Publications
USENIX Security
Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors IEEE S&P
TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads IEEE S&P
Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software Emulation uASC
Zero-Store Elimination and its Implications on the SIKE Cryptosystem CCS
RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs USENIX Security
SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution USENIX Security
Confusing Value with Enumeration: Studying the Use of CVEs in Academia DIMVA
Taming the Linux Memory Allocator for Rapid Prototyping S&P
Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage FC
Lixom: Protecting Encryption Keys with Execute-Only Memory FC
Do Compilers Break Constant-time Guarantees? NDSS
Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting ASPLOS
ShadowLoad: Injecting State into Hardware Prefetchers WWW
Peripheral Instinct: How External Devices Breach Browser Sandboxes ACSAC
No Leakage Without State Change: Repurposing Configurable CPU Exceptions to Prevent Microarchitectural Attacks IEEE S&P
Efficient and Generic Microarchitectural Hash-Function Recovery USENIX Security
CacheWarp: Software-based Fault Injection using Selective State Reset ESORICS
Reviving Meltdown 3a ESORICS
Indirect Meltdown: Building Novel Side-Channel Attacks from Transient-Execution Attacks ESORICS
A Rowhammer Reproduction Study Using the Blacksmith Fuzzer USENIX Security
Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels DRAMSec
Hammulator: Simulate Now-Exploit Later IEEE S&P
A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs