VLDB 2026 Research / reviewers in the wild / expert
Lukas Lamster
dblp:220/3453
· DBLP profile ↗
13ranked-venue papers
4as first author
13since 2021 · last 2025
0000-0003-4046-8727ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 4 first-author · 13 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | FatPTE - Expanding Page Table Entries for Security
Lukas Lamster, Martin Unterguggenberger, Moritz Waser, David Schrammel, Stefan Mangard |
ARES (2) | 1 |
| 2025 | CHERI UNCHAINED: Generic Instruction and Register Control for CHERI Capabilities
Moritz Waser, Lukas Lamster, David Schrammel, Martin Unterguggenberger, Stefan Mangard |
ARES (2) | 2 |
| 2025 | WaitWatcher and WaitGuard: Detecting Flush-Based Cache Side-Channels Through Spurious Wakeups
Lukas Lamster, Fabian Rauscher, Martin Unterguggenberger, Stefan Mangard |
ESORICS (3) | 1 |
| 2025 | Code Encryption with Intel TME-MK for Control-Flow Enforcement
Martin Unterguggenberger, Lukas Lamster, Mathias Oberhuber, Simon Scherer, Stefan Mangard |
ESORICS (2) | 2 |
| 2025 | TME-Box: Scalable In-Process Isolation through Intel TME-MK Memory Encryption
Martin Unterguggenberger, Lukas Lamster, David Schrammel, Martin Schwarzl, Stefan Mangard |
NDSS | 2 |
| 2024 | Memory Tagging using Cryptographic Integrity on Commodity x86 CPUsabstractMemory tagging allows to establish memory safety for software developed in unsafe languages like C/C++. Since it is an effective mechanism with low architectural complexity, ISA extensions, like ARM MTE or SPARC ADI, already integrate memory tagging on the architectural level for commodity computer systems. However, despite being in high demand, memory tagging features are currently absent in modern x86 processors. This work presents IntegriTag, a hardware-enforced memory tagging solution for existing commodity x86 CPUs. We leverage the Intel® Total Memory Encryption-Multi-Key (Intel® TME-MK) hardware feature that was initially envisioned for virtual machine isolation to instead provide memory tagging capabilities on off-the-shelf x86 processors. Unlike ARM MTE and SPARC ADI, this does not require the integration of a separate tagged memory architecture, which would increase the overall system complexity. Instead, our solution allows us to implicitly enforce the desired security policies by incorporating them into the existing memory encryption integrity checks. In addition, our design addresses security issues that affect tagged memory architectures with small tag spaces. Intel® TME-MK allows for a greater number of key identifier bits, thus offering significantly stronger security compared to the 4-bit tags of ARM MTE and SPARC ADI. We implement a holistic open-source software framework based on Intel® TME-MK, supporting several software-controlled and hardware-enforced memory safety policies. Moreover, we evaluate our design's performance overhead and security properties, underlining the practicability and efficacy of our approach. Our design is binary-compatible with existing software and provides both temporal and spatial memory safety while imposing an overhead of 32–41%, which is significantly lower than the overheads of memory safety schemes in software on commodity hardware that provide comparable security properties. David Schrammel, Martin Unterguggenberger, Lukas Lamster, Salmin Sultana, Karanvir Grewal, Michael LeMay, David Durham, Stefan Mangard |
EuroS&P | 3 |
| 2024 | Voodoo: Memory Tagging, Authenticated Encryption, and Error Correction through MAGIC
Lukas Lamster, Martin Unterguggenberger, David Schrammel, Stefan Mangard |
USENIX Security Symposium | 1 |
| 2024 | Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android Kernels
Lukas Maar, Florian Draschbacher, Lukas Lamster, Stefan Mangard |
USENIX Security Symposium | 3 |
| 2023 | SPEAR-V: Secure and Practical Enclave Architecture for RISC-VabstractTrusted Execution Environments (TEEs) and enclaves have become increasingly popular and are used from embedded devices to cloud servers. Today, many enclave architectures exist for different ISAs. However, some suffer from performance issues and controlled-channel attacks, while others only support constrained use cases for embedded devices or impose unrealistic constraints on the software. Modern cloud applications require a more flexible architecture that is both secure against such attacks and not constrained by, e.g., a limited number of physical memory ranges. David Schrammel, Moritz Waser, Lukas Lamster, Martin Unterguggenberger, Stefan Mangard |
AsiaCCS | 3 |
| 2023 | Multi-Tag: A Hardware-Software Co-Design for Memory Safety based on Multi-Granular Memory TaggingabstractMemory safety vulnerabilities are a severe threat to modern computer systems allowing adversaries to leak or modify security-critical data. To protect systems from this attack vector, full memory safety is required. As software-based countermeasures tend to induce significant runtime overheads, which is not acceptable for production code, hardware assistance is needed. Tagged memory architectures, e.g., already offered by the ARM MTE and SPARC ADI extensions, assign meta-information to memory objects, thus allowing to implement memory safety policies. However, due to the high tag collision probability caused by the small tag sizes, the protection guarantees of these schemes are limited. Martin Unterguggenberger, David Schrammel, Pascal Nasahl, Robert Schilling, Lukas Lamster, Stefan Mangard |
AsiaCCS | 5 |
| 2023 | Cryptographically Enforced Memory SafetyabstractC/C++ memory safety issues, such as out-of-bounds errors, are still prevalent in today's applications. The presence of a single exploitable software bug allows an adversary to gain unauthorized memory access and ultimately compromise the entire system. Typically, memory safety schemes only achieve widespread adaption if they provide lightweight and practical security. Thus, hardware support is indispensable. However, countermeasures often restrict unauthorized access to data using heavy-weight protection mechanisms that extensively reshape the processor's microarchitecture and break legacy compatibility. Martin Unterguggenberger, David Schrammel, Lukas Lamster, Pascal Nasahl, Stefan Mangard |
CCS | 3 |
| 2023 | CSI:Rowhammer - Cryptographic Security and Integrity against RowhammerabstractIn this paper, we present CSI:Rowhammer, a principled hardware-software co-design Rowhammer mitigation with cryptographic security and integrity guarantees, that does not focus on any specific properties of Rowhammer. We design a new memory error detection mechanism based on a low-latency cryptographic MAC and an exception mechanism initiating a software-level correction routine. The exception handler uses a novel instruction-set extension for the error correction and resumes execution afterward. In contrast to regular ECC-DRAM that remains exploitable if more than 2 bits are flipped, CSI:Rowhammer maintains the security level of the cryptographic MAC. We evaluate CSI:Rowhammer in a gem5 proof-of-concept implementation. Under normal conditions, we see latency overheads below 0.75% and no memory overhead compared to off-the-shelf ECC-DRAM. While the average latency to correct a single bitflip is below 20 ns (compared to a range from a few nanoseconds to several milliseconds for state-of-the-art ECC memory), CSI:Rowhammer can detect any number of bitflips with overwhelming probability and correct at least 8 bitflips in practical time constraints. Jonas Juffinger, Lukas Lamster, Andreas Kogler, Maria Eichlseder, Moritz Lipp, Daniel Gruss |
SP | 2 |
| 2023 | HashTag: Hash-based Integrity Protection for Tagged Architectures
Lukas Lamster, Martin Unterguggenberger, David Schrammel, Stefan Mangard |
USENIX Security Symposium | 1 |