Florent Bruguier

dblp:32/10313 · DBLP profile ↗
← Back
13ranked-venue papers
1as first author
9since 2021 · last 2026
0000-0002-7897-5700ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 9 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Microarchitectural Analysis of Speculative Execution Patterns in RISC-V using Machine Learning and ISA-Level Masking Wrappers
Maria Mushtaq, Lirida A. B. Naviner, Jawad Haj-Yahya, Florent Bruguier
IOLTS5
2026 Traphalt: Indirect Core Halt via Trap Handling to Halt a RISC-V Core from User Mode through Kernel-Mediated Fault Handling
Maria Mushtaq, Lirida A. B. Naviner, Jawad Haj-Yahya, Florent Bruguier
SECRYPT (2)5
2025 Fault Analysis through Body Bias Injection on the FLASH Memory Accelerator of a Microcontroller
abstract
The FLASH interface is a crucial component in modern Microcontrollers (MCUs), serving as an intermediary for transferring instructions between the processor and program memory. Previous studies have demonstrated the effectiveness of Electromagnetic Fault Injection (EMFI) and Laser Fault Injection (LFI) in disrupting the operation of FLASH accelerators, leading to instruction line replay and skip faults. However these studies are limited to the case of sequential code and to a single FLASH interface configuration of the target MCU. In this work, we present an investigation on the impact of Body Bias Injection (BBI) on the FLASH accelerator in a 32-bit MCU.The experiments confirm that BBI can similarly induce instruction line replay and skip faults. A detailed analysis of the fault manifestations under various operational configurations of the FLASH accelerator is provided. The study has also extended the fault model to the case of branch operation (non-sequential code).This research contributes a refined understanding of FLASH interface fault behavior under BBI, and highlights the security implication of the decorrelated design between the Program Counter and the FLASH interface.
Ziling Liao, Florent Bruguier, Philippe Maurine
FDTC2
2025 Body Bias Injection on the FLASH Memory Accelerator of a 32-Bit Microcontroller
abstract
Program flow attacks involve disrupting the flow of instruction execution in microcontrollers (MCUs), thereby threatening their operation. While traditional studies focus on program counter or instruction corruptions within pipelines, little attention has been paid to the stages between FLASH memory and the CPU, such as memory accelerators. Body Bias Injection (BBI) is a fault injection technique in which a voltage pulse is applied to the backside of an integrated circuit, i.e. its substrate, causing localized disruptions in the power network. Despite its proven effectiveness in inducing transient faults, to the best of our knowledge, there is no information on its impact on MCU program flow. Within this context, this paper demonstrates that BBI can efficiently disrupt MCU program flow, causing entire instruction lines to be skipped or repeated. It also shows that the most sensitive part of the MCUs against BBI is likely to be the memory accelerator rather than the processor itself.
Ziling Liao, Florent Bruguier, Philippe Maurine
IOLTS2
2024 Power Analysis Attack Against post-SAT Logic Locking schemes
abstract
Due to the globalization of the semiconductor industry, Integrated Circuits (ICs) and Intellectual Properties (IPs) are susceptible to specific threats. IP piracy, overproduction, and introduction of hardware Trojans can indeed compromise valuable design information and trust in the design flow. Logic Locking (LL) is one of the most popular Design-for-Trust techniques that aims to thwart these threats because of the wide range of risks it can prevent. This approach evolves from year to year in order to make it resistant to ever more advanced attacks. While most advanced LL solutions are assumed to be resistant against differential power analysis (DPA), we propose a new attack framework for challenging these approaches and show on several benchmarks that it is possible to reveal more than 88% of the key bits used for locking the designs thanks to DPA.
