VLDB 2026 Research / reviewers in the wild / expert
Benedikt Gierlichs
dblp:53/2144
· DBLP profile ↗
34ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-5866-1990ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 4 first-author · 2 since 2021Systems, architecture and hardware · 5 · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Graph-Theoretic Framework for Randomness Optimization in First-Order Masked CircuitsabstractWe present a generic, automatable framework to reduce the demand for fresh randomness in first-order masked circuits while preserving security in the glitch-extended probing model. The method analyzes the flow of randomness through a circuit to establish security rules based on the glitch-extended probing model. These rules are then encoded as an interference graph, transforming the optimization challenge into a graph coloring problem, which is solved efficiently with a DSATUR heuristic. Crucially, the optimization only rewires randomness inputs without altering core logic, ensuring seamless integration into standard EDA flows and applicability to various gadgets like DOM-indep (Domain-Oriented Masking) and HPC (Hardware Private Circuits). On 32-bit adder architectures, the framework substantially reduces randomness requirements by 79–90%; for instance, the Kogge–Stone adder’s requirement of 259 unique random inputs is reduced to 27. All optimized designs were evaluated using PROLEAD, with the leakage results indicating compliance with first-order glitch-extended probing security. S. V. Dilip Kumar, Benedikt Gierlichs, Ingrid Verbauwhede |
DATE | 2 |
| 2025 | AttackDefense Framework (ADF): Enhancing IoT Devices and Lifecycles Threat ModelingabstractThreat modeling (TM) is essential to manage, prevent, and fix security and privacy issues in our society. TM requires a data model to represent threats and tools to exploit such data. Current TM data models and tools have significant limitations preventing their usage in real-world scenarios. For example, it is challenging to TM embedded devices with current data models and tools as they cannot model their hardware, firmware, and low-level software. Moreover, it is impossible to TM a device lifecycle or security-privacy tradeoffs as these data models and tools were developed for other use cases (e.g., software security or user privacy). We fill this relevant gap by presenting the AttackDefense Framework (ADF), which provides a novel data model and related tools to augment TM. ADF’s building block is the AD object that can be used to represent heterogeneous and complex threats. Moreover, ADF provides automations to process a collection of AD objects, including ways to create sets, maps, chains, trees, and wordclouds of AD objects. We present ADF , a toolkit implementing ADF composed of four modules (Catalog, Parse, Check, and Analyze). We confirm that the data model and tools provided by ADF are useful by running an extensive set of experiments while threat modeling a crypto wallet and its lifecycle. Our experiments involved seven expert groups from academia and industry, each using the ADF on an orthogonal threat class. The evaluation generated 175 high-quality ADs covering ISA/IEC 62433-4-1 SecDev Lifecycle, side-channels, fault injection, microarchitectural attacks, speculative execution, pre-silicon testing, invasive physical chip modifications, Bluetooth protocol and implementation threats, and FIDO2 authentication. Tommaso Sacchetti, Marton Bognar, Jesse De Meulemeester, Benedikt Gierlichs, Frank Piessens, Volodymyr Bezsmertnyi, Maria Chiara Molteni, Stefano Cristalli, Arianna Gringiani, Olivier Thomas, Daniele Antonioli |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2025 | Low-Cost First-Order Secure Boolean Masking in Glitchy HardwareabstractWe describe how to securely implement the masked logical AND of two bits in hardware in the presence of glitches without the need for fresh randomness, and we provide guidelines for the composition of circuits. As a case study, we design, implement, and evaluate masked DES cores. We focus on first-order secure Boolean masking and do not aim for provable security. Our goal is a practically relevant trade-off between area, latency, randomness cost, and