News
9 Dec 2024
Published a preprint and the Code Artifact for On Borrowed Time – Preventing Static Side-Channel Analysis.22 Nov 2024
The paper On Borrowed Time – Preventing Static Side-Channel Analysis with will appear in NDSS 20257 Nov 2024
Our work CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives won the 2024 German IT Security Prize 29 Oct 2024
Congratulations to who completed a PhD on Enhancing State-of-the-Art Techniques Generating Low-Level Code for Cryptographic Arithmetic.15 Oct 2024
Spec-o-Scope: Cache Probing at Cache Speed received Distinguished Paper Award at CCS 2024.15 Oct 2024
Testing Side-Channel Security of Cryptographic Implementations against Future Microarchitectures received Distinguished Paper Award at CCS 2024.4 Jul 2024
Published the Code Artifact for Evict+Spec+Time: Exploiting Out-of-Order Execution to Improve Cache-Timing Attacks. 2 Jul 2024
Preprint available Protecting cryptographic code against Spectre-RSB (and, in fact, all known Spectre variants), co-authored with
,
,
,
,
,
,
, and
.
22 May 2024
The paper Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy Budget with will appear in CCS 202419 Apr 2024
I have been appointed as an adjunct faculty at the Max Planck Institute for Security and Privacy4 Apr 2024
The paper Testing Side-Channel Security of Cryptographic Implementations against Future Microarchitectures with will appear in CCS 202416 Mar 2024
The paper Evict+Spec+Time: Exploiting Out-of-Order Execution to Improve Cache-Timing Attacks with will appear in TCHES2 Feb 2024
Preprint available Testing Side-Channel Security of Cryptographic Implementations against Future Microarchitectures, co-authored with .2 Feb 2024
Preprint available Evict+Spec+Time: Exploiting Out-of-Order Execution to Improve Cache-Timing Attacks, co-authored with .1 Feb 2024
Preprint available Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy Budget, co-authored with
,
,
,
,
.
24 Jan 2024
Checking Passwords on Leaky Computers: A Side Channel Analysis of Chrome’s
Password Leak Detection Protocol accepted to RWC 2024.24 Jan 2024
The paper SoK: Can We Really Detect Cache Side-Channel Attacks by Monitoring Performance Counters? with will appear in AsiaCCS 202417 Nov 2023
The paper Pixel Thief: Exploiting SVG Filter Leakage in Firefox and Chrome with will appear in USENIX Security 20248 Nov 2023
's thesis has been awarded the Dean's Commendation for Master by Research Thesis Excellence5 Nov 2023
Congratulations to who completed a Master of Philosophy on Exploring the Vulnerability of Branch Prediction Unit.25 Oct 2023
The paper iLeakage: Browser-based Timerless Speculative Execution Attacks on Apple Devices with will appear in CCS 202324 Oct 2023
Congratulations to who completed a Master of Philosophy on Cache Attacks and Defenses16 Oct 2023
The paper SledgeHammer: Amplifying Rowhammer via Bank-level Parallelism with will appear in USENIX Security 20249 Oct 2023
Preprint available Leaky McEliece: Secret Key Recovery From Highly Erroneous Side-Channel Information, co-authored with
,
,
,
.
2 Oct 2023
Cyber Today, the magazine of the Australian Information Security Association (AISA) has a piece on CryptOpt19 Jul 2023
Preprint available On Borrowed Time – Preventing Static Power Side-Channel Analysis, co-authored with
and
.
19 Jul 2023
Our work CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives won the 2023 Humies Gold Award at GECCO 2023 19 Jun 2023
The paper Checking Passwords on Leaky Computers: A Side Channel Analysis of Chrome’s
Password Leak Detection Protocol with will appear in USENIX Security 202324 May 2023
The paper Hot Pixels: Frequency, Power, and Temperature Attacks on GPUs and Arm SoCs with will appear in USENIX Security 202311 May 2023
CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives will receive a Distinguished Paper Award at PLDI 2023.27 Apr 2023
The paper CacheFX: A Framework for Evaluating Cache Security with will appear in AsiaCCS 20232 Apr 2023
The paper CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives with will appear in PLDI 20231 Apr 2023
I am starting a new position at Ruhr University Bochum.14 Feb 2023
The paper BunnyHop: Exploiting the Instruction Prefetcher with will appear in USENIX Security 202327 Jan 2023
The paper Ultimate SLH: Taking Speculative Load Hardening to the Next Level with will appear in USENIX Security 202320 Jan 2023
CryptOpt: Automatic Optimization of Straightline Code accepted to the ICSE 2023 DEMO track11 Nov 2022
The paper The Gates of Time: Improving Cache Attacks with Transient Execution with will appear in USENIX Security 20232 Nov 2022
Published a new HotCRP-style conflicts generator.26 Aug 2022
The paper HammerScope: Observing DRAM Power Consumption Using Rowhammer with will appear in CCS 202231 Jul 2022
I will present a keynote titled Side Channels and the Art of Recovering Secrets from your Microarchitecture at DFRSW-APAC 202215 Jul 2022
The paper The Impostor Among US(B): Off Path Injection Attacks on USB Communications with will appear in USENIX Security 20238 Jul 2022
Preprint available CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives, co-authored with
,
,
,
,
,
,
,
,
,
, and
. 24 Jun 2022
The paper Spectre Declassified: Reading from the Right Place at the Wrong Time with will appear in IEEE SP 202331 May 2022
The paper Row, Row, Row Your Boat: How to Not Find Weak Keys in Pilsung with will appear in The Computer Journal25 Apr 2022
The paper Opportunities for Genetic Improvement of Cryptographic Code with will appear in GI@GECCO 20223 Apr 2022
Preprint available Spectre Declassified: Reading from the Right Place at the Wrong Time, co-authored with , , , , , , , , and 28 Feb 2022
I will serve on the PC of CFAIL 2022.8 Feb 2022
The paper SoK: Design Tools for Side-Channel-Aware Implementations with will appear in AsiaCCS 20225 Feb 2022
I am co-chairing the program committee of SEED 2022 with .1 Feb 2022
I will serve on the PC of ACISP 2022.27 Jan 2022
Preprint available CacheFX: A Framework for Evaluating Cache Security, co-authored with , , , , and 21 Jan 2022
I will serve as an associate chair on the program committee of IEEE S&P 2023.4 Jan 2022
I will serve on the PC of CCS 2022.31 Dec 2021
The paper DrawnApart: A Unique Device Identification Technique based on Remote GPU Fingerprinting with will appear in NDSS 20225 Nov 2021
The paper RSA Key Recovery from Digit Equivalence Information with will appear in ACNS 202224 Sep 2021
New blogpost: Surveillance is not necessary for secure vaccine passports22 Sep 2021
Added a copy of my PhD thesis because everyone should read it.19 Sep 2021
Received the certificate for the NSA Best Scientific Cybersecurity Paper Competition 2020 5 Sep 2021
The paper Rosita++: Automatic Higher-Order Leakage Elimination from Cryptographic Code with will appear in CCS 202111 Aug 2021
The paper Spook.js: Attacking Chrome Strict Site Isolation via Speculative Execution with will appear in IEEE SP 202215 Jun 2021
The paper Row, Row, Row Your Boat: How to Not Find Weak Keys in Pilsung with will appear in CFail 202128 May 2021
I will serve on the PC of USENIX Security 2022.17 Apr 2021
I will serve on the PC of CARDIS 2021.30 Mar 2021
I will serve on the PC of IEEE S&P 2022.17 Feb 2021
I will serve on the PC of DRAMSec 2021.31 Jan 2021
The paper Nonce@Once: A Single-Trace EM Side Channel Attack on Several Constant-Time Elliptic Curve Implementations in Mobile Platforms with will appear in Euro S&P 202118 Jan 2021
Added Resources for Postgraduate Students.14 Jan 2021
The recording of our Real World Crypto presentations on Rosita and CacheOut is available here.8 Dec 2020
The paper Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses with will appear in USENIX Security 20218 Dec 2020
The paper Security Architecture Framework for Enterprises with will appear in Enterprise Information Systems1 Dec 2020
The Spectre paper won the NSA’s 8th Annual Best Scientific Cybersecurity Research Paper Competition.21 Nov 2020
The paper CacheOut: Leaking Data on Intel CPUs via Cache Evictions with will appear in IEEE SP 202113 Nov 2020
Successful Discovery Project with Chitchanok Chuengsatiansup, Markus Wagner, Jason Xue, and Lejla Batina.4 Nov 2020
The paper Whack-a-Meltdown: Microarchitectural Security Games with will appear in IEEE S&P Magazine30 Oct 2020
I will serve on the program committee of ACISP 202127 Oct 2020
I am participating in a panel on Recent trends in Crypto at ECC 202023 Oct 2020
The paper Rosita: Towards Automatic Elimination of Power-Analysis Leakage in Ciphers with will appear in NDSS 202121 Oct 2020
Our project 'Intelligent Technologies for Smart Cryptography', with Chitchanok Chuengsatiansup, Markus Wagner, and Jason Xue, has been awarded ECMS Seed Funding.7 Oct 2020
I will serve on the PC of ESORICS 2021.26 Sep 2020
Added submission history page.17 Aug 2020
I am humbled and honoured to be named as a recipient of the SA 2020 Tall Poppy Award.