var bibbase_data = {"data":"\"Loading..\"\n\n
\n\n \n\n \n\n \n \n\n \n\n \n \n\n \n\n \n
\n generated by\n \n \"bibbase.org\"\n\n \n
\n \n\n
\n\n \n\n\n
\n\n Excellent! Next you can\n create a new website with this list, or\n embed it in an existing web page by copying & pasting\n any of the following snippets.\n\n
\n JavaScript\n (easiest)\n
\n \n <script src=\"https://bibbase.org/show?bib=https%3A%2F%2Fcomsec.ethz.ch%2Fwp-content%2Ffiles%2Fbibtex.bib&css=none&owner=&filter=authors:Razavi,keywords:(type_tier1|type_award),year:(2024|2023|2022)&fullnames=1&jsonp=1&jsonp=1\"></script>\n \n
\n\n PHP\n
\n \n <?php\n $contents = file_get_contents(\"https://bibbase.org/show?bib=https%3A%2F%2Fcomsec.ethz.ch%2Fwp-content%2Ffiles%2Fbibtex.bib&css=none&owner=&filter=authors:Razavi,keywords:(type_tier1|type_award),year:(2024|2023|2022)&fullnames=1&jsonp=1\");\n print_r($contents);\n ?>\n \n
\n\n iFrame\n (not recommended)\n
\n \n <iframe src=\"https://bibbase.org/show?bib=https%3A%2F%2Fcomsec.ethz.ch%2Fwp-content%2Ffiles%2Fbibtex.bib&css=none&owner=&filter=authors:Razavi,keywords:(type_tier1|type_award),year:(2024|2023|2022)&fullnames=1&jsonp=1\"></iframe>\n \n
\n\n

\n For more details see the documention.\n

\n
\n
\n\n
\n\n This is a preview! To use this list on your own web site\n or create a new web site from it,\n create a free account. The file will be added\n and you will be able to edit it in the File Manager.\n We will show you instructions once you've created your account.\n
\n\n
\n\n

To the site owner:

\n\n

Action required! Mendeley is changing its\n API. In order to keep using Mendeley with BibBase past April\n 14th, you need to:\n

    \n
  1. renew the authorization for BibBase on Mendeley, and
  2. \n
  3. update the BibBase URL\n in your page the same way you did when you initially set up\n this page.\n
  4. \n
\n

