VLDB 2026 Research / reviewers in the wild / expert
Kai Lehniger
dblp:223/0478
· DBLP profile ↗
6ranked-venue papers
5as first author
4since 2021 · last 2026
0000-0002-3274-2469ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Elevating Parallel Shadow Stack Concepts for Architectures With Register WindowsabstractRegister windows are a processor feature that was originally developed to reduce the frequency for register spilling. This paper investigates how this mechanism can be used to implement a parallel shadow stack to protect return addresses from being corrupted. Furthermore, multiple improvements based on properties directly following the usage of register windows are proposed. Different configurations of parallel shadow stacks are evaluated based on prototype implementations on an ESP32 microcontroller and tested with different benchmarks. Performance overheads below 0.01% for CoreMark, below 3% for the worst case in MbedsTLS, and a worst case scenario of 22.153% for a recursive function show that our concepts are able to be efficiently developed even for embedded devices like the ESP32. Kai Lehniger, Peter Langendörfer |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Hardware-Friendly Nyström Approximation for Water Treatment Anomaly DetectionabstractThis paper presents an approach to accelerate One-Class Support Vector Machines (SVM) using a hardware-friendly kernel that doesn't rely on multiplication operations, thus adaptable to hardware platforms. Leveraging Nyström approximation, we implemented a pipeline and compared its performance against a software implementation using libsvm. Furthermore, we evaluated the efficiency of our approach by deploying it on an FPGA. Our experiments, conducted on the SWaT dataset, demonstrate a 50x speedup using the FPGA implementation, achieving a classification time of 21 microseconds per instance. Importantly, we find no degradation in performance, as measured by the f-score of the attack class in the test set. This study explores the potential of hardware acceleration in optimizing anomaly detection systems for real-time applications. Marcin Aftowicz, Markus Fritscher, Kai Lehniger, Christian Wenger, Peter Langendörfer, Marcin Brzozowski |
IECON | 3 |
| 2023 | Window Canaries: Re-Thinking Stack Canaries for Architectures With Register WindowsabstractThis paper presents Window Canaries, a novel approach to Stack Canaries for architectures with a register window that protects return addresses and stack pointers without the need of adding additional instruction to each potentially vulnerable function. Instead, placement and check of the canary word is moved to window exception handlers that are responsible to handle register window overflows and underflows. The approach offers low performance overhead while guaranteeing that return addresses are protected by stack buffer overflows without relying on a heuristic that decides which functions to instrument. The contributions of this paper are a complete implementation of the approach for the Xtensa LX architecture with register window option as well as a performance evaluation and discussion of advantages and drawbacks. Kai Lehniger, Peter Langendörfer |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Combination of ROP Defense Mechanisms for Better Safety and Security in Embedded SystemsabstractControl flow integrity (CFI) checks are used in desktop systems, in order to protect them from various forms of attacks, but they are rarely investigated for embedded systems, due to their introduced overhead. The contribution of this paper is an efficient software implementation of a CFI-check for ARM-and Xtensa processors. Moreover, we propose the combination of this CFI-check with another defense mechanism against return-oriented-programming (ROP). We show that by this combination the security is significantly improved. Moreover, it will also in-crease the safety of the system, since the combination can detect a failed ROP-attack and bring the system in a safe state, which is not possible when using each technique separately. We will also report on the introduced overhead in code size and run time. Kai Lehniger, Mario Schölzel, Jonas Jelonek, Peter Tabatt, Marcin Aftowicz, Peter Langendörfer |
DSD | 1 |
| 2020 | Challenges of Return-Oriented-Programming on the Xtensa Hardware ArchitectureabstractThis paper shows how the Xtensa architecture can be attacked with Return-Oriented-Programming (ROP). The presented techniques include possibilities for both supported Application Binary Interfaces (ABIs). Especially for the windowed ABI a powerful mechanism is presented that not only allows to jump to gadgets but also to manipulate registers without relying on specific gadgets. This paper purely focuses on how the properties of the architecture itself can be exploited to chain gadgets and not on specific attacks or a gadget catalog. Kai Lehniger, Marcin Aftowicz, Peter Langendörfer, Zoya Dyka |
DSD | 1 |
| 2018 | Heuristic for Page-Based Incremental Reprogramming of Wireless Sensor NodesabstractWireless sensor nodes may need code updates for a variety of reasons. These updates are costly in terms of energy and can lead to early battery failure. Incremental reprogramming can save energy by reusing the existing code image on the node and transmitting only a delta file. It can not be assumed that the flash memory is randomly erasable and programmable. When updating the flash page by page, usable data could be unintentionally overwritten, which increases the size of the delta. This paper proposes heuristics for page-based incremental reprogramming of wireless sensor nodes, to find a good sequence for pages in the flash memory to be updated that lead to an overall smaller delta file. A graph model for page dependencies is presented, graph-based algorithms are proposed and page dependency weights are estimated. Results show that the page update sequence can have a significant impact on the size of the delta file. Kai Lehniger, Stefan Weidling, Mario Schölzel |
DDECS | 1 |