Nassim Riadi, Florent Bruguier, Pascal Benoit, Sophie Dupuis, Marie-Lise Flottes
ETS2
2024 Hardware Accelerator for FIPS 202 Hash Functions in Post-Quantum Ready SoCs
abstract
In today’s digital landscape, cryptography plays a vital role in ensuring communication security through encryption and authentication algorithms. While traditional cryptographic methods rely on hard mathematical problems for security, the rise of quantum computing threatens their effectiveness. Post-Quantum Cryptography (PQC) algorithms, like CRYSTALSKyber, aim to withstand quantum attacks. Recently standardized, CRYSTALS-Kyber is a lattice-based algorithm designed to resist quantum attacks. However, its implementation faces computational challenges, particularly with Keccak-based functions, which are crucial for security and upon which the FIPS 202 standard is based. Our paper addresses this technological challenge by designing a FIPS 202 hardware accelerator to enhance CRYSTALS-Kyber efficiency and security. We chose to implement the entire FIPS 202 standard in hardware in order to widen the applicability of the accelerator to all possible algorithms that rely on such hash functions, taking care to provide realistic assumptions on system-level integration inside a System-on-Chip (SoC). We provide results in terms of area, frequency, and clock cycles for both ASIC and FPGA targets. An area reduction of up to $22.3 \%$ is achieved with respect to state-ofthe-art solutions. In addition, we integrated the accelerator inside a 32-bit RISC-V based security-oriented SoC, where we show a strong performance gain on CRYSTALS-Kyber execution. The design presented in this paper performs better in all Kyber1024 primitives, with an improvement up to $3.21 \times$ in Kyber-KeyGen.
Diamante Simone Crescenzo, Rafael Carrera Rodriguez, Riccardo Alidori, Florent Bruguier, Emanuele Valea, Pascal Benoit, Alberto Bosio
IOLTS4
2024 Decoding Attack Behaviors by Analyzing Patterns in Instruction-Based Attacks using gem5
abstract
The diversity of Instruction Set Architectures (ISAs), each with its unique constraints and optimization strategies, presents significant opportunities and challenges in processor design. Modern processor vendors exploit these ISAs to enhance security, reliability, and performance. Recent security vulnerabilities, notably Spectre and Meltdown, have highlighted the critical need for robust hardware security measures. In this paper, we employ gem5, a state-of-the-art cycle-accurate simulation tool, to simulate the Spectre attack. We developed and modified scripts for both x86 and ARM architectures to ensure compatibility with gem5 version 23.1. Our simulation setup involved running attack scenarios under various configurations to gather comprehensive data on cache misses, cache hits, mispredicted branches, and level 2 cache hits and misses. In the simulation, we analyzed the trace files generated by gem5, utilizing a range of debug flags such as Exec for disassembly (dasm) insights. By detailed analysis of cache and branch prediction using detailed debug data revealed by gem5 traces, we identify some specific attack patterns that are useful for automating the detection of the attacks. Our future work aims to expand this analysis to include additional attack vectors and find more attack patterns, thereby strengthening our attack pattern recognition capabilities.
Maria Mushtaq, Lirida A. B. Naviner, Florent Bruguier, Jawad Haj-Yahya, Pascal Benoit
RSP4
2021 Transit-Guard: An OS-based Defense Mechanism Against Transient Execution Attacks
abstract
Transient attacks manipulate speculative execution to alter the control flow path in an application program and modify microarchitectural state. These state changes are not captured by the existing Instruction Set Architectures (ISAs). In this paper, we propose a novel OS-level detection-based mitigation mechanism, called Transit-Guard, that uses machine learning and real-time behavioral data of concurrent processes to detect and subsequently mitigate these attacks at run-time.
Maria Mushtaq, David Novo, Florent Bruguier, Pascal Benoit, Muhammad Khurram Bhatti
ETS3
2021 Implementing Rowhammer Memory Corruption in the gem5 Simulator
abstract
Modern computer memories have shown to have reliability issues. The main memory is the target of a security threat called Rowhammer, which causes bit flips in adjacent victim cells of aggressor rows. Numerous countermeasures have been proposed, some of the most efficient ones relying on memory controller modifications, which make them non-integrable in existing systems. These solutions have to be effective against attacks on current and future architectures and technology nodes. In order to prove the efficiency of such mitigation techniques, we have to use simulation platforms. Unfortunately, existing architecture simulators do not provide any implementation of unintended memory modifications like bit-flips. Integrating memory corruption into architecture simulators would allow the construction of attacks and mitigations for current and future computers, using feedback from the simulator. In this paper, we propose an implementation of the Rowhammer effect in the gem5 architecture simulator, demonstrate its capabilities and state its limitations.
