VLDB 2026 Research / reviewers in the wild / expert
Roukoz Nabhan
dblp:348/7354
· DBLP profile ↗
4ranked-venue papers
4as first author
4since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HEED: A Highly Efficient Electromagnetic Fault Detection SchemeabstractElectroMagnetic Fault Injection (EMFI) is a hard-ware attack technique that uses EM perturbations to deliberately induce faults in integrated circuits for attack purposes. In this paper, we propose to use a Digital Sensor (DS) based on a Time-to-Digital Converter (TDC) to detect such EMFI attacks. A TDC uses a delay line to sense variations in a device’s core voltage at the rate of its clock. Thus, it can detect EMFI attacks involving voltage and clock signal perturbations. The sensor output is expressed as a digital index, FN, which captures EMFI-induced delay variations. We evaluated the sensor’s effectiveness on real silicon using an FPGA test vehicle through extensive experiments. The results demonstrate that a single sensor can efficiently detect 100% of faults injected into an AES crypto-accelerator while ensuring wide circuit area coverage, with a highly negligible 1% false alarms rate thanks to the proposed differential fault detection methodology. To ascertain the sensor’s robustness, experiments were conducted under various thermal and noise conditions. Beyond fault detection, the sensor provides insight into the EMFI mechanism. The observed behavior is consistent with a timing constraint violation fault model. Roukoz Nabhan, Mohammad Ebrahimabadi, Jean-Luc Danger, Jean-Max Dutertre, Sylvain Guilley, Naghmeh Karimi, Raphael Viera 0001, Iyad Zaarour |
DATE | 1 |
| 2024 | EM Fault Injection-Induced Clock Glitches: From Mechanism Analysis to Novel Sensor DesignabstractThis paper introduces a novel sensor that is capable of detecting faults injected by electromagnetic disturbances. The sensor has been designed from an understanding of the physical mechanisms of ElectroMagnetic Fault Injection (EMFI). A recent study has identified an EMFI mechanism based on the timing violation fault model, which highlights the coexistence of two distinct mechanisms: electromagnetic disturbances that are coupled to the target’s power distribution network, which can cause timing faults by extending the propagation time of logic gates beyond the clock period, and disturbances that are coupled to the target’s clock distribution network, which can cause timing constraint violations due to EMFI-induced voltage glitches within the target’s clock tree. Building on this work, we have investigated the mechanism of EMFI-induced clock glitches, providing useful insights for designing a new sensor. The sensor incorporates two dummy clock paths that are maintained in a frozen state within the circuit. Both paths are respectively capable of detecting both positive and negative EMFI-induced glitches along these paths. The proposed sensor offers significant advantages, including full digitization, ease of implementation, low cost in terms of silicon area, low power consumption, and a high fault detection rate. Accurate design and experimental tests were performed on an FPGA board. Validation experiments were supported by spatial and temporal sensitivity maps covering the full-frequency spectrum of the target, which confirmed the effectiveness of the sensor. Roukoz Nabhan, Jean-Max Dutertre, Jean-Baptiste Rigaud, Jean-Luc Danger, Laurent Sauvage |
IOLTS | 1 |
| 2023 | Highlighting Two EM Fault Models While Analyzing a Digital Sensor LimitationsabstractFault injection attacks can be carried out against an operating circuit by exposing it to EM perturbations. These attacks can be detected using embedded digital sensors based on the EM fault injection mechanism, as the one introduced by El Baze et al. [1] which uses the sampling fault model [2], [3]. We tested on an experimental basis the efficiency of this sensor embedded in the AES accelerator of an FPGA. It proved effective when the target was clocked at moderate frequency (the injected faults were consistent with the sampling fault model). As the clock frequency was progressively increased, faults started to escape detection, which raises warnings about possible limitations of the sampling model. Further tests at frequencies close to the target maximal frequency revealed faults injected according to a timing fault model. Both series of experimental results ascertain that EM injection can follow at least two different fault models. Undetected faults and the existence of different fault injection mechanisms cast doubt upon the use of sensors based on a single model. Roukoz Nabhan, Jean-Max Dutertre, Jean-Baptiste Rigaud, Jean-Luc Danger, Laurent Sauvage |
DATE | 1 |
| 2023 | A Tale of Two Models: Discussing the Timing and Sampling EM Fault Injection ModelsabstractInvestigating the dynamics and mechanisms of Electromagnetic Fault Injection (EMFI) attacks, which expose an active circuit to electromagnetic disturbances, presents a persisting challenge due to the diverse and complex fault mechanisms involved. An improved understanding of EMFI modeling is paramount for developing proficient on-chip detection sensors, serving as countermeasures to these attacks. In light of this, our research evaluated the effectiveness of EMFI detection sensors, introduced by Elbaze et al., which rest on the premise that the sampling fault model accounts for EMFI. To assess the functionality of these sensors, we integrated them into an Advanced Encryption Standard (AES) accelerator of a Field-Programmable Gate Array (FPGA) and performed a series of experiments. The resulting evidence suggests that the explanation for EMFI is not a singular fault model but rather, two underlying mechanisms are implicated. At high frequencies, which corresponds to low slack, electromagnetic disturbances, in tandem with the target's Power Distribution Network (PDN), initiated timing constraint violations. This violation subsequently increased the logic propagation times, surpassing the clock period. Contrarily, at low to moderate frequencies, the induced faults generally aligned with the sampling fault model. However, certain deviations from the theoretical framework called into question the model's validity. Upon a deeper examination of the results, we determined that these faults, rather than being sampling faults, were tied to a different mechanism. Electromagnetic disturbances, when coupled with a target's Clock Distribution Network (CDN), can cause timing constraint violations due to EMFI-induced voltage glitches within the target's clock tree. By integrating the mechanisms of EMFI-induced clock glitches and timing faults into the timing violations fault model, we attain a holistic comprehension of EMFI mechanisms. It encapsulates both mechanisms induced by EMFI, spanning the full-frequency spectrum of the target. Roukoz Nabhan, Jean-Max Dutertre, Jean-Baptiste Rigaud, Jean-Luc Danger, Laurent Sauvage |
FDTC | 1 |