VLDB 2026 Research / reviewers in the wild / expert
Cynthia Sturton
dblp:54/7563
· DBLP profile ↗
16ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0003-3930-7440ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 4 since 2021Software engineering, systems software and programming languages · 7 · 1 first-author · 3 since 2021Security and privacy · 4 · 2 first-authorTheory of computation · 3 · 1 first-author · 1 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SYLQ-SV: Scaling Symbolic Execution of Hardware Designs with Query CachingabstractSymbolic execution of hardware designs is a path-based analysis that can deliver high quality coverage and security verification results. Unfortunately, the technique has historically struggled with the path explosion problem and, despite recent advances, remains expensive. We present SylQ-SV, a dedicated SystemVerilog symbolic execution engine that uses SMT query caching to improve execution times, reducing run time by up to 17% over the state of the art. SylQ-SV provides language support for all necessary SystemVerilog constructs, including SystemVerilog Assertions, to provide end-to-end verification workflows of the open-source designs most commonly appearing in the literature. We evaluate SYLQ-SV on the OR1200 CPU, the OpenTitan SoC with Ibex core, and two SoC designs from the HACK@DAC competitions (with PULPissimo core and CVA6 core, respectively). We make the SylQ-SV source code and all data used in the evaluation publicly available. Kaki Ryan, Cynthia Sturton |
ASPLOS (3) | 2 |
| 2025 | Leveraging Piecewise Composition to Infer Environment Constraints for Hardware DesignsabstractWe introduce a symbolic execution-based framework to generate the environment constraints needed to formally verify a hardware design. The core of the approach is a new search strategy that leverages piecewise composition, a divide-and-conquer algorithm introduced in prior work, to guide symbolic execution toward paths more likely to generate needed environment constraints. In our preliminary evaluation using the decoder module of the OpenTitan SoC, the framework finds the needed constraints without overconstraining the environment. Kaki Ryan, Cynthia Sturton |
FDL | 2 |
| 2025 | Special Session: Bringing Symbolic Execution to the Security Verification of Hardware DesignsabstractSymbolic execution is a path-based symbolic analysis that is emerging as a versatile and effective method for security verification of hardware designs. In this paper we describe symbolic execution, explain why it is so well suited to the hardware design space, and present our recent work designing symbolic execution for the security verification of hardware designs. Kaki Ryan, Cynthia Sturton |
VTS | 2 |
| 2023 | Sylvia: Countering the Path Explosion Problem in the Symbolic Execution of Hardware Designs
Kaki Ryan, Cynthia Sturton |
FMCAD | 2 |
| 2023 | Special Session: CAD for Hardware Security - Promising Directions for Automation of Security AssuranceabstractHardware security creates a hardware-based security foundation for secure and reliable operation of systems and applications used in our modern life. The presence of design for security, security assurance, and general security design life cycle practices in product life cycle of many large semiconductor design and manufacturing companies these days indicates that the importance of hardware security has been very well observed in industry. However, the high cost, time, and effort for building security into designs and assuring their security - due to using many manual processes - is still an important obstacle for economy of secure product development. This paper presents several promising directions for automation of design for security and security assurance practices to reduce the overall time and cost of secure product development. First, we present security verification challenges of SoCs, possible vulnerabilities that could be introduced inadvertently by tools mapping a design model in one level of abstraction to its lower level, and our solution to the problem by automatically mapping security properties from one level to its lower level incorporating techniques for extension and expansion of the properties. Then, we discuss the foundation necessary for further automation of formal security analysis of a design by incorporating threat model and common security vulnerabilities into an intermediate representation of a hardware model to be used to automatically determine if there is a chance for direct or indirect flow of information to compromise