VLDB 2026 Research / reviewers in the wild / expert
Tamara Silbergleit Lehman
dblp:191/7792 · also Tamara Lehman
· DBLP profile ↗
14ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0001-9779-1838ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SSMR: Statically Detecting Speculation Safe Memory Regions to Mitigate Transient Execution AttacksabstractTransient execution attacks exploit speculative execution to leak confidential data through unauthorized transient memory accesses. We make the observation that transient attacks can be identified by one unusual memory access, the transient sensitive data access. To protect systems from such attacks while minimizing performance overhead, we propose leveraging compile-time information to identify memory operations that cannot extract sensitive data and can therefore be deemed safe. Safe memory operations are allowed to execute transiently, causing no extra performance cost. Unsafe memory operations delay accessing the memory system until they are no longer in a speculative state, preventing unauthorized transient accesses to sensitive data. To communicate this information to the microarchitecture, we introduce the set safe memory region (ssmr) instruction. Inserted automatically by the compiler, it establishes the memory regions that may be accessed transiently by a sequence of instructions. This defense incurs only a 7% performance overhead compared to the insecure baseline and mitigates at least two variants of transient execution attacks. Ange-Thierry Ishimwe, Sam McDiarmid-Sterling, Zack McKevitt, Tamara Silbergleit Lehman |
CC | 4 |
| 2026 | Characterizing and Optimizing Cache Placement for Secure Memory MetadataabstractTo mitigate well-studied memory vulnerabilities [14], [21], [24], [25], memory devices may implement secure memory [9], [10], [27], [29], [34], an extension to the memory controller logic that guarantees the confidentiality and integrity of data stored in main memory. The memory encryption engine (MEE) is responsible for decrypting and integrity verifying data that comes from the off-chip memory device [10]. To protect outgoing data, the MEE encrypts and protects the integrity of data in 64B-block granularity. To provide confidentiality, the MEE uses counter-mode encryption (CME) [22], [23], [34]. To verify data’s integrity, the MEE maintains a per-block hashed message authentication code (HMAC) [7], [16] in memory. Additionally, Bonsai Merkle Trees (BMT) are used [27] to protect the encryption counter from replay attacks. The root of the BMT is stored on-chip in trusted hardware and serves as a root of trust for authentications. When fetching data from memory, the requisite metadata (i.e., encryption counter, HMAC, and path through the integrity tree) are also fetched to decrypt the data and authenticate its state against the HMAC and trusted root. This ensures that the processor does not perform computation on any corrupted data and that data is private while off-chip. Blake Cragen, R. Iris Bahar, Tamara Silbergleit Lehman |
ISPASS | 4 |
| 2026 | Di5Guise: 5G Privacy with vSIMabstractSIM cards have been the key building block of user authentication and security in cellular networks. While they are meant to serve as privacy protecting elements in cellular communications, they can be the root cause of privacy loss. Current eSIMs come with a fixed device profile—comprising a secret key, a certificate, and a unique eUICC identifier—that permanently binds every subscriber profile provisioned on the device to that device profile. This binding enables an attacker with the vantage point of a cellular operator to correlate subscriber identities back to a single device, piecing together a complete pattern of life—online activities, movement patterns, and real-world identity—even when users rotate subscriber identities or employ traffic obfuscation techniques. To mitigate this concern, we introduce Di5Guise, a privacy-enhancing architecture that breaks this correlation at its root by decoupling the device identity from the subscriber identity. Central to Di5Guise is vSIM, a virtualized SIM card that enables dynamic device profile provisioning, allowing each subscriber profile to be associated with a distinct, unlinkable device profile. Di5Guise establishes trust with the operator by ensuring that vSIM is running on secure hardware in a trustworthy state. We prototype Di5Guise on a Field Programmable Gate Array (FPGA) board and integrate it with srsRAN to demonstrate full compatibility with existing 5G infrastructure. Using a complex user correlation model, we show that Di5Guise reduces user re-identification accuracy from 93% to 49% when combined with obfuscation. Shirin Ebadi, Zach Moolman, Tamara Silbergleit Lehman, Eric Keller |
Proc. Priv. Enhancing Technol. | 3 |
| 2026 | Coeus: Secure Similarity-Aware Data Integrity Verification for Secure MemoriesabstractAs secure memory support is becoming an essential part of modern processors, minimizing its performance overheads is crucial. With the ever-increasing complexity of attacks, more users desire to enable memory security primitives in environments with minimal physical control (e.g., cloud systems and edge devices). However, the performance overheads are burdening the wide adoption of such support. In particular, the performance overheads for data integrity verification are very costly. Thus, a timely need is to revisit secure memory implementations and provide practical optimizations to bridge the performance gap between secure and non-secure memory systems. In this paper, we exploit many applications' well-known data similarity characteristics to reduce the performance overheads of integrity verification significantly. Specifically, we proposeCoeus, a secure memory implementation that allows secure exploitation of data similarity in improving the performance of integrity verification. We discuss the security challenges for exploiting data similarity and how we elegantly overcome them in well-established secure memory implementations. Our evaluation, based on memory-intensive benchmarks from SPEC2006 and SPEC2017, shows that Coeus can eliminate 33.2% (up to 99%) of the expensive MAC calculations and thus improve the performance by 21.8% (up to 90%). Kazi Abu Zubair, Rahaf Abdullah, David Mohaisen, Tamara Silbergleit Lehman, Amro Awad |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | CommTox: Contextually-Aware Community Perceived Toxicity Classification
Ayan Chowdhury, Rhett Hanscom, Tamara Silbergleit Lehman, Qin Lv, Shivakant Mishra |
ASONAM (2) | 3 |
| 2025 | THORN-ML: Transparent Hardware Offloaded Resilient Networks for RDMA based Distributed ML WorkloadsabstractDistributed deep learning (DDL) requires a great investment in cloud infrastructure, including accelerated compute nodes and networking hardware capable of supporting high-performance networking, e.g., Remote Direct Memory Access (RDMA). When a host running a DDL application becomes unreachable, the cost can be high as application-level failure recovery is slow and disruptive. When the host is unreachable due to host failure, this is unavoidable; however, when the network components involved in attaching the host to the core data center network fail, we argue that this cost is avoidable. This paper introduces THORN-ML, a hardware-offloaded resilient network architecture that is completely transparent to DDL applications and works with commodity hardware. We evaluate THORN-ML on a cluster of 5 nodes with Nvidia A100 GPUs and Mellanox ConnectX-5 NICs, with several applications leveraging model parallelism and/or data parallelism, and find that THORN-ML reduces disruption from minutes (impacting the whole cluster) to milliseconds (impacting packets that can be re-transmitted). Maziyar Nazari, Daniel Noland, Giulio Sidoretti, Erika Hunhoff, Tamara Silbergleit Lehman, Eric Keller |
SoCC | 5 |
| 2024 | A Midsummer Night's Tree: Efficient and High Performance Secure SCMabstractSecure memory is a highly desirable property to prevent memory corruption-based attacks. The emergence of nonvolatile, storage class memory (SCM) devices presents new challenges for secure memory. Metadata for integrity verification, organized in a Bonsai Merkle Tree (BMT), is cached on-chip in volatile caches, and may be lost on a power failure. As a consequence, care is required to ensure that metadata updates are always propagated into SCM. To optimize metadata updates, state-of-the-art approaches propose lazy update crash consistent metadata schemes. However, few consider the implications of their optimizations on on-chip area, which leads to inefficient utilization of scarce on-chip space. In this paper, we propose A Midsummer Night's Tree (AMNT), a novel "tree within a tree" approach to provide crash consistent integrity with low run-time overhead while limiting on-chip area for security metadata. Our approach offloads the potential hardware complexity of our technique to software to keep area overheads low. Our proposed mechanism results in significant improvements (a 41% reduction in execution overhead on average versus the state-of-the-art) for in-memory storage applications while significantly reducing the required on-chip area to implement our protocol. Kidus Workneh, Jac McCarty, Joseph Izraelevitz, Tamara Silbergleit Lehman, R. Iris Bahar |
ASPLOS (3) | 5 |
| 2023 | SpecCheck: A Tool for Systematic Identification of Vulnerable Transient Execution in gem5abstractSpeculative execution attacks leverage a processor's speculative execution optimization to leak secret information. Previous attempts to generalize transient execution attacks often analyze specific gadgets in software or look solely at mi-croarchitectural state artifacts to explain the fundamental logic behind these attacks. In this work, we present SPECCHECK, a systematic security verification for detecting potential transient data leakage. SPECCHECK is based on a description of a generic transient execution attack in the form of a register based Finite State Machine (FSM). SPECCHECK'S key insight is the fact that transient execution attacks involve both the software and the hardware to succeed and the only way to verify if a design is capable of mitigating such attacks is by considering both at verification time. The FSM is easily incorporated into commonly used processor simulators. As a proof of concept, we implement SPECCHECK'S FSM in the gem5 simulator to check for suspicious program flows during an arbitrary program's simulation and lay the groundwork for a robust and systematic hardware security verification tool. We show that SPECCHECK is able to identify known transient execution gadgets in two of the main Spectre variants, variant 1 (PHT) and 2 (BTB), with a 100% true positives and an average of 14% false positive rate for malicious sequences of code and an average of 19% vulnerable windows identified for the SPEC benchmark suite. Zack McKevitt, Ashutosh Trivedi 0001, Tamara Silbergleit Lehman |
PACT | 3 |
| 2022 | Acuerdo: Fast Atomic Broadcast over RDMAabstractAtomic broadcast protocols ensure that messages are delivered to a group of machines in some total order, even when some of these machines can fail. These protocols are key to making distributed services fault-tolerant, as their total order guarantee allows keeping multiple service replicas in sync. But, unfortunately, atomic broadcast protocols are also notoriously expensive. Joseph Izraelevitz, Gaukas Wang, Rhett Hanscom, Kayli Silvers, Tamara Silbergleit Lehman, Gregory V. Chockler, Alexey Gotsman |