security. We provide two low-cost solutions. Our first solution focuses on strong security while simultaneously aiming for low implementation costs. The resulting DES engine shows no evidence of first-order leakage in a non-specific leakage assessment with 50M traces. Our second solution follows the opposite approach: we focus on lowering implementation costs, latency to be specific, while not sacrificing much on security. Our low-latency DES engine exhibits signs of first-order leakage only after approximately 15M traces. S. V. Dilip Kumar, Josep Balasch, Benedikt Gierlichs, Ingrid Verbauwhede |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | An In-Depth Security Evaluation of the Nintendo DSi Gaming Console
pcy Sluys, Lennert Wouters, Benedikt Gierlichs, Ingrid Verbauwhede |
CARDIS | 3 |
| 2023 | Low-Cost First-Order Secure Boolean Masking in Glitchy HardwareabstractWe describe how to securely implement the logical AND of two bits in hardware in the presence of glitches without the need for fresh randomness. As a case study, we design, implement and evaluate a DES core using our AND gate. Our goal is an overall practically relevant tradeoff between area, latency, randomness cost and security. We focus on first-order secure Boolean masking and we do not aim for provable security. The resulting DES engine shows no evidence of first-order leakage in a non-specific leakage assessment with 50M traces. S. V. Dilip Kumar, Josep Balasch, Benedikt Gierlichs, Ingrid Verbauwhede |
DATE | 3 |
| 2022 | Energy and side-channel security evaluation of near-threshold cryptographic circuits in 28nm FD-SOI technologyabstractThis paper is the first to present an implementation of a cryptographic circuit in 28nm FD-SOI using near-threshold design. The implemented cipher, Ketje Jr, is a lightweight authenticated encryption algorithm. The energy consumption of representative authenticated encryption operations as well as the information leakage through the power consumption side-channel are evaluated. The results show that an ultra-low energy implementation can be achieved, and that the near-threshold design has little influence on the Signal to Noise Ratio in the power measurements of our chip. Arthur Beckers, Roel Uytterhoeven, Thomas Vandenabeele, Jo Vliegen, Lennert Wouters, Joan Daemen, Wim Dehaene, Benedikt Gierlichs, Nele Mentens |
CF | 8 |
| 2019 | Design Considerations for EM Pulse Fault Injection
Arthur Beckers, Masahiro Kinugawa, Yuichi Hayashi, Daisuke Fujimoto, Josep Balasch, Benedikt Gierlichs, Ingrid Verbauwhede |
CARDIS | 6 |
| 2018 | An In-Depth and Black-Box Characterization of the Effects of Laser Pulses on ATmega328P
S. V. Dilip Kumar, Arthur Beckers, Josep Balasch, Benedikt Gierlichs, Ingrid Verbauwhede |
CARDIS | 4 |
| 2017 | Consolidating Inner Product Masking
Josep Balasch, Sebastian Faust, Benedikt Gierlichs, Clara Paglialonga, François-Xavier Standaert |
ASIACRYPT (1) | 3 |
| 2017 | Fault Analysis of the ChaCha and Salsa Families of Stream Ciphers
Arthur Beckers, Benedikt Gierlichs, Ingrid Verbauwhede |
CARDIS | 2 |
| 2017 | A First-Order Chosen-Plaintext DPA Attack on the Third Round of DES
Oscar Reparaz, Benedikt Gierlichs |
CARDIS | 2 |
| 2017 | Fast Leakage Assessment
Oscar Reparaz, Benedikt Gierlichs, Ingrid Verbauwhede |
CHES | 2 |
| 2015 | DPA, Bitslicing and Masking at 1 GHz
Josep Balasch, Benedikt Gierlichs, Oscar Reparaz, Ingrid Verbauwhede |
CHES | 2 |
| 2015 | Consolidating Masking Schemes
Oscar Reparaz, Begül Bilgin, Svetla Nikova, Benedikt Gierlichs, Ingrid Verbauwhede |
CRYPTO (1) | 4 |
| 2015 | Inner Product Masking Revisited
Josep Balasch, Sebastian Faust, Benedikt Gierlichs |
EUROCRYPT (1) | 3 |
