due to the encrypted payloads, indicating an area for future research in handling encrypted traffic.
Perhaps the most compelling proof of concept came from the comparison with Blacktooth, a state-of-the-art BLE instruction fuzzer. For this experiment, BLuEMan ran its fuzzer against a target application where the host ran on Linux, and an nRF52840 development kit served as the controller. For Blacktooth, firmware was flashed onto an ESP Rover Kit. Each experiment was run for 5 hours. Despite the longer duration, Blacktooth's coverage growth typically stopped increasing after roughly 40 seconds. In contrast, BLuEMan achieved 1.44 to 1.69 times higher code coverage than Blacktooth within the same timeframe, demonstrating its superior exploration capabilities.
Finally, the ultimate proof of BLuEMan's effectiveness was its ability to uncover four new vulnerabilities across different layers of the BLE stack. These discoveries validate the framework's design principles—combining efficient simulation, context-aware seed generation, and a flexible mutation engine—in identifying real-world security issues in open-source BLE implementations. The resources, including the GitHub repository, source code snapshot, and full paper, were made publicly available via QR codes, allowing others to verify and build upon this work.
Defensive Implications
▶ Watch: Handling BLE complexity with combined fuzzing approach (10:00)
The findings presented by BLuEMan have significant implications for developers, vendors, and users of Bluetooth Low Energy devices. The continued discovery of critical vulnerabilities, even in widely adopted open-source stacks, underscores the persistent need for robust security practices.
- Prioritize Fuzzing in Development Pipelines: Developers and vendors of BLE protocol stacks, especially those for RTOS, should integrate advanced fuzzing techniques like BLuEMan into their continuous integration and development pipelines. The efficiency and effectiveness demonstrated by BLuEMan highlight that high-fidelity, full-stack fuzzing is no longer an insurmountable challenge. Automating vulnerability discovery at an early stage can prevent costly post-release patches and reputational damage.
- Focus on Cross-Layer Protocol Integrity: The emphasis on context-aware seed generation and stackable mutation in BLuEMan highlights that vulnerabilities often arise from subtle interactions and dependencies across different layers of the BLE stack. Developers must pay meticulous attention to how data and state transition between the link, L2CAP, ATT, and GATT layers, ensuring that all protocol invariants are maintained.
- Regularly Update and Patch BLE Stacks: Given the dynamic nature of vulnerability discovery, it is crucial for device manufacturers to provide mechanisms for over-the-air (OTA) updates and promptly release patches for identified security flaws. End-users should be encouraged to regularly update their BLE-enabled devices to mitigate known risks.
- Consider Vendor-Specific Extensions as Attack Surface: The talk mentioned the complexity introduced by vendor extensions. These custom additions to the BLE protocol can introduce unique vulnerabilities. Developers must apply the same rigorous security testing, including fuzzing, to their proprietary extensions as they do to the core BLE specification.
- Invest in Simulation-Based Testing: The dramatic speed and stability advantages of BabelSim over physical devices or partial emulation suggest that simulation-based testing environments are a powerful tool for security research and quality assurance. Investing in and contributing to such open-source simulation platforms can accelerate the discovery and remediation of vulnerabilities across the industry.
- Enhance Security for Encrypted Traffic: The observation that fuzzing encrypted BLE Mesh packets yielded limited coverage highlights a current challenge. Future defensive strategies and fuzzing tools need to evolve to effectively test and secure encrypted communication flows, perhaps through integration with key management systems or side-channel analysis in simulated environments.
By adopting these defensive strategies, the security posture of the vast and growing ecosystem of BLE-enabled devices can be significantly improved, protecting users from the increasingly sophisticated threats posed by malicious actors.
Key Takeaways
- BLuEMan is a novel stateful, simulation-based fuzzing framework for open-source RTOS BLE protocol stacks, designed to overcome limitations of existing fuzzers.
- It achieves significantly higher speed and fidelity by using BabelSim, an open-source physical layer simulator, running approximately 100 times faster than physical devices and 162.3 times faster than Swi.
- The framework automates the generation of high-quality, context-aware packet sequences across multiple BLE layers (Link, L2CAP, ATT, GATT, OTS) for effective deep protocol exploration.
- BLuEMan employs a stackable mutation architecture with layer-specific plugins and uses code coverage as feedback to guide fuzzing, eliminating the need for complex, hand-crafted state machines.
- It demonstrated superior performance in coverage, achieving 1.44 to 1.69 times higher coverage than the state-of-the-art Blacktooth fuzzer and uncovering four new vulnerabilities in open-source BLE stacks.
- The modular design and adherence to protocol semantics through constrained mutations ensure efficient and effective fuzzing, minimizing packet rejections and maximizing exploration of valid execution paths.
About the Speaker(s)
Wei-Che Kao is a researcher currently working at Defc Core. This work was a collaborative effort with a team from National Yang Ming Chiao Tung University, where he presented BLuEMan, a significant contribution to the field of Bluetooth Low Energy security research.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid academic security research that solves a real, concrete problem in BLE fuzzing — the trifecta of slow execution, incomplete stack coverage, and state-machine complexity — with a genuinely clever architecture. Four new CVEs and measurable coverage wins over SOTA put this squarely in 'you built something, it worked' territory.
Heather Calloway (CISO) — PASS
Technically competent fuzzing research with real results — four new vulnerabilities found, meaningful speed improvements, a credible methodology. But this is deep protocol security research aimed at academics and tool builders, not operators or security leaders. Nothing here informs a governance decision, a board conversation, or a program investment.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)