\n\n

\n \n \n Fix it now\n

\n
\n\n
\n\n\n
\n \n \n
\n
\n  \n 2024\n \n \n (3)\n \n \n
\n
\n \n \n
\n \n\n \n \n \n \n \n \n ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms.\n \n \n \n \n\n\n \n Patrick Jattke; Max Wipfli; Flavien Solt; Michele Marazzi; Matej Bölcskei; and Kaveh Razavi.\n\n\n \n\n\n\n In USENIX Security, August 2024. \n \n\n\n\n
\n\n\n\n \n \n \"ZenHammer:Paper\n  \n \n \n \"ZenHammer:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 59 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{jattke_zenhammer_2024,\n\ttitle = {{ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms}}, \n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/zenhammer_sec24.pdf URL=https://comsec.ethz.ch/zenhammer},\n\tbooktitle = {{USENIX Security}},\n\tauthor = {Jattke, Patrick and Wipfli, Max and Solt, Flavien and Marazzi, Michele and Bölcskei, Matej and Razavi, Kaveh},\n\tmonth = aug,\n\tyear = {2024},\n\tkeywords = {dir\\_dram, proj\\_mfs, proj\\_promise, proj\\_nccr, type\\_conf, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n Cascade: CPU Fuzzing via Intricate Program Generation.\n \n \n \n \n\n\n \n Flavien Solt; Katharina Ceesay-Seitz; and Kaveh Razavi.\n\n\n \n\n\n\n In USENIX Security, August 2024. \n \n\n\n\n
\n\n\n\n \n \n \"Cascade:Paper\n  \n \n \n \"Cascade:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 228 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{solt_cascade_2024,\n\ttitle = {{Cascade: CPU Fuzzing via Intricate Program Generation}}, \n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/cascade_sec24.pdf URL=https://comsec.ethz.ch/cascade},\n\tbooktitle = {{USENIX Security}},\n\tauthor = {Solt, Flavien and Ceesay-Seitz, Katharina and Razavi, Kaveh},\n\tmonth = aug,\n\tyear = {2024},\n\tkeywords = {dir\\_designsec, proj\\_lastbug, proj\\_promise, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n HiFi-DRAM: Enabling High-fidelity DRAM Research by Uncovering Sense Amplifiers with IC Imaging.\n \n \n \n\n\n \n Michele Marazzi; Tristan Sachsenweger; Flavien Solt; Peng Zeng; Kubo Takashi; Maksym Yarema; and Kaveh Razavi.\n\n\n \n\n\n\n In ISCA, July 2024. \n \n\n\n\n
\n\n\n\n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{marazzi_hifidram_2024,\n\ttitle = {{HiFi-DRAM: Enabling High-fidelity DRAM Research by Uncovering Sense Amplifiers with IC Imaging}}, \n\tbooktitle = {{ISCA}},\n\tauthor = {Marazzi, Michele and Sachsenweger, Tristan and Solt, Flavien and Zeng, Peng and Takashi, Kubo and Yarema, Maksym and Razavi, Kaveh},\n\tmonth = jul,\n\tyear = {2024},\n\tkeywords = {dir\\_dram, proj\\_mfs, proj\\_promise, proj\\_nccr, type\\_conf, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n\n\n\n
\n
\n\n
\n
\n  \n 2023\n \n \n (3)\n \n \n
\n
\n \n \n
\n \n\n \n \n \n \n \n \n Phantom: Exploiting Decoder-detectable Mispredictions.\n \n \n \n \n\n\n \n Johannes Wikner; Daniël Trujillo; and Kaveh Razavi.\n\n\n \n\n\n\n In MICRO, October 2023. \n Best Paper Award, ETH medal\n\n\n\n
\n\n\n\n \n \n \"Phantom:Paper\n  \n \n \n \"Phantom:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 199 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{wikner_phantom_2023,\n\ttitle = {{Phantom: Exploiting Decoder-detectable Mispredictions}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/phantom_micro23.pdf URL=https://comsec.ethz.ch/research/microarch/inception},\n\tbooktitle = {{MICRO}},\n\tnote = {Best Paper Award, ETH medal},\n\tauthor = {Wikner, Johannes and Trujillo, Daniël and Razavi, Kaveh},\n\tmonth = oct,\n\tyear = {2023},\n\tkeywords = {dir\\_microarch, type\\_tier1, proj\\_promise}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n Inception: Exposing New Attack Surfaces with Training in Transient Execution.\n \n \n \n \n\n\n \n Daniël Trujillo; Johannes Wikner; and Kaveh Razavi.\n\n\n \n\n\n\n In USENIX Security, August 2023. \n ETH medal\n\n\n\n
