VLDB 2026 Research / reviewers in the wild / expert
Dean Sullivan
dblp:144/4578
· DBLP profile ↗
15ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0002-7186-4346ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 2 first-author · 3 since 2021Security and privacy · 6 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | When Repairs Are Not Unique: Rethinking RTL Repair Benchmarks
Maisha Mastora, Dean Sullivan |
ACM Great Lakes Symposium on VLSI | 2 |
| 2026 | IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel Isolation
Yingjie Cao, Xiaogang Zhu 0001, Dean Sullivan, Lei Xue 0001, Chenxiong Qian, Minrui Yan, Xiapu Luo |
NDSS | 3 |
| 2025 | Poster: PainNOVA: Privacy-Aware Voice-Based Pain-Level DetectionabstractPain-level detection is vital to determine proper medical treatment. Existing self-reporting, behavioral, and image-based pain detection methods typically lead to high costs for professional staff and clinical equipment and also have a high risk of leaking sensitive information, which could be exploited by adversaries to learn gender, age group, and underlying health conditions. To address these challenges, we propose a privacy-aware voice-based pain-level detection framework, which extracts frequency-domain characteristics from audio files, removes the gender-sensitive features from the identified characteristics, and trains a convolutional neural network (CNN) to perform 3-level pain classification. Our preliminary analysis and experiments based on a commonly adopted database (TAME Pain dataset) indicate that log-Mel spectrogram and zero-crossing rate are two promising voice features for effective pain-level classification. We further extend our study to a nonverbal dataset, VIVAE (Variably Intense Vocalizations of Affect and Emotion Corpus), and confirm that the identified voice features are applicable to both verbal and nonverbal patients for pain classification. Andrew Lu, Mashrafi Alam Kajol, Wei Lu 0018, Dean Sullivan |
CCS | 4 |
| 2024 | Microscope: Causality Inference Crossing the Hardware and Software Boundary from Hardware PerspectiveabstractThe increasing complexity of System-on-Chip (SoC) designs and the rise of third-party vendors in the semiconductor industry have led to unprecedented security concerns. Traditional formal methods struggle to address software-exploited hardware bugs, and existing solutions for hardware-software co-verification often fall short. This paper presents Microscope, a novel framework for inferring software instruction patterns that can trigger hardware vulnerabilities in SoC designs. Microscope enhances the Structural Causal Model (SCM) with hardware features, creating a scalable Hardware Structural Causal Model (HW-SCM). A domain-specific language (DSL) in SMT-LIB represents the HW-SCM and predefined security properties, with incremental SMT solving deducing possible instructions. Microscope identifies causality to determine whether a hardware threat could result from any software events, providing a valuable resource for patching hardware bugs and generating test input. Extensive experimentation demonstrates Microscope’s capability to infer the causality of a wide range of vulnerabilities and bugs located in SoC-level benchmarks. Zhaoxiang Liu, Kejun Chen, Dean Sullivan, Orlando Arias, Raj Gautam Dutta, Yier Jin, Xiaolong Guo 0001 |
ASPDAC | 3 |
| 2023 | PDNPulse: Sensing PCB Anomaly With the Intrinsic Power Delivery NetworkabstractThe ubiquitous presence of printed circuit boards (PCBs) in modern electronic systems and embedded devices makes their integrity a top security concern. To take advantage of the economies of scale, today’s PCB design and manufacturing are often performed by suppliers around the globe, exposing them to many security vulnerabilities along the segmented PCB supply chain. Moreover, the increasing complexity of the PCB designs also leaves ample room for numerous sneaky board-level attacks to be implemented throughout each stage of a PCB’s lifetime, threatening many electronic devices. In this paper, we proposePDNPulse, a power delivery network (PDN) based PCB anomaly detection framework that can identify a wide spectrum of board-level malicious modifications. PDNPulse leverages the fact that the PDN’s characteristics are inevitably affected by modifications to the PCB. By detecting changes to the PDN impedance profile against the golden model and using the Frechet distance-based anomaly detection algorithms, PDNPulse can robustly and successfully discern malicious modifications across the system. Using PDNPulse, we conduct extensive experiments on seven commercial-off-the-shelf PCBs, covering different design scales, different threat models, and seven different anomaly types. The results confirm that PDNPulse creates an effective security asymmetry between attack and defense. Huifeng Zhu, Haoqi Shan, Dean Sullivan, Xiaolong Guo 0001, Yier Jin, Xuan Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Invisible Finger: Practical Electromagnetic Interference Attack on Touchscreen-based Electronic DevicesabstractTouchscreen-based electronic devices such as smart phones and smart tablets are widely used in our daily life. While the security of electronic devices have been heavily investigated recently, the resilience