VLDB 2026 Research / reviewers in the wild / expert
Meni Orenbach
dblp:172/0911
· DBLP profile ↗
7ranked-venue papers
4as first author
3since 2021 · last 2025
0000-0002-8180-3598ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | BlueGuard: Accelerated Host and Guest Introspection Using DPUs
Meni Orenbach, Rami Ailabouni, Nael Masalha, Ahmad Saleh, Frank Block, Fritz Alder, Ofir Arkin, Ahmad Atamli-Reineh |
USENIX Security Symposium | 1 |
| 2024 | One for All and All for One: GNN-based Control-Flow Attestation for Embedded DevicesabstractControl-Flow Attestation (CFA) is a security service that allows an entity (verifier) to verify the integrity of code execution on a remote computer system (prover). Existing CFA schemes suffer from impractical assumptions, such as requiring access to the prover’s internal state (e.g., memory or code), the complete Control-flow graph (CFG) of the prover’s software, large sets of measurements, or tailor-made hardware. Moreover, current CFA schemes are inadequate for attesting embedded systems due to their high computational overhead and resource usage.In this paper, we overcome the limitations of existing CFA schemes for embedded devices by introducing RAGE, a novel, lightweight CFA approach with minimal requirements. RAGE can detect Code Reuse Attacks (CRA), including control-and non-control-data attacks. It efficiently extracts features from one execution trace and leverages Unsupervised Graph Neural Networks (GNNs) to identify deviations from benign executions. The core intuition behind RAGE is to exploit the correspondence between execution trace, execution graph, and execution embeddings to eliminate the unrealistic requirement of having access to a complete CFG.We evaluate RAGE on embedded benchmarks and demonstrate that (i) it detects 40 real-world attacks on embedded software; (ii) Further, we stress our scheme with synthetic returnoriented programming (ROP) and data-oriented programming (DOP) attacks on the real-world embedded software benchmark Embench, achieving 98.03% (ROP) and 91.01% (DOP) F1-Score while maintaining a low False Positive Rate of 3.19%; (iii) Additionally, we evaluate RAGE on OpenSSL, used by millions of devices and achieve 97.49% and 84.42% F1-Score for ROP and DOP attack detection, with an FPR of 5.47%. Marco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn, Ahmad Atamli-Reineh, Ahmad-Reza Sadeghi |
SP | 3 |
| 2023 | Fuzzing LibraryOSes for Iago vulnerabilitiesabstractWe present a new fuzzing approach for Iago vulnerabilities in Library OSes for SGX enclaves. Based on the filesystem model, it allows efficiently combining valid and malicious values to reach deeper paths in LibraryOS to identify more potential security vulnerabilities. Leonid Dyachkov, Meni Orenbach, Mark Silberstein |
SYSTOR | 2 |
| 2020 | Autarky: closing controlled channels with self-paging enclavesabstractAs the first widely-deployed secure enclave hardware, Intel SGX shows promise as a practical basis for confidential cloud computing. However, side channels remain SGX's greatest security weakness. Inparticular, the "controlled-channel attack" on enclave page faults exploits a longstanding architectural side channel and still lacks effective mitigation. Meni Orenbach, Andrew Baumann, Mark Silberstein |
EuroSys | 1 |
| 2019 | CoSMIX: A Compiler-based System for Secure Memory Instrumentation and Execution in Enclaves
Meni Orenbach, Yan Michalevsky, Christof Fetzer, Mark Silberstein |
USENIX ATC | 1 |
| 2017 | Eleos: ExitLess OS Services for SGX EnclavesabstractIntel Software Guard extensions (SGX) enable secure and trusted execution of user code in an isolated enclave to protect against a powerful adversary. Unfortunately, running I/O-intensive, memory-demanding server applications in enclaves leads to significant performance degradation. Such applications put a substantial load on the in-enclave system call and secure paging mechanisms, which turn out to be the main reason for the application slowdown. In addition to the high direct cost of thousands-of-cycles long SGX management instructions, these mechanisms incur the high indirect cost of enclave exits due to associated TLB flushes and processor state pollution. Meni Orenbach, Pavel Lifshits, Marina Minkin, Mark Silberstein |
EuroSys | 1 |
| 2016 | NearBucket-LSH: Efficient Similarity Search in P2P Networks
Naama Kraus, David Carmel, Idit Keidar, Meni Orenbach |
SISAP | 4 |