VLDB 2026 Research / reviewers in the wild / expert
Salman Qazi
dblp:305/3800
· DBLP profile ↗
5ranked-venue papers
0as first author
5since 2021 · last 2026
0009-0009-4311-4394ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization
Diego Meyer, Patrick Jattke, Michele Marazzi, Salman Qazi, Daniel Moghimi, Kaveh Razavi |
SP | 4 |
| 2025 | MOAT: Securely Mitigating Rowhammer with Per-Row Activation Counters
Moinuddin K. Qureshi, Salman Qazi |
ASPLOS (1) | 2 |
| 2025 | MoPAC: Efficiently Mitigating Rowhammer with Probabilistic Activation CountingabstractRowhammer has worsened over the last decade.Existing in-DRAM solutions, such as TRR, were broken with simple patterns.In response, the recent DDR5 JEDEC standards modify the DRAM array to enable Per-Row Activation Counters (PRAC) for tracking aggressor rows.They also extend the DRAM timings to support the operations required to update the PRAC counters.Unfortunately, the increased memory timings cause significant performance overheads (on average 10%) even for benign applications and even at current Rowhammer thresholds.The goal of this paper is to minimize the slowdown of PRAC while retaining the security benefits of PRAC.This paper proposes Mitigating Rowhammer with Probabilistic Activation Counts (MoPAC), which reduces the slowdown of updating the PRAC counters by performing the updates probabilistically, thereby incurring the latency overhead of counter updates for only a small subset of activations.To ensure security in the presence of probabilistic counters, MOPAC adjusts the threshold at which the row undergoes mitigation.We propose two variants of MoPAC: MoPAC-C (Memory-Controller Side) and MoPAC-D (DRAM Side).MoPAC-C relies on having two types of precharge commands: one that incurs normal latency and does not do counter updates, and the other that incurs higher latency and performs counter updates.MoPAC-C probabilistically chooses when the longer precharge must be used to perform update of the PRAC counter.MoPAC-D is a completely in-DRAM solution that probabilistically selects which activations will be selected for performing counter updates and obtains the time required for counter-updates using ALERT or REF.Our evaluations show that, for a Rowhammer threshold of 500 (10× lower than current thresholds), MoPAC-C and MoPAC-D incur an average slowdown of only 1.7% and 0.7%, much less than the 10% incurred by PRAC.MoPAC removes one of the major obstacles to the commercial adoption of PRAC. Suhas Vittal, Salman Qazi, Poulami Das 0005, Moinuddin K. Qureshi |
ISCA | 2 |
| 2024 | MINT: Securely Mitigating Rowhammer with a Minimalist in-DRAM TrackerabstractThis paper investigates secure low-cost in-DRAM trackers for mitigating Rowhammer (RH). In-DRAM solutions have the potential to solve the RH problem within the DRAM chip without relying on other parts of the system. However, in-DRAM mitigation suffers from two key challenges: First, the mitigations are synchronized with refresh, which means that we cannot mitigate at arbitrary times. Second, the SRAM area available for aggressor tracking is limited to only a few bytes. Existing low-cost in-DRAM trackers (such as TRR) have been broken by well-crafted access patterns, whereas, secure counter-based schemes require impractical overheads of hundreds or thousands of entries per bank. The goal of our paper is to develop an ultra-low-cost secure in-DRAM tracker. Our solution is based on a simple observation: If only one row can be mitigated at refresh, we should ideally need to track only one row. We propose a Minimalist In-DRAM Tracker (MINT), which provides secure mitigation with just a single entry. Unlike prior trackers that decide the row to be mitigated based on the past behavior (select based on activation counts) or solely based on the current activation (select with some probability), MINT decides which row in the future will get mitigated. At each refresh, MINT probabilistically decides which activation in the upcoming interval will be selected for mitigation at the next refresh. MINT provides guaranteed protection against classic single and double-sided attacks. We also derive the minimum RH threshold (TRH*) tolerated by MINT across all patterns. MINT has a TRH* of 1482, which can be lowered to 356 with RFM. The TRH* of MINT is lower than a prior counter-based design with 677 entries per bank, and is within 2x of the TRH* of an idealized design that stores one-counter-per-row. We also analyze the impact of refresh postponement on the TRH* of low-cost in-DRAM trackers, and propose an efficient solution to make such trackers compatible with refresh postponement. Moinuddin K. Qureshi, Salman Qazi, Aamer Jaleel |
MICRO | 2 |
| 2022 | Half-Double: Hammering From the Next Row Over
Andreas Kogler, Jonas Juffinger, Salman Qazi, Yoongu Kim, Moritz Lipp, Nicolas Boichat, Eric Shiu, Mattias Nissler, Daniel Gruss |
USENIX Security Symposium | 3 |