ICPP | 5 |
| 2021 | Analyzing behavioral changes of Twitter users after exposure to misinformationabstractSocial media platforms have been exploited to disseminate misinformation in recent years. The widespread online misinformation has been shown to affect users' beliefs and is connected to social impact such as polarization. In this work, we focus on misinformation's impact on specific user behavior and aim to understand whether general Twitter users changed their behavior after being exposed to misinformation. We compare the before and after behavior of exposed users to determine whether the frequency of the tweets they posted, or the sentiment of their tweets underwent any significant change. Our results indicate that users overall exhibited statistically significant changes in behavior across some of these metrics. Through language distance analysis, we show that exposed users were already different from baseline users before the exposure. We also study the characteristics of two specific user groups, multi-exposure and extreme change groups, which were potentially highly impacted. Finally, we study if the changes in the behavior of the users after exposure to misinformation tweets vary based on the number of their followers or the number of followers of the tweet authors, and find that their behavioral changes are all similar. Yichen Wang 0008, Richard Han 0001, Tamara Silbergleit Lehman, Qin Lv, Shivakant Mishra |
ASONAM | 3 |
| 2021 | Analyzing Twitter Users' Behavior Before and After Contact by the Russia's Internet Research AgencyabstractSocial media platforms have been exploited to conduct election interference in recent years. In particular, the Russian-backed Internet Research Agency (IRA) has been identified as a key source of misinformation spread on Twitter prior to the 2016 U.S. presidential election. The goal of this research is to understand whether general Twitter users changed their behavior in the year following first contact from an IRA account. We compare the before and after behavior of contacted users to determine whether there were differences in their mean tweet count, the sentiment of their tweets, and the frequency and sentiment of tweets mentioning @realDonaldTrump or @HillaryClinton. Our results indicate that users overall exhibited statistically significant changes in behavior across most of these metrics, and that those users that engaged with the IRA generally showed greater changes in behavior. Upasana Dutta, Rhett Hanscom, Jason Shuo Zhang, Richard Han 0001, Tamara Silbergleit Lehman, Qin Lv, Shivakant Mishra |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2020 | Understanding How Readers Determine the Legitimacy of Online News Articles in the Era of Fake NewsabstractInternet users are routinely exposed to fake news in their social media feeds. The main goal of this paper is to identify the factors readers consider important in discriminating against fake news from true news when reading an online news article. We design and conduct three surveys using Amazon Mechanical Turk to identify the top factors and rate them under diverse scenarios. Our results suggest that people perceive news Source and Content to be the most important factors, in general, to distinguish fake news from true news, however, their importance reduces in practice when people actually read a news article. Furthermore, the importance of different factors in the credibility determination of a news article varies with people's political leanings. Our work is the first of its kind and offers new insights into how people determine the legitimacy of online news articles. Srihaasa Pidikiti, Jason Shuo Zhang, Richard Han 0001, Tamara Silbergleit Lehman, Qin Lv, Shivakant Mishra |
ASONAM | 4 |
| 2018 | MAPS: Understanding Metadata Access Patterns in Secure MemoryabstractSecure memory increases both the latency and energy required for memory accesses. To reduce these overheads, computer architects have sought to cache metadata on the processor chip, but placing metadata in a simple cache has not been as effective as expected. With a detailed analysis of metadata access patterns, we clarify myths in metadata caching and provide insight into more efficient caching strategies. We provide three observations that can help architects design future metadata caches. First, caching all metadata types improves efficiency. Second, the size of the metadata cache should match the reuse distance of the metadata. Third, when designing a better eviction policy, the traditional Belady's MIN algorithm cannot be used as the optimal replacement policy. Tamara Silbergleit Lehman, Andrew D. Hilton, Benjamin C. Lee |
ISPASS | 1 |
| 2016 | PoisonIvy: Safe speculation for secure memoryabstractEncryption and integrity trees guard against physical attacks, but harm performance. Prior academic work has speculated around the latency of integrity verification, but has done so in an insecure manner. No industrial implementations of secure processors have included speculation. This work presents PoisonIvy, a mechanism which speculatively uses data before its integrity has been verified while preserving security and closing address-based side-channels. PoisonIvy reduces performance overheads from 40% to 20% for memory intensive workloads and down to 1.8%, on average. Tamara Silbergleit Lehman, Andrew D. Hilton, Benjamin C. Lee |
MICRO | 1 |