VLDB 2026 Research / reviewers in the wild / expert
Marc Andrysco
dblp:165/5403
· DBLP profile ↗
3ranked-venue papers
3as first author
0since 2021 · last 2018
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Hardware security and side channels · 66% Cryptographic primitives and cryptanalysis · 28% Privacy and data protection · 6% | |
| Software engineering, system software, and programming languages
1 paper |
Compilers and program optimization · 77% Programming languages and type systems · 23% |
Topics — the 5 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels › side-channel attack
timing side channel |
0.5 | 2 | 2018 | Towards Verified, Constant-time Floating Point Operations · CCS 2018 On Subnormal Floating Point and Abnormal Timing · IEEE Symposium on Security and Privacy 2015 |
Cryptographic primitives and cryptanalysis › cryptographic implementation
constant-time implementation |
0.3 | 1 | 2018 | Towards Verified, Constant-time Floating Point Operations · CCS 2018 |
Compilers and program optimization
floating-point conversion |
0.2 | 1 | 2016 | Printing floating-point numbers: a faster, always correct method · POPL 2016 |
Hardware security and side channels
side-channel attack |
0.2 | 1 | 2015 | On Subnormal Floating Point and Abnormal Timing · IEEE Symposium on Security and Privacy 2015 |
Programming languages and type systems › type systems
numeric types |
0.1 | 1 | 2016 | Printing floating-point numbers: a faster, always correct method · POPL 2016 |
Methods — techniques the papers use, named apart from their topics
domain-specific language · 0.3SMT solver · 0.3LLVM bitcode · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | Towards Verified, Constant-time Floating Point OperationsabstractThe runtimes of certain floating-point instructions can vary up to two orders of magnitude with instruction operands, allowing attackers to break security and privacy guarantees of real systems (\eg browsers). To prevent attacks due to such floating-point timing channels, we introduce CTFP, an efficient, machine-checked, and extensible system that transforms unsafe floating-point operations into safe, constant-time computations. CTFP relies on two observations. First, that it is possible to execute floating-point computations in constant-time by emulating them in software; and second, that most security critical applications do not require full IEEE-754 floating-point precision. We use these observations to: eliminate certain classes of dangerous values from ever reaching floating-point hardware; emulate floating-point operations on dangerous values when eliminating them would severely alter application semantics; and, leverage fast floating-point hardware when it is safe to do so. We implement the constant-time transformations with our own domain-specific language that produces LLVM bitcode. Since the transformations themselves equate to bit surgery on already complicated floating-point arithmetic, we use a satisfiability modulo theories (SMT) solver to ensure that their behavior fits our specifications. Finally, we find that CTFP neither breaks real world applications nor incurs overwhelming overhead. Marc Andrysco, Andres Nötzli, Fraser Brown, Ranjit Jhala, Deian Stefan |
CCS | 1 |
| 2016 | Printing floating-point numbers: a faster, always correct methodabstractFloating-point numbers are an essential part of modern software, recently gaining particular prominence on the web as the exclusive numeric format of Javascript. To use floating-point numbers, we require a way to convert binary machine representations into human readable decimal outputs. Existing conversion algorithms make trade-offs between completeness and performance. The classic Dragon4 algorithm by Steele and White and its later refinements achieve completeness --- i.e. produce correct and optimal outputs on all inputs --- by using arbitrary precision integer (bignum) arithmetic which leads to a high performance cost. On the other hand, the recent Grisu3 algorithm by Loitsch shows how to recover performance by using native integer arithmetic but sacrifices optimality for 0.5% of all inputs. We present Errol, a new complete algorithm that is guaranteed to produce correct and optimal results for all inputs while simultaneously being 2x faster than the incomplete Grisu3 and 4x faster than previous complete methods. Marc Andrysco, Ranjit Jhala, Sorin Lerner |
POPL | 1 |
| 2015 | On Subnormal Floating Point and Abnormal TimingabstractWe identify a timing channel in the floating point instructions of modern x86 processors: the running time of floating point addition and multiplication instructions can vary by two orders of magnitude depending on their operands. We develop a benchmark measuring the timing variability of floating point operations and report on its results. We use floating point data timing variability to demonstrate practical attacks on the security of the Fire fox browser (versions 23 through 27) and the Fuzz differentially private database. Finally, we initiate the study of mitigations to floating point data timing channels with libfixedtimefixedpoint, a new fixed-point, constant-time math library. Modern floating point standards and implementations are sophisticated, complex, and subtle, a fact that has not been sufficiently recognized by the security community. More work is needed to assess the implications of the use of floating point instructions in security-relevant software. Marc Andrysco, David Kohlbrenner, Keaton Mowery, Ranjit Jhala, Sorin Lerner, Hovav Shacham |
IEEE Symposium on Security and Privacy | 1 |