\n\n\n\n \n \n \"Inception:Paper\n  \n \n \n \"Inception:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 145 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{trujillo_inception_2023,\n\ttitle = {{Inception: Exposing New Attack Surfaces with Training in Transient Execution}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/inception_sec23.pdf URL=https://comsec.ethz.ch/research/microarch/inception},\n\tbooktitle = {{USENIX Security}},\n\tnote = {ETH medal},\n\tauthor = {Trujillo, Daniël and Wikner, Johannes and Razavi, Kaveh},\n\tmonth = aug,\n\tyear = {2023},\n\tkeywords = {dir\\_microarch, type\\_tier1, proj\\_promise}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n REGA: Scalable Rowhammer Mitigation with Refresh-Generating Activations.\n \n \n \n \n\n\n \n Michele Marazzi; Flavien Solt; Patrick Jattke; Kubo Takashi; and Kaveh Razavi.\n\n\n \n\n\n\n In S&P, May 2023. \n Patent pending\n\n\n\n
\n\n\n\n \n \n \"REGA:Paper\n  \n \n \n \"REGA:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 111 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{marazzi_rega_2023,\n\ttitle = {{REGA}: {Scalable} {Rowhammer} {Mitigation} with {Refresh-Generating} {Activations}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/rega_sp23.pdf URL=https://comsec.ethz.ch/research/dram/rega},\n\tbooktitle = {{S\\&P}},\n\tnote = {Patent pending},\n\tauthor = {Marazzi, Michele and Solt, Flavien and Jattke, Patrick and Takashi, Kubo and Razavi, Kaveh},\n\tmonth = may,\n\tyear = {2023},\n\tkeywords = {dir\\_dram, proj\\_mfs, proj\\_promise, proj\\_nccr, type\\_conf, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n\n\n\n
\n
\n\n
\n
\n  \n 2022\n \n \n (7)\n \n \n
\n
\n \n \n
\n \n\n \n \n \n \n \n \n RemembERR: Leveraging Microprocessor Errata for Design Testing and Validation.\n \n \n \n \n\n\n \n Flavien Solt; Patrick Jattke; and Kaveh Razavi.\n\n\n \n\n\n\n In MICRO, October 2022. \n \n\n\n\n
\n\n\n\n \n \n \"RemembERR:Paper\n  \n \n \n \"RemembERR:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 46 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{solt_rememberr_2022,\n\ttitle = {{RemembERR: Leveraging Microprocessor Errata for Design Testing and Validation}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/rememberr_micro22.pdf URL=https://comsec.ethz.ch/research/hardware-design-security/rememberr},\n\tbooktitle = {{MICRO}},\n\tauthor = {Solt, Flavien and Jattke, Patrick and Razavi, Kaveh},\n\tmonth = oct,\n\tyear = {2022},\n\tkeywords = {dir\\_designsec, proj\\_lastbug, proj\\_promise, proj\\_nccr, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n Retbleed: Arbitrary Speculative Code Execution with Return Instructions.\n \n \n \n \n\n\n \n Johannes Wikner; and Kaveh Razavi.\n\n\n \n\n\n\n In USENIX Security, August 2022. \n Intel Bounty Reward, CSAW Europe finalist\n\n\n\n
\n\n\n\n \n \n \"Retbleed:Paper\n  \n \n \n \"Retbleed:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 67 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{wikner_retbleed_2022,\n\ttitle = {{Retbleed: Arbitrary Speculative Code Execution with Return Instructions}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/retbleed_sec22.pdf URL=https://comsec.ethz.ch/research/microarch/retbleed},\n\tbooktitle = {{USENIX Security}},\n\tauthor = {Wikner, Johannes and Razavi, Kaveh},\n\tnote = {Intel Bounty Reward, CSAW Europe finalist},\n\tmonth = aug,\n\tyear = {2022},\n\tkeywords = {dir\\_microarch, type\\_tier1, proj\\_promise}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTL.\n \n \n \n \n\n\n \n Flavien Solt; Ben Gras; and Kaveh Razavi.\n\n\n \n\n\n\n In USENIX Security, August 2022. \n Patent pending\n\n\n\n
