Publications

USENIX Security Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors
IEEE S&P TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads
IEEE S&P Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software Emulation
uASC Zero-Store Elimination and its Implications on the SIKE Cryptosystem
CCS RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs
USENIX Security SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution
USENIX Security Confusing Value with Enumeration: Studying the Use of CVEs in Academia
DIMVA Taming the Linux Memory Allocator for Rapid Prototyping
S&P Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage
FC Lixom: Protecting Encryption Keys with Execute-Only Memory
FC Do Compilers Break Constant-time Guarantees?
NDSS Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting
ASPLOS ShadowLoad: Injecting State into Hardware Prefetchers
WWW Peripheral Instinct: How External Devices Breach Browser Sandboxes
ACSAC No Leakage Without State Change: Repurposing Configurable CPU Exceptions to Prevent Microarchitectural Attacks
IEEE S&P Efficient and Generic Microarchitectural Hash-Function Recovery
USENIX Security CacheWarp: Software-based Fault Injection using Selective State Reset
ESORICS Reviving Meltdown 3a
ESORICS Indirect Meltdown: Building Novel Side-Channel Attacks from Transient-Execution Attacks
ESORICS A Rowhammer Reproduction Study Using the Blacksmith Fuzzer
USENIX Security Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels
DRAMSec Hammulator: Simulate Now-Exploit Later
IEEE S&P A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs