Publications (17)
Meltdown
Moritz Lipp, Michael Schwarz, Daniel Gruss +7
The security of computer systems fundamentally relies on memory isolation, e.g., kernel address ranges are marked as non-accessible and are protected from user access. In this pape…
Thunderhammer: Rowhammer Bitflips via PCIe and Thunderbolt (USB-C)
Robert Dumitru, Junpeng Wan, Daniel Genkin +4
In recent years, Rowhammer has attracted significant attention from academia and industry alike. This technique, first published in 2014, flips bits in memory by repeatedly accessi…
CacheOut: Leaking Data on Intel CPUs via Cache Evictions
Stephan van Schaik, Marina Minkin, Andrew Kwong +2
Recent transient-execution attacks, such as RIDL, Fallout, and ZombieLoad, demonstrated that attackers can leak information while it transits through microarchitectural buffers. Na…
CacheFX: A Framework for Evaluating Cache Security
Daniel Genkin, William Kosasih, Fangfei Liu +3
Over the last two decades, the danger of sharing resources between programs has been repeatedly highlighted. Multiple side-channel attacks, which seek to exploit shared components…
Light Commands: Laser-Based Audio Injection Attacks on Voice-Controllable Systems
Takeshi Sugawara, Benjamin Cyr, Sara Rampazzi +2
We propose a new class of signal injection attacks on microphones by physically converting light to sound. We show how an attacker can inject arbitrary audio signals to a target mi…
Revisiting Lightweight Compiler Provenance Recovery on ARM Binaries
Jason Kim, Daniel Genkin, Kevin Leach
A binary's behavior is greatly influenced by how the compiler builds its source code. Although most compiler configuration details are abstracted away during compilation, recoverin…