Loïc France, Florent Bruguier, Maria Mushtaq, David Novo, Pascal Benoit
RSP2
2014 Aging and voltage scaling impacts under neutron-induced soft error rate in SRAM-based FPGAs
abstract
This work investigates the effects of aging and voltage scaling in neutron-induced bit-flip in SRAM-based FPGAs. Experimental results show that aging and voltage scaling can increase in at least two times the susceptibility of SRAM-based FPGAs to Soft Error Rate (SER). These results are innovative, because they combine three real effects that occur in programmable circuits operating at ground-level applications. In addition, a model at electrical simulation for aging, soft error and different voltages was described to investigate the effects observed at the practical neutron irradiation experiment. Results can guide designers to predict soft error effects during the lifetime of devices operating in different power supply mode.
Fernanda Lima Kastensmidt, Jorge L. Tonfat, Thiago Hanna Both, Paolo Rech, Gilson I. Wirth, Ricardo Augusto da Luz Reis, Florent Bruguier, Pascal Benoit, Lionel Torres, Christopher Frost 0002
ETS7
2014 Aging effects in FPGAs: an experimental analysis
abstract
Modern Field Programmable Gate Arrays (FPGAs) are built using the most advanced technology nodes to meet performance and power demands. This makes them susceptible to various reliability challenges at nano-scale, and in particular to transistor aging. In this paper, an experimental analysis is made to identify the main parameters and phenomena influencing the performance degradation of FPGAs. For that purpose, a set of controlled ring-oscillator-based sensors with different frequencies and tunable activity control are implemented on a Spartan-6 FPGA. Thus, the internal switching activities (SAs) and signal probabilities (SPs) of the sensors can be varied. We performed accelerated-lifetime conditions using elevated temperatures and voltages in a controlled setting to stress the FPGA. A novel monitoring method based on measuring the electromagnetic emissions of the FPGA is used to accurately monitor the performance of the sensors before and after the stress. The experiments reveal the extent of performance degradations, the impact of SPs and SAs, and the relative impacts of BTI and HCI aging factors.
Abdulazim Amouri, Florent Bruguier, Saman Kiamehr, Pascal Benoit, Lionel Torres, Mehdi Baradaran Tahoori
FPL2
2014 Method for dynamic power monitoring on FPGAs
abstract
The ever-increasing integration densities make it possible to configure multi-core systems composed of hundreds of blocks on existing FPGAs that may influence overall consumption differently. Observing total consumption is not sufficient to accurately assess internal circuit activity to be able to deploy effective adaptation strategies. In this case monitoring techniques are required. This paper presents a CAD flow for high-level dynamic power estimation on FPGAs. The method is based on the monitoring of toggling activity for relevant signals by introducing event counters. The appropriate signals are selected using the Greedy Stepwise filter. Our approach is based on a generic method that is able to produce a power model for any block-based circuit. We evaluated our contribution on a SoC RTL model implemented on Spartan3, Virtex5, and Spartan6 FPGAs. A power model and monitors are automatically generated to achieve the best tradeoff between accuracy and overhead.
Mohamad Najem, Pascal Benoit, Florent Bruguier, Gilles Sassatelli, Lionel Torres
FPL3
2011 A New Process Characterization Method for FPGAs Based on Electromagnetic Analysis
abstract
Thanks to their inherent regularity and reconfigurability, FPGAs offer an ideal structure to manage process variability. Recent works from the literature have addressed the process characterization problem for FPGAs: proposed approaches rely on process sensors (ring oscillators) and a measurement subsystem implemented into the configurable logic blocks. In this article, we propose for the first time in the literature a non-invasive characterization method based on electromagnetic analysis. The whole experimental set-up is described and the characterization accuracy is discussed. This paper proves the feasibility of this new method on FPGAs.
Florent Bruguier, Pascal Benoit, Philippe Maurine, Lionel Torres
FPL1