Sandro Rüegge

dblp:418/9033 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2026
0009-0009-8004-740XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Hardware security and side channels · 84% Network security · 16%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Cloud and datacenter computing · 71% Processor architecture and microarchitecture · 29%

Topics — the 9 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels › microarchitectural side channel
branch predictor side channel
1.012026
VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud Environments · SP 2026
Hardware security and side channels
microarchitectural side channel
1.012026
VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud Environments · SP 2026
Cloud and datacenter computing
cloud security
1.012026
VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud Environments · SP 2026
Cloud and datacenter computing › cloud security
cross-VM side-channel attack
1.012026
VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud Environments · SP 2026
Network security
covert channel
0.912025
One Flew over the Stack Engine's Nest: Practical Microarchitectural Attacks on the Stack Engine · MICRO 2025
Hardware security and side channels
microarchitectural attacks
0.912025
One Flew over the Stack Engine's Nest: Practical Microarchitectural Attacks on the Stack Engine · MICRO 2025
Hardware security and side channels › hardware attacks
side-channel and fault attacks
0.912025
Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race Conditions · USENIX Security Symposium 2025
Hardware security and side channels
side-channel attack
0.912025
One Flew over the Stack Engine's Nest: Practical Microarchitectural Attacks on the Stack Engine · MICRO 2025
Processor architecture and microarchitecture
branch prediction
0.622026
VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud Environments · SP 2026
Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race Conditions · USENIX Security Symposium 2025

Methods — techniques the papers use, named apart from their topics

side-channel attack · 2.0reverse engineering · 1.7prime+sync+probe · 1.7
YearPublicationVenuePosition
2026 VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud Environments
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, Kaveh Razavi
SP2
2025 One Flew over the Stack Engine's Nest: Practical Microarchitectural Attacks on the Stack Engine
abstract
Security research on modern CPUs has raised numerous concerns in recent years.These security issues stem from classic microarchitectural optimizations designed decades ago, without consideration for security.Stack pointer tracking, also known as the stack engine in recent CPUs, is one such optimization.To investigate the security implications of the stack engine, we reverse engineer its operational details on a number of recent Intel and AMD CPUs for the first time.Our results show the particular microarchitecturedependent behaviors of the stack engine, such as the conditions under which it needs to synchronize the stack pointer values with the backend.Using these results, we build three primitives called Direct Underflow, Sync+Reload and Prime+Sync+Probe that enable information leakage through the stack engine under different conditions.We use these primitives in the construction of various covert and side-channel attacks, leaking sensitive patient records from a widely-used JSON library as an example.Our mitigation efforts reveal that recent AMD Zen 4 and Zen 5 CPUs include undocumented chicken bits which allow enabling or disabling the stack engine.Using these bits to disable the stack engine, we measure 3.98% and 3.94% slowdown using SPEC CPU2017 on Zen 4 and Zen 5, respectively, prompting the need to consider more secure designs for the stack engine in future CPUs which we also discuss. CCS Concepts• Security and privacy → Side-channel analysis and countermeasures.
Silvan Niederer, Sandro Rüegge, Ali Hajiabadi, Kaveh Razavi
MICRO2
2025 Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race Conditions
Sandro Rüegge, Johannes Wikner, Kaveh Razavi
USENIX Security Symposium1