VLDB 2026 Research / reviewers in the wild / expert
Boru Chen
dblp:362/1699
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0001-8024-1116ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RTeAAL Sim: Using Tensor Algebra to Represent and Accelerate RTL SimulationabstractRTL simulation on CPUs remains a persistent bottleneck in hardware design. State-of-the-art simulators embed the circuit directly into the simulation binary, resulting in long compilation times and execution that is fundamentally CPU frontend-bound, with severe instruction-cache pressure. This work proposes RTeAAL Sim, which reformulates RTL simulation as a sparse tensor algebra problem. By representing RTL circuits as tensors and simulation as a sparse tensor algebra kernel, RTeAAL Sim decouples simulation behavior from binary size and makes RTL simulation amenable to well-studied tensor algebra optimizations. We demonstrate that a prototype of our tensor-based simulator, even with a subset of these optimizations, already mitigates the compilation overhead and frontend pressure and achieves performance competitive with the highly optimized Verilator simulator across multiple CPUs and ISAs. Boru Chen, Christopher W. Fletcher, Nandeeka Nayak |
ASPLOS (2) | 2 |
| 2025 | Controlled Preemption: Amplifying Side-Channel Attacks from UserspaceabstractMicroarchitectural side channels are an ongoing threat in today's systems. Yet, many side-channel methodologies suffer from low temporal resolution measurement, which can either preclude or significantly complicate an attack. Yongye Zhu, Boru Chen, Zirui Neil Zhao, Christopher W. Fletcher |
ASPLOS (2) | 2 |
| 2025 | $\mu\text{STT}$: Microarchitecture Design for Speculative Taint TrackingabstractSpeculative execution attacks exploit malicious speculation to leak sensitive data via microarchitectural covert channels. Speculative Taint Tracking (STT) is a state-of-the-art hardware mechanism that blocks such threats by tainting data flowing from speculative loads, untainting data once all its dependencies are not speculative, and delaying instructions that create covert channels until their inputs are untainted. However, STT's hardware feasibility remains unclear due to a lack of detailed hardware cost analysis. This paper presents the first in-depth hardware cost analysis of STT and identifies two key challenges: (1) the logic delay of taint propagation, which grows with rename width, and (2) area overhead from instruction delaying, which requires expensive CAM-style logic to enforce speculation safety. To address these, we propose a new microarchitecture for STT, called$\mu$STT.$\mu$STT is based on two new mechanisms. First, the Age Matrix is a shallow taint propagation circuit that removes 85% of the logic delay overhead of prior STT designs, while only adding 36 % more area at the default rename width of 8. Second, the impede micro-op implements instruction delaying in a fashion that increases STT's performance overhead by only 5 percentage points (from 16 % to 21 %), while replacing bespoke STT hardware with existing RAW dependency tracking. Together, these contributions reduce STT's hardware complexity and cost in the context of high-end wide-issue processor designs. Boru Chen, Rutvik Choudhary, Kaustubh Khulbe, Archie Lee, Adam Morrison 0001, Christopher W. Fletcher |
ICCD | 1 |
| 2025 | Peek-a-Walk: Leaking Secrets via Page Walk Side ChannelsabstractMicroarchitectural side-channel attacks are an insidious threat to program security. An emerging class of these attacks constructs gadgets that dereference the contents of data memory directly. This is caused by optimizations, such as speculative execution and data-memory prefetching, that can guess (incorrectly) that the program is performing a pointer chase. In theory, this is devastating for security, as dereferencing a secret seemingly leaks it over memory-based side channels, e.g., through the cache. In practice, it is not. Since most secrets do not look like valid pointers, their dereference typically fails and does not leak anything. In this paper, we introduce the page walk side channel (PWSC), a new attack that can leak information even when an invalid pointer is dereferenced. In particular, given a 64-bit secret that passes the address canonicality check, PWSC can leak all remaining bits of the secret except for the low-order 6 bits, without making any assumptions on what these bits look like. We demonstrate how PWSC amplifies leakage in scenarios exploiting speculative execution and data-memory prefetching. For speculative execution, we show that PWSC, combined with Intel's LAM feature, can be exploited to leak nearly all of physical memory and that even without LAM, PWSC can be used to leak Dilithium secret keys. For data-memory prefetching, we reverse engineer the semantics of Intel's data-memory dependent prefetcher (DMP) and show how this DMP and PWSC can be combined to break security in an intra-process sandbox setting. Alan Wang 0004, Boru Chen, Yingchen Wang, Christopher W. Fletcher, Daniel Genkin, David Kohlbrenner, Riccardo Paccagnella |
SP | 2 |
| 2024 | GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent Prefetchers
Boru Chen, Yingchen Wang, Pradyumna Shome, Christopher W. Fletcher, David Kohlbrenner, Riccardo Paccagnella, Daniel Genkin |
USENIX Security Symposium | 1 |