confidentiality or integrity of security assets. Finally, we discuss a pre-silicon-based framework for practical and time-and-cost effective power-side channel leakage analysis, root-causing the side-channel leakage by using the automatically generated leakage profile of circuit nodes, providing insight to mitigate the side-channel leakage by addressing the high leakage nodes, and assuring the effectiveness of the mitigation by reprofiling the leakage to prove its acceptable level of elimination. We hope that sharing these efforts and ideas with the security research community can accelerate the evolution of security-aware CAD tools targeted to design for security and security assurance to enrich the ecosystem to have tools from multiple vendors with more capabilities and higher performance. Sohrab Aftabjahani, Mark Tehranipoor, Farimah Farahmandi, Bulbul Ahmed, Ryan Kastner, Francesco Restuccia 0002, Andres Meza 0001, Kaki Ryan, Nicole Fern, Jasper Van Woudenberg, Rajesh Velegalati, Cees-Bart Breunesse, Cynthia Sturton, Calvin Deutschbein |
VTS | 13 |
| 2022 | Automating hardware security property generation: invitedabstractSecurity verification is an important part of the hardware design process. Security verification teams can uncover weaknesses, vulnerabilities, and flaws. Unfortunately, the verification process involves substantial manual analysis to create the threat model, identify important security assets, articulate weaknesses, define security requirements, and specify security properties that formally describe security requirements upon the hardware. This work describes current hardware security verification practices. Many of these rely on manual analysis. We argue that the property generation process is a first step towards scalable and reproducible hardware security verification. Ryan Kastner, Francesco Restuccia 0002, Andres Meza 0001, Sayak Ray, Jason M. Fung, Cynthia Sturton |
DAC | 6 |
| 2020 | Transys: Leveraging Common Security Properties Across Hardware DesignsabstractThis paper presents Transys, a tool for translating security critical properties written for one hardware design to analogous properties suitable for a second design. Transys works in three passes adjusting the variable names, arithmetic expressions, logical preconditions, and timing constraints of the original property to retain the intended semantics of the property while making it valid for the second design. We evaluate Transys by translating 27 assertions written in a temporal logic and 9 properties written for use with gate level information flow tracking across 38 AES designs, 3 RSA designs, and 5 RISC processor designs. Transys successfully translates 96% of the properties. Among these, the translation of 23 (64%) of the properties achieved a semantic equivalence rate of above 60%. The average translation time per property is about 70 seconds. Rui Zhang 0068, Cynthia Sturton |
SP | 2 |
| 2018 | End-to-End Automated Exploit Generation for Validating the Security of Processor DesignsabstractThis paper presents Coppelia, an end-to-end tool that, given a processor design and a set of security-critical invariants, automatically generates complete, replayable exploit programs to help designers find, contextualize, and assess the security threat of hardware vulnerabilities. In Coppelia, we develop a hardware-oriented backward symbolic execution engine with a new cycle stitching method and fast validation technique, along with several optimizations for exploit generation. We then add program stubs to complete the exploit. We evaluate Coppelia on three CPUs of different architectures. Coppelia is able to find and generate exploits for 29 of 31 known vulnerabilities in these CPUs, including 11 vulnerabilities that commercial and academic model checking tools can not find. All of the generated exploits are successfully replayable on an FPGA board. Moreover, Coppelia finds 4 new vulnerabilities along with exploits in these CPUs. We also use Coppelia to verify whether a security patch indeed fixed a vulnerability, and to refine a set of assertions. Rui Zhang 0068, Calvin Deutschbein, Peng Huang 0005, Cynthia Sturton |
MICRO | 4 |
| 2017 | Identifying Security Critical Properties for the Dynamic Verification of a ProcessorabstractWe present a methodology for identifying security critical properties for use in the dynamic verification of a processor. Such verification has been shown to be an effective way to prevent exploits of vulnerabilities in the processor, given a meaningful set of security properties. We use known processor errata to establish an initial set of security-critical invariants of the processor. We then use machine learning to infer an additional set of invariants that are not tied to any particular, known vulnerability, yet are critical to security. Rui Zhang 0068, Natalie Stanley, Christopher Griggs, Andrew Chi, Cynthia Sturton |
