4 papers
μRL: Discovering Transient Execution Vulnerabilities Using Reinforcement Learning
M. Caner Tol, Kemal Derya, Berk Sunar
We propose using reinforcement learning to address the challenges of discovering microarchitectural vulnerabilities, such as Spectre and Meltdown, which exploit subtle interactions…
FAULT+PROBE: A Generic Rowhammer-based Bit Recovery Attack
Kemal Derya, M. Caner Tol, Berk Sunar
Rowhammer is a security vulnerability that allows unauthorized attackers to induce errors within DRAM cells. To prevent fault injections from escalating to successful attacks, a wi…
Mayhem: Targeted Corruption of Register and Stack Variables
Andrew J. Adiletta, M. Caner Tol, Yarkın Doröz +1
In the past decade, many vulnerabilities were discovered in microarchitectures which yielded attack vectors and motivated the study of countermeasures. Further, architectural and p…
ZeroLeak: Using LLMs for Scalable and Cost Effective Side-Channel Patching
M. Caner Tol, Berk Sunar
Security critical software, e.g., OpenSSL, comes with numerous side-channel leakages left unpatched due to a lack of resources or experts. The situation will only worsen as the pac…