VLDB 2026 Research / reviewers in the wild / expert
Florian Stolz
dblp:272/7352
· DBLP profile ↗
6ranked-venue papers
1as first author
6since 2021 · last 2025
0000-0002-0898-8135ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Revisiting Prime+Prune+Probe: Pitfalls and RemediesabstractRandomizing the mapping of memory addresses to cache locations is a promising approach for protecting computer systems against cache attacks. Multiple randomized caches have been proposed recently, with the aim of preventing adversaries from creating eviction sets - collections of addresses that compete with target memory addresses on cache space. However, Purnal et al. (IEEE SP 2021) demonstrated the Prime+ Prune+ Probeattack, which allows attackers to efficiently build generalized eviction sets, enabling target memory address eviction with a high probability. As the complexity of constructing eviction set is a key factor in randomized cache design, the Prime+prune+probe attack significantly reduces the security bounds of these randomizing designs. Since the Prime+prune+probe attack is probabilistic, generalized eviction sets often get stuck after repeated use, making them ineffective for typical cache attack settings. Prior works have noticed this behavior and proposed mitigation approaches. These approaches are based on evicting members of the eviction set from the cache, either probabilistically, using random memory accesses, or directly, using dedicated flush instructions. However, these proposals do not analyze the effectiveness of the techniques or evaluate their success. In this work we revisit Prime+prune+probe and analyze it in light of the possibility of eviction sets getting stuck. We observe that flushing does not behave as anticipated in realistic cache architectures, where invalid cache lines are filled first before evicting other lines. We further propose a new technique for allowing repeated attacks - combining random noise with flushing. We conduct an in-depth analysis of all discussed techniques and compare their complexity attacking an AES T-table implementation. We find that combining probabilistic eviction with flushing outperforms the traditional approaches by a factor of two, allowing attackers to increase the granularity and observe victim processes even better than in prior works. Moritz Peters, Florian Stolz, Jan Philipp Thoma, Tim Güneysu, Yuval Yarom |
ACSAC | 2 |
| 2025 | To Extend or Not to Extend: Agile Masking Instructions for PQC
Markus Krausz, Georg Land, Florian Stolz, Jan Richter-Brockmann, Tim Güneysu |
CANS | 3 |
| 2024 | Three Sidekicks to Support Spectre CountermeasuresabstractThe Spectre attack revealed a critical security threat posed by speculative execution and since then numerous related attacks have been discovered and exploited to leak secrets across process boundaries. As the primary cause of the attack is deeply rooted in the microarchitectural processor design, mitigating speculative execution attacks with minimal impact on performance is far from straightforward. For example, various countermeasures have been proposed to limit speculative execution for certain instruction patterns, however, resulting in severe performance overheads. In this paper, we propose a set of code transformations to reduce the number of speculatively executed instructions and therefore significantly reduce the performance overhead of various countermeasures. We evaluate our code transformations combined with a hardware-based countermeasure in gem5. Our results demonstrate that our code transformations speed up the secure system by up to 16.6%. Markus Krausz, Jan Philipp Thoma, Florian Stolz, Marc Fyrbiak, Tim Güneysu |
DATE | 3 |
| 2024 | Cips: The Cache Intrusion Prevention System
Jan Philipp Thoma, Florian Stolz, Tim Güneysu |
ESORICS (4) | 2 |
| 2023 | Recommendation for a Holistic Secure Embedded ISA Extension
Florian Stolz, Marc Fyrbiak, Pascal Sasdrich, Tim Güneysu |
ACNS | 1 |
| 2021 | On the Design and Misuse of Microcoded (Embedded) Processors - A Cautionary Note
Nils Albartus, Clemens Nasenberg, Florian Stolz, Marc Fyrbiak, Christof Paar, Russell Tessier |
USENIX Security Symposium | 3 |