VLDB 2026 Research / reviewers in the wild / expert
Yan Michalevsky
dblp:70/10805
· DBLP profile ↗
8ranked-venue papers
4as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | G-DBREACH Attacks: Algorithmic Techniques for Faster and Stronger Compression Side Channels
Britney Bourassa, Yan Michalevsky, Saba Eskandarian |
ACNS (2) | 2 |
| 2023 | DBREACH: Stealing from Databases Using Compression Side ChannelsabstractWe introduce new compression side-channel attacks against database storage engines that simultaneously support compression of database pages and encryption at rest. Given only limited, indirect access to an encrypted and compressed database table, our attacks extract arbitrary plaintext with high accuracy. We demonstrate accurate and performant attacks on the InnoDB storage engine variants found in MariaDB and MySQL as well as the WiredTiger storage engine for MongoDB.Our attacks overcome obstacles unique to the database setting that render previous techniques developed to attack TLS ineffective. Unlike the web setting, where the exact length of a compressed and encrypted message can be observed, we make use of only approximate ciphertext size information gleaned from file sizes on disk. We amplify this noisy signal and combine it with new attack heuristics tailored to the database setting to extract secret plaintext. Our attacks can detect whether a random string appears in a table with > 90% accuracy and extract 10-character random strings from encrypted tables with > 95% success. Mathew Hogan, Yan Michalevsky, Saba Eskandarian |
SP | 2 |
| 2019 | CoSMIX: A Compiler-based System for Secure Memory Instrumentation and Execution in Enclaves
Meni Orenbach, Yan Michalevsky, Christof Fetzer, Mark Silberstein |
USENIX ATC | 2 |
| 2018 | Decentralized Policy-Hiding ABE with Receiver Privacy
Yan Michalevsky, Marc Joye |
ESORICS (2) | 1 |
| 2018 | Online detection of effectively callback free objects with applications to smart contractsabstractCallbacks are essential in many programming environments, but drastically complicate program understanding and reasoning because they allow to mutate object's local states by external objects in unexpected fashions, thus breaking modularity. The famous DAO bug in the cryptocurrency framework Ethereum, employed callbacks to steal $150M. We define the notion of Effectively Callback Free (ECF) objects in order to allow callbacks without preventing modular reasoning. An object is ECF in a given execution trace if there exists an equivalent execution trace without callbacks to this object. An object is ECF if it is ECF in every possible execution trace. We study the decidability of dynamically checking ECF in a given execution trace and statically checking if an object is ECF. We also show that dynamically checking ECF in Ethereum is feasible and can be done online. By running the history of all execution traces in Ethereum, we were able to verify that virtually all existing contract executions, excluding these of the DAO or of contracts with similar known vulnerabilities, are ECF. Finally, we show that ECF, whether it is verified dynamically or statically, enables modular reasoning about objects with encapsulated state. Shelly Grossman, Ittai Abraham, Guy Golan-Gueta, Yan Michalevsky, Noam Rinetzky, Shmuel Sagiv, Yoni Zohar |
Proc. ACM Program. Lang. | 4 |
| 2016 | MASHaBLE: mobile applications of secret handshakes over bluetooth LEabstractWe present new applications for cryptographic secret handshakes between mobile devices on top of Bluetooth Low-Energy (LE). Secret handshakes enable mutual authentication, with the property that the parties learn nothing about each other unless they have been both issued credentials by a group administrator. This property provides strong privacy guarantees that enable interesting applications. One of them is proximity-based discovery for private communities. We introduce MASHaBLE, a mobile application that enables participants to discover and interact with nearby users if and only if they belong to the same secret community. We use direct peer-to-peer communication over Bluetooth LE, rather than relying on a central server. We discuss the specifics of implementing secret handshakes over Bluetooth LE and present our prototype implementation. Yan Michalevsky, Suman Nath, Jie Liu 0001 |
MobiCom | 1 |
| 2015 | PowerSpy: Location Tracking Using Mobile Device Power Analysis
Yan Michalevsky, Aaron Schulman, Gunaa Arumugam Veerapandian, Dan Boneh, Gabi Nakibly |
USENIX Security Symposium | 1 |
| 2014 | Gyrophone: Recognizing Speech from Gyroscope Signals
Yan Michalevsky, Dan Boneh, Gabi Nakibly |
USENIX Security Symposium | 1 |