| 2015 | Trade-Offs for Threshold Implementations Illustrated on AESabstractEmbedded cryptographic devices are vulnerable to power analysis attacks. Threshold implementations (TIs) provide provable security against first-order power analysis attacks for hardware and software implementations. Like masking, the approach relies on secret sharing but it differs in the implementation of logic functions. While masking can fail to provide protection due to glitches in the circuit, TIs rely on few assumptions about the hardware and are fully compatible with standard design flows. We investigate two important properties of TIs in detail and point out interesting trade-offs between circuit area and randomness requirements. We propose two new TIs of AES that, starting from a common previously published implementation, illustrate possible trade-offs. We provide concrete ASIC implementation results for all three designs using the same library, and we evaluate the practical security of all three designs on the same FPGA platform. Our analysis allow us to directly compare the security provided by the different trade-offs, and to quantify the associated hardware cost. Begül Bilgin, Benedikt Gierlichs, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2014 | Higher-Order Threshold Implementations
Begül Bilgin, Benedikt Gierlichs, Svetla Nikova, Ventzislav Nikov, Vincent Rijmen |
ASIACRYPT (2) | 2 |
| 2014 | On the Cost of Lazy Engineering for Masked Software Implementations
Josep Balasch, Benedikt Gierlichs, Vincent Grosso, Oscar Reparaz, François-Xavier Standaert |
CARDIS | 2 |
| 2012 | Theory and Practice of a Leakage Resilient Masking Scheme
Josep Balasch, Sebastian Faust, Benedikt Gierlichs, Ingrid Verbauwhede |
ASIACRYPT | 3 |
| 2012 | Selecting Time Samples for Multivariate DPA Attacks
Oscar Reparaz, Benedikt Gierlichs, Ingrid Verbauwhede |
CHES | 2 |
| 2012 | Power Analysis of Atmel CryptoMemory - Recovering Keys from Secure EEPROMs
Josep Balasch, Benedikt Gierlichs, Roel Verdult, Lejla Batina, Ingrid Verbauwhede |
CT-RSA | 2 |
| 2011 | To Infinity and Beyond: Combined Attack on ECC Using Points of Low Order
Junfeng Fan, Benedikt Gierlichs, Frederik Vercauteren |
CHES | 2 |
| 2011 | An In-depth and Black-box Characterization of the Effects of Clock Glitches on 8-bit MCUsabstractThe literature about fault analysis typically describes fault injection mechanisms, e.g. glitches and lasers, and cryptanalytic techniques to exploit faults based on some assumed fault model. Our work narrows the gap between both topics. We thoroughly analyse how clock glitches affect a commercial low-cost processor by performing a large number of experiments on five devices. We observe that the effects of fault injection on two-stage pipeline devices are more complex than commonly reported in the literature. While injecting a fault is relatively easy, injecting an exploitable fault is hard. We further observe that the easiest to inject and reliable fault is to replace instructions, and that random faults do not occur. Finally we explain how typical fault attacks can be mounted on this device, and describe a new attack for which the fault injection is easy and the cryptanalysis trivial. Josep Balasch, Benedikt Gierlichs, Ingrid Verbauwhede |
FDTC | 2 |
| 2011 | Mutual Information Analysis: a Comprehensive Study
Lejla Batina, Benedikt Gierlichs, Emmanuel Prouff, Matthieu Rivain, François-Xavier Standaert, Nicolas Veyrat-Charvillon |
J. Cryptol. | 2 |
| 2010 | The World Is Not Enough: Another Look on Second-Order DPA
François-Xavier Standaert, Nicolas Veyrat-Charvillon, Elisabeth Oswald, Benedikt Gierlichs, Marcel Medwed, Markus Kasper, Stefan Mangard |
ASIACRYPT | 4 |
| 2010 | Revisiting Higher-Order DPA Attacks:
Benedikt Gierlichs, Lejla Batina, Bart Preneel, Ingrid Verbauwhede |
CT-RSA | 1 |
| 2009 | Differential Cluster Analysis
Lejla Batina, Benedikt Gierlichs, Kerstin Lemke-Rust |
CHES | 2 |
| 2008 | Mutual Information Analysis
Benedikt Gierlichs, Lejla Batina, Pim Tuyls, Bart Preneel |
CHES | 1 |
| 2008 | Power and Fault Analysis Resistance in Hardware through Dynamic Reconfiguration
Nele Mentens, Benedikt Gierlichs, Ingrid Verbauwhede |
CHES | 2 |
| 2008 | Fault Analysis Study of IDEA
Christophe Clavier, Benedikt Gierlichs, Ingrid Verbauwhede |
CT-RSA | 2 |
| 2008 | Comparative Evaluation of Rank Correlation Based DPA on an AES Prototype Chip
Lejla Batina, Benedikt Gierlichs, Kerstin Lemke-Rust |
ISC | 2 |
| 2008 | Perfect Matching Disclosure Attacks
Carmela Troncoso, Benedikt Gierlichs, Bart Preneel, Ingrid Verbauwhede |
Privacy Enhancing Technologies | 2 |
| 2007 | DPA-Resistance Without Routing Constraints?
Benedikt Gierlichs |
CHES | 1 |
| 2006 | Templates vs. Stochastic Methods
Benedikt Gierlichs, Kerstin Lemke-Rust, Christof Paar |
CHES | 1 |