of touchscreens against various attacks has yet to be thoroughly investigated. In this paper, for the first time, we show that touchscreen-based electronic devices are vulnerable to intentional electromagnetic interference (IEMI) attacks in a systematic way and how to conduct this attack in a practical way. Our contribution lies in not just demonstrating the attack, but also analyzing and quantifying the underlying mechanism allowing the novel IEMI attack on touchscreens in detail. We show how to calculate both the minimum amount of electric field and signal frequency required to induce touchscreen ghost touches. We further analyze our IEMI attack on real touchscreens with different magnitudes, frequencies, duration, and multitouch patterns. The mechanism of controlling the touchscreen-enabled electronic devices with IEMI signals is also elaborated. We design and evaluate an out-of-sight touchscreen locator and touch injection feedback mechanism to assist a practical IEMI attack. Our attack works directly on the touchscreen circuit regardless of the touchscreen scanning mechanism or operating system. Our attack can inject short-tap, long-press, and omnidirectional gestures on touchscreens from a distance larger than the average thickness of common tabletops. Compared with the state-of-the-art touchscreen attack, ours can accurately inject different types of touch events without the need for sensing signal synchronization, which makes our attack more robust and practical. In addition, rather than showing a simple proof-of-concept attack, we present and demonstrate the first ready-to-use IEMI based touchscreen attack vector with end-to-end attack scenarios Haoqi Shan, Zihao Zhan, Dean Sullivan, Shuo Wang 0003, Yier Jin |
SP | 4 |
| 2021 | Quantifying Rowhammer Vulnerability for DRAM SecurityabstractRowhammer is a memory-based attack that leverages capacitive-coupling to induce faults in modern dynamic random-access memory (DRAM). Over the last decade, a significant number of Rowhammer attacks have been presented to reveal that it is a severe security issue capable of causing privilege escalations, launching distributed denial-of-service (DDoS) attacks, and even runtime attack such as control flow hijacking. Moreover, the Rowhammer vulnerability has also been identified and validated in both cloud computing and data center environments, threatening data security and privacy at a large scale. Various solutions have been proposed to counter Rowhammer attacks but existing methods lack a circuit-level explanation of the capacitive-coupling phenomenon in modern DRAMs, the key cause of Rowhammer attacks.In this paper, we develop an analytical model of capacitive-coupling vulnerabilities in DRAMs. We thoroughly analyze all parameters in the mathematical model contributing to the Rowhammer vulnerability and quantify them through real DRAM measurements. We validate the model with different attributions on a wide range of DRAM brands from various manufacturers. Through our model we re-evaluate existing Rowhammer attacks on both DDR3 and DDR4 memory, including the recently developed TRRespass attack. Our analysis presents a new Rowhammer attack insight and will guide future research in this area. Huifeng Zhu, Dean Sullivan, Xiaolong Guo 0001, Xuan Zhang 0001, Yier Jin |
DAC | 3 |
| 2020 | SaeCAS: Secure Authenticated Execution Using CAM-Based Vector StorageabstractAuthenticated execution (AE) is a security mechanism that cryptographically validates an application's code as it executes, as well as verifies its control flow. AE provides fully local guarantees which can deliver protection for control flow, instruction flow, and software intellectual property which makes it ideal for devices with little to no connectivity. However, we find that previous AE approaches make concessions in their implementation that severely hinder their security guarantees. In this article, we examine the weaknesses in previous AE approaches and why they occur. We also introduce SAECAS as a mechanism to reliably perform AE in an embedded device. We formally prove the security aspects of SAECAS, demonstrating its security capabilities. Moreover, we implement SAECAS on a RISC-V core and test it on a Terasic DE2-115 FPGA board to demonstrate its capabilities, showing that a reliable system can be made with a hardware overhead of ≈ 2× when including extra SoC components and no performance impact. Orlando Arias, Dean Sullivan, Haoqi Shan, Yier Jin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2018 | Microarchitectural Minefields: 4K-Aliasing Covert Channel and Multi-Tenant Detection in Iaas Clouds
Dean Sullivan, Orlando Arias, Travis Meade, Yier Jin |
NDSS | 1 |
