VLDB 2026 Research / reviewers in the wild / expert
Michael Gruber
dblp:73/1396
· DBLP profile ↗
13ranked-venue papers
3as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 2Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Breaking ECDSA with Electromagnetic Side-Channel Attacks: Challenges and Practicality on Modern Smartphones
Felix Oberhansl, Marc Schink, Nisha Jacob Kabakci, Michael Gruber, Dominik Klein 0001, Sven Freud, Tobias Damm, Michael Hartmeier, Ivan Gavrilan, Silvan Streit, Jonas Stappenbeck, Andreas Zankl |
EuroS&P | 4 |
| 2025 | Fault Detection in the Control- and Data-Path of Neural NetworksabstractMachine learning and neural networks experience growing usage in resource-constrained devices. However, moving neural networks to small devices also brings new requirements regarding the reliability and security of the networks and their hardware. In many areas, such as autonomous driving, the device must detect possible errors during execution to ensure safe functionality. Moreover, an adversary can gain physical access to the device, opening the door for hardware attacks like fault injections that target misclassification or parameter retrieval. This work proposes a fault detection mechanism for software implementations of neural networks running on a microcontroller to increase the reliability and security of the neural network. Our technique uses AN-codes, a type of error-detecting code, to detect errors in calculations within the neural network without any implications on the accuracy of protected networks. In addition, signature checking ensures the integrity of the control flow. Simulations and real-world testing show that our mechanism successfully detects faults in all possible locations in the neural network’s program code. Despite the robustness of our fault detection mechanism, it has an overhead in code size of only about 10%, independent of the implemented network. The memory usage increases by at most 232 bytes independently of the neural network size, ensuring that the mechanism is not overly burdensome for the memory. Matthias Probst, Manuel Brosch, Augustin Ewald, Michael Gruber, Georg Sigl |
FDTC | 4 |
| 2024 | Fault-Simulation-Based Flip-Flop Classification for Reverse EngineeringabstractThis work outlines a crucial step in gate-level netlist reverse engineering: classifying control and data flip-flops (FFs) to discern control logic and data paths. Existing methods rely mainly on structural characteristics, which can have disavantages. Our work introduces a novel approach that classifies FFs based on observed characteristics after fault insertion and propagation. We develop three new classification methods for block cipher implementations, emphasizing their significance in system security. However, we also explore the approach's applicability to other design types. We apply the approach on AES implementations using an automatic fault simulation framework, which shows perfect results for most classifications. Michael Mildner, Michaela Brunner, Michael Gruber, Johanna Baehr 0001, Georg Sigl |
DDECS | 3 |
| 2024 | Switch-Glitch : Location of Fault Injection Sweet Spots by Electro-Magnetic EmanationabstractWhile several approaches exist to locate spatial coordinates on a chip that are susceptible to Side-Channel Analysis (SCA), e.g., Test Vector Leakage Assessment (TVLA), so far, an equivalent for localized Electro-Magnetic (EM) based Fault Injection Analysis (FIA) is missing. This work analyzes the spatial relationship between EM emanation and Electro-Magnetic Fault Injection (EMFI) susceptibility and effect. Our experiments are based on a two-step approach where we first capture a heatmap based on a single trace per location, which is then used to find promising spatial EMFI positions. We chose an STM32F303 microcontroller, which shows that the injection locations that result in data modification are almost entirely contained within areas of high Signal-to-Noise Ratio (SNR). An EMFI based attack can be accelerated up significantly using this relationship. Matthias Probst, Michael Gruber, Manuel Brosch, Tim Music, Georg Sigl |
FDTC | 2 |
| 2023 | FPGANeedle: Precise Remote Fault Attacks from FPGA to CPUabstractFPGA as general-purpose accelerators can greatly improve system efficiency and performance in cloud and edge devices alike. However, they have recently become the focus of remote attacks, such as fault and side-channel attacks from one to another user of a part of the FPGA fabric. In this work, we consider system-on-chip platforms, where an FPGA and an embedded processor core are located on the same die. We show that the embedded processor core is vulnerable to voltage drops generated by the FPGA logic. Our experiments demonstrate the possibility of compromising the data transfer from external DDR memory to the processor cache hierarchy. Furthermore, we were also able to fault and skip instructions executed on an ARM Cortex-A9 core. The FPGA based fault injection is shown precise enough to recover the secret key of an AES T-tables implementation found in the mbedTLS library. Mathieu Gross, Jonas Krautter, Dennis Gnad, Michael Gruber, Georg Sigl, Mehdi Baradaran Tahoori |
ASP-DAC | 4 |
| 2021 | Algebraic Fault Analysis of Subterranean 2.0abstractAlgebraic Fault Analysis (AFA) is based on the principles of algebraic cryptanalysis in conjunction with fault analysis. One of the main benefits of AFA is the ability to use off the shelf solving tools like SAT solvers to conduct fault analysis in an automated fashion. In this work we show how the principles of AFA can be applied to the authenticated encryption scheme Subterranean 2.0, a second round candidate of the ongoing NIST-LWC competition. In order to find the optimal parameters for a fault injection we investigated the fault model’s influence on the solving time. The optimal fault parameters turned out as a single bitflip fault in conjunction with a known but randomly chosen fault location, where the fault is applied just one cycle before the tag generation. We verify the efficiency of our attack by means of simulation. Conducting our proposed attack with optimal fault parameters requires only five fault injections to recover the secret key of Subterranean 2.0 in less than four seconds. Michael Gruber, Patrick Karl, Georg Sigl |
FDTC | 1 |
