VLDB 2026 Research / reviewers in the wild / expert
Frank McKeen
dblp:151/7533
· DBLP profile ↗
2ranked-venue papers
0as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Hardware security and side channels · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Processor architecture and microarchitecture · 62% Memory systems · 38% |
Topics — the 10 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels
microarchitectural side channel |
0.5 | 1 | 2021 | Speculative interference attacks: breaking invisible speculation schemes · ASPLOS 2021 |
Hardware security and side channels › microarchitectural attacks › transient execution attack › speculative execution attack
spectre |
0.5 | 1 | 2021 | Speculative interference attacks: breaking invisible speculation schemes · ASPLOS 2021 |
Hardware security and side channels › microarchitectural attacks › transient execution attack
speculative execution attack |
0.5 | 1 | 2021 | Speculative interference attacks: breaking invisible speculation schemes · ASPLOS 2021 |
Processor architecture and microarchitecture
speculative execution |
0.5 | 1 | 2021 | Speculative interference attacks: breaking invisible speculation schemes · ASPLOS 2021 |
Hardware security and side channels › side-channel countermeasures
cache partitioning |
0.2 | 1 | 2016 | CATalyst: Defeating last-level cache side channel attacks in cloud computing · HPCA 2016 |
Hardware security and side channels › side-channel attack
cache side-channel attacks |
0.2 | 1 | 2016 | CATalyst: Defeating last-level cache side channel attacks in cloud computing · HPCA 2016 |
Hardware security and side channels
trusted execution environments |
0.2 | 1 | 2016 | CATalyst: Defeating last-level cache side channel attacks in cloud computing · HPCA 2016 |
Memory systems
cache |
0.1 | 1 | 2021 | Speculative interference attacks: breaking invisible speculation schemes · ASPLOS 2021 |
Memory systems
cache management |
0.1 | 1 | 2016 | CATalyst: Defeating last-level cache side channel attacks in cloud computing · HPCA 2016 |
Memory systems › cache management
cache partitioning |
0.1 | 1 | 2016 | CATalyst: Defeating last-level cache side channel attacks in cloud computing · HPCA 2016 |
Methods — techniques the papers use, named apart from their topics
timing analysis · 1.0proof-of-concept attack · 1.0pseudo-locking · 0.5intel cache allocation technology · 0.5hardware-software hybrid cache partitioning · 0.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Speculative interference attacks: breaking invisible speculation schemesabstractRecent security vulnerabilities that target speculative execution (e.g., Spectre) present a significant challenge for processor design. These highly publicized vulnerabilities use speculative execution to learn victim secrets by changing the cache state. As a result, recent computer architecture research has focused on invisible speculation mechanisms that attempt to block changes in cache state due to speculative execution. Prior work has shown significant success in preventing Spectre and other attacks at modest performance costs. In this paper, we introduce speculative interference attacks, which show that prior invisible speculation mechanisms do not fully block speculation-based attacks that use cache state. We make two key observations. First, mis-speculated younger instructions can change the timing of older, bound-to-retire instructions, including memory operations. Second, changing the timing of a memory operation can change the order of that memory operation relative to other memory operations, resulting in persistent changes to the cache state. Using both of these observations, we demonstrate (among other attack variants) that secret information accessed by mis-speculated instructions can change the order of bound-to-retire loads. Load timing changes can therefore leave secret-dependent changes in the cache, even in the presence of invisible speculation mechanisms. We show that this problem is not easy to fix. Speculative interference converts timing changes to persistent cache-state changes, and timing is typically ignored by many cache-based defenses. We develop a framework to understand the attack and demonstrate concrete proof-of-concept attacks against invisible speculation mechanisms. We conclude with a discussion of security definitions that are sufficient to block the attacks, along with preliminary defense ideas based on those definitions. Mohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu, Zirui Neil Zhao, Thomas Unterluggauer, Josep Torrellas, Carlos V. Rozas, Adam Morrison 0001, Frank McKeen, Fangfei Liu, Ron Gabor, Christopher W. Fletcher, Abhishek Basak, Alaa R. Alameldeen |
ASPLOS | 11 |
| 2016 | CATalyst: Defeating last-level cache side channel attacks in cloud computingabstractCache side channel attacks are serious threats to multi-tenant public cloud platforms. Past work showed how secret information in one virtual machine (VM) can be extracted by another co-resident VM using such attacks. Recent research demonstrated the feasibility of high-bandwidth, low-noise side channel attacks on the last-level cache (LLC), which is shared by all the cores in the processor package, enabling attacks even when VMs are scheduled on different cores. This paper shows how such LLC side channel attacks can be defeated using a performance optimization feature recently introduced in commodity processors. Since most cloud servers use Intel processors, we show how the Intel Cache Allocation Technology (CAT) can be used to provide a system-level protection mechanism to defend from side channel attacks on the shared LLC. CAT is a way-based hardware cache-partitioning mechanism for enforcing quality-of-service with respect to LLC occupancy. However, it cannot be directly used to defeat cache side channel attacks due to the very limited number of partitions it provides. We present CATalyst, a pseudo-locking mechanism which uses CAT to partition the LLC into a hybrid hardware-software managed cache. We implement a proof-of-concept system using Xen and Linux running on a server with Intel processors, and show that LLC side channel attacks can be defeated. Furthermore, CATalyst only causes very small performance overhead when used for security, and has negligible impact on legacy applications. Fangfei Liu, Qian Ge 0001, Yuval Yarom, Frank McKeen, Carlos V. Rozas, Gernot Heiser, Ruby B. Lee |
HPCA | 4 |