| 2017 | ATRIUM: Runtime attestation resilient under memory attacksabstractRemote attestation is an important security service that allows a trusted party (verifier) to verify the integrity of a software running on a remote and potentially compromised device (prover). The security of existing remote attestation schemes relies on the assumption that attacks are software-only and that the prover's code cannot be modified at runtime. However, in practice, these schemes can be bypassed in a stronger and more realistic adversary model that is hereby capable of controlling and modifying code memory to attest benign code but execute malicious code instead - leaving the underlying system vulnerable to Time of Check Time of Use (TOCTOU) attacks. In this work, we first demonstrate TOCTOU attacks on recently proposed attestation schemes by exploiting physical access to prover's memory. Then we present the design and proof-of-concept implementation of ATRIUM, a runtime remote attestation system that securely attests both the code's binary and its execution behavior under memory attacks. ATRIUM provides resilience against both software- and hardware-based TOCTOU attacks, while incurring minimal area and performance overhead. Shaza Zeitouni, Ghada Dessouky, Orlando Arias, Dean Sullivan, Ahmad Ibrahim 0002, Yier Jin, Ahmad-Reza Sadeghi |
ICCAD | 4 |
| 2017 | LAZARUS: Practical Side-Channel Resilient Kernel-Space Randomization
David Gens, Orlando Arias, Dean Sullivan, Christopher Liebchen, Yier Jin, Ahmad-Reza Sadeghi |
RAID | 3 |
| 2016 | Strategy without tactics: policy-agnostic hardware-enhanced control-flow integrityabstractControl-flow integrity (CFI) is a general defense against code-reuse exploits that currently constitute a severe threat against diverse computing platforms. Existing CFI solutions (both in software and hardware) suffer from shortcomings such as (i) inefficiency, (ii) security weaknesses, or (iii) are not scalable. In this paper, we present a generic hardware-enhanced CFI scheme that tackles these problems and allows to enforce diverse CFI policies. Our approach fully supports multi-tasking, shared libraries, prevents various forms of code-reuse attacks, and allows CFI protected code and legacy code to co-exist. We evaluate our implementation on SPARC LEON3 and demonstrate its high efficiency. Dean Sullivan, Orlando Arias, Lucas Davi, Per Larsen, Ahmad-Reza Sadeghi, Yier Jin |
DAC | 1 |
| 2015 | HAFIX: hardware-assisted flow integrity extensionabstractCode-reuse attacks like return-oriented programming (ROP) pose a severe threat to modern software on diverse processor architectures. Designing practical and secure defenses against code-reuse attacks is highly challenging and currently subject to intense research. However, no secure and practical system-level solutions exist so far, since a large number of proposed defenses have been successfully bypassed. To tackle this attack, we present HAFIX (Hardware-Assisted Flow Integrity eXtension), a defense against code-reuse attacks exploiting backward edges (returns). HAFIX provides fine-grained and practical protection, and serves as an enabling technology for future control-flow integrity instantiations. This paper presents the implementation and evaluation of HAFIX for the Intel® Siskiyou Peak and SPARC embedded system architectures, and demonstrates its security and efficiency in code-reuse protection while incurring only 2% performance overhead. Lucas Davi, Matthias Hanreich, Debayan Paul, Ahmad-Reza Sadeghi, Patrick Koeberl, Dean Sullivan, Orlando Arias, Yier Jin |
DAC | 6 |
| 2014 | FIGHT-Metric: Functional Identification of Gate-Level Hardware TrustworthinessabstractTo address the concern that a complete detection scheme for effective hardware Trojan identification is lacking, we have designed an RTL security metric in order to evaluate the quality of IP cores (with the same or similar functionality) and counter Trojan attacks at the pre-fabrication stages of the IP design flow. The proposed security metric is constructed on top of two criteria, from which a quantitative security value can be assigned to the target circuit: 1) Distribution of controllability; 2) Existence of rare events. The proposed metric, called FIGHT, is an automated tool whereby malicious modifications to ICs and/or the vulnerability of the IP core can be identified, by monitoring both internal node controllability and the corresponding control value distribution plotted as a histogram. Experimentation on an RS232 module was performed to demonstrate our dual security criteria and proved security degradation to the IP module upon hardware Trojan insertion. Dean Sullivan, Jeff Biggers, Guidong Zhu, Shaojie Zhang 0001, Yier Jin |
DAC | 1 |
| 2014 | Real-time trust evaluation in integrated circuitsabstractThe use of side-channel measurements and fingerprinting, in conjunction with statistical analysis, has proven to be the most effective method for accurately detecting hardware Trojans in fabricated integrated circuits. However, these post-fabrication trust evaluation methods overlook the capabilities of advanced design skills that attackers can use in designing sophisticated Trojans. To this end, we have designed a Trojan using power-gating techniques and demonstrate that it can be masked from advanced side-channel fingerprinting detection while dormant. We then propose a real-time trust evaluation framework that continuously monitors the on-board global power consumption to monitor chip trustworthiness. The measurements obtained corroborate our frameworks effectiveness for detecting Trojans. Finally, the results presented are experimentally verified by performing measurements on fabricated Trojan-free and Trojan-infected variants of a reconfigurable linear feedback shift register (LFSR) array. Yier Jin, Dean Sullivan |
DATE | 2 |