ASPLOS | 5 |
| 2017 | A System to Verify Network Behavior of Known Cryptographic Clients
Andrew Chi, Robert A. Cochran, Marie Nesfield, Michael K. Reiter, Cynthia Sturton |
NSDI | 5 |
| 2015 | SPECS: A Lightweight Runtime Mechanism for Protecting Software from Security-Critical Processor BugsabstractProcessor implementation errata remain a problem, and worse, a subset of these bugs are security-critical. We classified 7 years of errata from recent commercial processors to understand the magnitude and severity of this problem, and found that of 301 errata analyzed, 28 are security-critical. We propose the SECURITY-CRITICAL PROCESSOR ER- RATA CATCHING SYSTEM (SPECS) as a low-overhead solution to this problem. SPECS employs a dynamic verification strategy that is made lightweight by limiting protection to only security-critical processor state. As a proof-of- concept, we implement a hardware prototype of SPECS in an open source processor. Using this prototype, we evaluate SPECS against a set of 14 bugs inspired by the types of security-critical errata we discovered in the classification phase. The evaluation shows that SPECS is 86% effective as a defense when deployed using only ISA-level state; incurs less than 5% area and power overhead; and has no software run-time overhead. Matthew Hicks, Cynthia Sturton, Samuel T. King, Jonathan M. Smith |
ASPLOS | 2 |
| 2015 | Usability of Augmented Reality for Revealing Secret Messages to Users but Not Their Devices
Sarah J. Andrabi, Michael K. Reiter, Cynthia Sturton |
SOUPS | 3 |
| 2013 | Symbolic software model validation
Cynthia Sturton, Rohit Sinha 0001, Thurston H. Y. Dang, Sakshi Jain, Michael McCoyd, Wei Yang Tan, Petros Maniatis, Sanjit A. Seshia, David A. Wagner 0001 |
MEMOCODE | 1 |
| 2012 | Verification with small and short worlds
Rohit Sinha 0001, Cynthia Sturton, Petros Maniatis, Sanjit A. Seshia, David A. Wagner 0001 |
FMCAD | 2 |
| 2011 | Defeating UCI: Building Stealthy and Malicious HardwareabstractIn previous work Hicks et al. proposed a method called Unused Circuit Identification (UCI) for detecting malicious backdoors hidden in circuits at design time. The UCI algorithm essentially looks for portions of the circuit that go unused during design-time testing and flags them as potentially malicious. In this paper we construct circuits that have malicious behavior, but that would evade detection by the UCI algorithm and still pass design-time test cases. To enable our search for such circuits, we define one class of malicious circuits and perform a bounded exhaustive enumeration of all circuits in that class. Our approach is simple and straight forward, yet it proves to be effective at finding circuits that can thwart UCI. We use the results of our search to construct a practical attack on an open-source processor. Our malicious backdoor allows any user-level program running on the processor to enter supervisor mode through the use of a secret â knock. We close with a discussion on what we see as a major challenge facing any future design-time malicious hardware detection scheme: identifying a sufficient class of malicious circuits to defend against. Cynthia Sturton, Matthew Hicks, David A. Wagner 0001, Samuel T. King |
IEEE Symposium on Security and Privacy | 1 |
| 2009 | On voting machine design for verification and testabilityabstractWe present an approach for the design and analysis of an electronic voting machine based on a novel combination of formal verification and systematic testing. The system was designed specifically to enable verification and testing. In our architecture, the voting machine is a finite-state transducer that implements the bare essentials required for an election. We formally specify how each component of the machine is intended to work and formally verify that a Verilog implementation of our design meets this specification. However, it is more challenging to verify that the composition of these components will behave as a voter would expect, because formalizing human expectations is difficult. We show how systematic testing can be used to address this issue, and in particular to verify that the machine will behave correctly on election day. Cynthia Sturton, Susmit Jha, Sanjit A. Seshia, David A. Wagner 0001 |
CCS | 1 |