\n\n\n\n \n \n \"CellIFT:Paper\n  \n \n \n \"CellIFT:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 35 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{solt_cellift_2022,\n\ttitle = {{CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTL}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/cellift_sec22.pdf URL=https://comsec.ethz.ch/cellift},\n\tbooktitle = {{USENIX Security}},\n\tauthor = {Solt, Flavien and Gras, Ben and Razavi, Kaveh},\n\tnote = {Patent pending},\n\tmonth = aug,\n\tyear = {2022},\n\tkeywords = {dir\\_designsec, proj\\_lastbug, proj\\_promise, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n ProTRR: Principled yet Optimal In-DRAM Target Row Refresh.\n \n \n \n \n\n\n \n Michele Marazzi; Patrick Jattke; Flavien Solt; and Kaveh Razavi.\n\n\n \n\n\n\n In S&P, May 2022. \n Patent pending, ETH Spark Award Nomination, CSAW Europe finalist\n\n\n\n
\n\n\n\n \n \n \"ProTRR:Paper\n  \n \n \n \"ProTRR:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 33 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{marazzi_protrr_2022,\n\ttitle = {{ProTRR}: {Principled} yet {Optimal} {In-DRAM} {Target Row Refresh}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/protrr_sp22.pdf URL=https://comsec.ethz.ch/research/dram/protrr},\n\tbooktitle = {{S\\&P}},\n\tnote = {Patent pending, ETH Spark Award Nomination, CSAW Europe finalist},\n\tauthor = {Marazzi, Michele and Jattke, Patrick and Solt, Flavien and Razavi, Kaveh},\n\tmonth = may,\n\tyear = {2022},\n\tkeywords = {dir\\_dram, proj\\_mfs, proj\\_nccr, type\\_conf, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n Blacksmith: Scalable Rowhammering in the Frequency Domain.\n \n \n \n \n\n\n \n Patrick Jattke; Victor Veen; Pietro Frigo; Stijn Gunter; and Kaveh Razavi.\n\n\n \n\n\n\n In S&P, May 2022. \n \n\n\n\n
\n\n\n\n \n \n \"Blacksmith:Paper\n  \n \n \n \"Blacksmith:URL\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 290 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{jattke_blacksmith_2022,\n\ttitle = {{Blacksmith}: {Scalable} {Rowhammering} in the {Frequency} {Domain}},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/blacksmith_sp22.pdf URL=https://comsec.ethz.ch/research/dram/blacksmith},\n\tbooktitle = {{S\\&P}},\n\tauthor = {Jattke, Patrick and van der Veen, Victor and Frigo, Pietro and Gunter, Stijn and Razavi, Kaveh},\n\tmonth = may,\n\tyear = {2022},\n\tkeywords = {dir\\_dram, proj\\_mfs, proj\\_nccr, type\\_conf, type\\_tier1}\n}\n\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux Kernel.\n \n \n \n \n\n\n \n Brian Johannesmeyer; Jakob Koschel; Kaveh Razavi; Herbert Bos; and Cristiano Giuffrida.\n\n\n \n\n\n\n In NDSS, April 2022. \n \n\n\n\n
\n\n\n\n \n \n \"Kasper:Paper\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 517 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{johannesmeyer_kasper_2022,\n\ttitle = {Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux Kernel},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/kasper_ndss22.pdf},\n\tbooktitle = {{NDSS}},\n\tauthor = {Johannesmeyer, Brian and Koschel, Jakob and Razavi, Kaveh and Bos, Herbert and Giuffrida, Cristiano},\n\tmonth = apr,\n\tyear = {2022},\n\tkeywords = {dir\\_microarch, type\\_conf, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n
\n \n\n \n \n \n \n \n \n DupeFS: Leaking Data Over the Network With Filesystem Deduplication Side Channels.\n \n \n \n \n\n\n \n Andrei Bacs; Saidgani Musaev; Kaveh Razavi; Cristiano Giuffrida; and Herbert Bos.\n\n\n \n\n\n\n In FAST, February 2022. \n \n\n\n\n
\n\n\n\n \n \n \"DupeFS:Paper\n  \n \n\n \n\n \n link\n  \n \n\n bibtex\n \n\n \n\n \n  \n \n 127 downloads\n \n \n\n \n \n \n \n \n \n \n\n  \n \n \n \n \n \n \n \n \n \n \n\n\n\n
\n
@inproceedings{dupefs_bacs_2022,\n\ttitle = {DupeFS: Leaking Data Over the Network With Filesystem Deduplication Side Channels},\n\turl = {Paper=https://comsec.ethz.ch/wp-content/files/dupefs_fast22.pdf},\n\tbooktitle = {{FAST}},\n\tauthor = {Bacs, Andrei and Musaev, Saidgani and Razavi, Kaveh and Giuffrida, Cristiano and Bos, Herbert},\n\tmonth = feb,\n\tyear = {2022},\n\tkeywords = {dir\\_os, dir\\_peripheral, type\\_conf, type\\_tier1}\n}\n\n
\n
\n\n\n\n
\n\n\n\n\n\n
\n
\n\n\n\n\n
\n\n\n \n\n \n \n \n \n\n
\n"}; document.write(bibbase_data.data);