VLDB 2026 Research / reviewers in the wild / expert
Leon Trampert
dblp:329/6688
· DBLP profile ↗
11ranked-venue papers
5as first author
11since 2021 · last 2026
0009-0001-6891-965XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 4 first-author · 9 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution Vulnerabilities
Daniel Weber 0007, Fabian Thomas, Leon Trampert, Ruiyi Zhang 0001, Michael Schwarz 0001 |
SP | 3 |
| 2026 | Trust on Reload: Securing Browser-Based End-to-End Encryption
Simon Schwarz 0001, Florian Bauckholt, Leon Trampert |
WWW | 3 |
| 2025 | Styled to Steal: The Overlooked Attack Surface in Email ClientsabstractEmail is still a widely used communication medium, particularly in professional contexts. Standards such as OpenPGP and S/MIME offer encryption while maintaining compatibility with existing infrastructure. Within the end-to-end encryption threat model, email servers are untrusted, which creates opportunities for attackers to inject malicious HTML or CSS into encrypted emails---either live during email transport, or by re-sending leaked emails. Leon Trampert, Daniel Weber 0007, Christian Rossow, Michael Schwarz 0001 |
CCS | 1 |
| 2025 | Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting
Leon Trampert, Daniel Weber 0007, Lukas Gerlach 0001, Christian Rossow, Michael Schwarz 0001 |
NDSS | 1 |
| 2025 | Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address LeakageabstractMicroarchitectural attacks are a growing threat to modern computing systems. CPU caches are an essential but complex element in many microarchitectural attacks, making it crucial to understand the inner workings. Despite progress in reverse-engineering techniques, non-linear cache-slice functions remain challenging to analyze, especially in recent Intel hybrid microarchitectures. In this paper, we introduce a novel approach towards reverse-engineering complex, non-linear cache-slice functions, particularly on modern Intel CPUs with hybrid microarchi-tectures. Our method significantly advances prior work by understanding the specific structure of microarchitectural hash functions, reducing the time required for reverse-engineering from days to minutes. In contrast to prior work, our technique successfully handles systems with 512 GB of memory and diverse slice configurations. We present 13 newly identified functions used for cache-slice addressing and extend existing functions to support systems with more DRAM for multiple CPU generations. Additionally, we introduce an unprivileged virtual-to-physical address oracle that is a direct consequence of the complexity of the non-linear slice functions. Our method is particularly effective on modern Intel hybrid CPUs, in-cluding Alder Lake and Meteor Lake, where previously used methods for measuring slices or leaking physical addresses are unavailable. In 3 case studies, we validate our approach, demonstrating its effectiveness in executing targeted Spectre attacks on non-attacker-mapped memory, enabling DRAMA attacks, and creating cache eviction sets. Our findings em-phasize the increased attack surface introduced by complex cache-slice functions in modern CPU s. Mikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz, Leon Trampert, Lukas Gerlach 0001, Michael Schwarz 0001 |
SP | 5 |
| 2025 | SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution
Daniel Weber 0007, Lukas Gerlach 0001, Leon Trampert, Youheng Lü, Jo Van Bulck, Michael Schwarz 0001 |
USENIX Security Symposium | 3 |
| 2025 | Confusing Value with Enumeration: Studying the Use of CVEs in Academia
Moritz Schloegel, Daniel Klischies, Simon Koch 0001, David Klein 0001, Lukas Gerlach 0001, Malte Wessels, Leon Trampert, Martin Johns, Mathy Vanhoef, Michael Schwarz 0001, Thorsten Holz, Jo Van Bulck |
USENIX Security Symposium | 7 |
| 2025 | Peripheral Instinct: How External Devices Breach Browser SandboxesabstractBrowser APIs such as WebHID, WebUSB, Web Serial, and Web MIDI enable web applications to interact directly with external devices. The support of such APIs in Chromium-based browsers, such as Chrome and Edge, radically changes the threat model for peripherals and increases the attack surface. In the past, devices could assume a trusted host, i.e., the operating system. Now, the host is a potentially malicious website and cannot be trusted. Leon Trampert, Lorenz Hetterich, Lukas Gerlach 0001, Mona Schappert, Christian Rossow, Michael Schwarz 0001 |
WWW | 1 |
| 2023 | FetchBench: Systematic Identification and Characterization of Proprietary PrefetchersabstractPrefetchers speculatively fetch memory using predictions on future memory use by applications. Different CPUs may use different prefetcher types, and two implementations of the same prefetcher can differ in details of their characteristics, leading to distinct runtime behavior. For a few implementations, security researchers showed through manual analysis how to exploit specific prefetchers to leak data. Identifying such vulnerabilities required tedious reverse-engineering, as prefetcher implementations are proprietary and undocumented. So far, no systematic study of prefetchers in common CPUs is available, preventing further security assessment. Till Schlüter, Amit Choudhari, Lorenz Hetterich, Leon Trampert, Hamed Nemati, Ahmad Ibrahim 0002, Michael Schwarz 0001, Christian Rossow, Nils Ole Tippenhauer |
CCS | 4 |
| 2023 | Honey, I Cached our Security Tokens Re-usage of Security Tokens in the WildabstractIn order to mitigate the effect of Web attacks, modern browsers support a plethora of different security mechanisms. Mechanisms such as anti-Cross-Site Request Forgery (CSRF) tokens or nonces in a Content Security Policy rely on a random number that must only be used once. Notably, those Web security mechanisms are shipped through HTML tags or HTTP response headers from the server to the client side. To decrease the server load and the traffic burdened on the server infrastructure, many Web applications are served via a Content Delivery Network (CDN), which caches certain responses from the server to deliver them to multiple clients. This, however, affects not only the content but also the settings of the security mechanisms deployed via HTML meta tags or HTTP headers. If those are also cached, their content is fixed, and the security tokens are no longer random for each request. Even if the responses are not cached, operators may re-use tokens, as generating random numbers that are unique for each request introduces additional complexity for preserving the state on the server side. This work sheds light on the re-usage of security tokens in the wild, investigates what caused the static tokens, and elaborates on the security impact of the non-random security tokens. Leon Trampert, Ben Stock, Sebastian Roth |
RAID | 1 |
| 2022 | Browser-Based CPU Fingerprinting
Leon Trampert, Christian Rossow, Michael Schwarz 0001 |
ESORICS (3) | 1 |