| 2021 | DOMREP-An Orthogonal Countermeasure for Arbitrary Order Side-Channel and Fault Attack ProtectionabstractProtection against physical attacks is a major requirement for cryptographic implementations on devices which can be accessed by attackers. Side-channel and fault injection attacks are the most common types of physical attacks. In this work we present a novel generic solution for simultaneous protection against side-channel and fault attacks with arbitrary order. We combine domain oriented masking and repetition codes in an orthogonal way and call this approach DOMREP. The resistance against side-channel attacks and fault attacks can be scaled independently of each other, for the protection against higher-order side-channel analysis and the injection of multiple faults including SIFA. We develop the generic concept of orthogonal protection, and implement the DOMREP concept on GIMLI, a round two NIST LWC competition candidate, on a Xilinx Artix-7 FPGA. Our implementation of GIMLI is verified to be resistant against univariate first-order side-channel attacks by TVLA. The resistance against SIFA is verified by means of fault emulation of single as well as multiple bit faults. Our implementation of GIMLI achieves the expected security level according to these measurements. We also provide numbers for the area overhead for our protected implementation of GIMLI. Michael Gruber, Matthias Probst, Patrick Karl, Thomas Schamberger, Lars Tebelmann, Michael Tempelmeier, Georg Sigl |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Persistent Fault Analysis of OCB, DEOXYS and COLMabstractPersistent Fault Analysis (PFA) was introduced as a new approach to attack block ciphers at CHES 2018. Since then, it has been proven to be a powerful attack with an easy to achieve fault model which relies on the persistent alternation of constants e.g. S-Boxes. One of the main benefits, when working with PFA, comes from the perspective of an attacker: there is no need to conduct fault injections at runtime. As authenticated encryption is gaining more and more attraction from the research community e.g. the CAESAR competition, we opted to apply the principals of PFA to authenticated encryption schemes. Therefore, we decided to attack a subset of the AES based CAESAR finalists. In this work, we present a PFA of Deoxys-II, OCB and COLM. We show how to extend the original PFA to fit the needs of authenticated encryption schemes and what makes them vulnerable to PFA. Finally, we demonstrate the efficiency of the attacks by means of simulation. Michael Gruber, Matthias Probst, Michael Tempelmeier |
FDTC | 1 |
| 2019 | An Empirical Evaluation of Search Algorithms for App Testing
Leon Sell, Michael Auer, Christoph Frädrich, Michael Gruber, Philemon Werli, Gordon Fraser 0001 |
ICTSS | 4 |
| 2007 | ProVeR: Probabilistic Video Retrieval using the Gauss-TreeabstractModeling objects by probability density functions (pdf) is a new powerful method to represent complex objects in databases. By representing an object as a pdf e.g. a Gaussian, it is possible to represent very large and complex objects in a compact and still descriptive way. In this contribution, we propose ProVeR a prototype search engine for content-based video retrieval which represents a video as a set of Gaussians. The Gaussians are managed by the Gauss-tree, an index structure allowing the efficient processing of probabilistic queries. ProVeR provides even non-expert users with an intuitive method for efficient, content-based retrieval of videos containing similar shots and scenes. Christian Böhm 0001, Michael Gruber, Peter Kunath, Alexey Pryakhin, Matthias Schubert |
ICDE | 2 |
| 2006 | VICO: Visualizing Connected Object Orderings
Stefan Brecheisen, Hans-Peter Kriegel, Matthias Schubert, Michael Gruber |
EDBT | 4 |
| 2000 | R-trees for organizing and visualizing 3D GIS databasesabstractWith the migration from 2D to 3D geographical information systems (GISs), the amounts of data to manage grow substantially. At the same time, 3D real-time rendering is necessary to provide a convenient user interface. Traditional GIS data management functions are too slow for this purpose, while computer graphics algorithms fail to deal with the sheer amount of data efficiently. In this paper we present LOD-R-trees, a new data structure which elegantly combines R-trees with LODs (levels of detail). Two applications demonstrate the versatility of our approach. With the Vienna Walkthrough System one can virtually walk through Vienna, the capital of Austria. The geometric model consists of about 20,000 blocks of buildings, covering about 75% of Vienna (150 km2 out of 200 km2). With the Styria Flyover System one can virtually fly over Styria, a province of Austria. The digital model covers Styria and parts of its adjoining provinces (30,000 km2); it is based on a digital terrain model (DTM) consisting of more than 23 million triangles and of 50 Mbyte texture data (satellite images). Both applications provide progressive rendering and dynamic performance adjustment. On an SGI 02 they deliver about 10 frames per second. Our approach demonstrates that efficient algorithms make a fast 3D GIS user interface possible without spending a fortune on hardware. Copyright © 2000 John Wiley & Sons, Ltd. Michael Kofler, Michael Gervautz, Michael Gruber |
Comput. Animat. Virtual Worlds | 3 |
| 1998 | The Styria Flyover - LoD Management for Huge Textured Terrain ModelsabstractWith the Styria Flyover one can virtually fly over Styria, a province of Austria. The countryside is characterized by a mixture of rather flat regions in the south east and mountains up to 3000 m in the north west. The digital model covers Styria and parts of its adjoining provinces (30,000 km/sup 2/); it is based on a DTM consisting of more than 23 million triangles and on 50 Mbyte texture data (satellite images). The framework combines an R-tree data structure with efficient LOD management (automatic mesh refinement), progressive rendering and dynamic performance adjustment. On a SGI O2 it delivers more than 8 frames per second. The authors' approach demonstrates that efficient algorithms make a fast 3D GIS user interface possible without spending a fortune on hardware. The paper focuses on techniques and data structures to maximize the performance of visualization. Michael Kofler, Michael Gervautz, Michael Gruber |
Computer Graphics International | 3 |