Ruiyi Zhang 0001

dblp:08/7975-1 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
12since 2021 · last 2026
0009-0007-9094-6412ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 11 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMs
Ruiyi Zhang 0001, Albert Cheu, Adrià Gascón, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz 0001, Octavian Suciu
NDSS1
2026 TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads
Tristan Hornetz, Hosein Yavarzadeh, Albert Cheu, Adrià Gascón, Lukas Gerlach 0001, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz 0001, Ruiyi Zhang 0001
SP9
2026 Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution Vulnerabilities
Daniel Weber 0007, Fabian Thomas, Leon Trampert, Ruiyi Zhang 0001, Michael Schwarz 0001
SP4
2025 ShadowLoad: Injecting State into Hardware Prefetchers
abstract
Hardware prefetchers are an optimization in modern CPUs that predict memory accesses and preemptively load the corresponding value into the cache. Previous work showed that the internal state of hardware prefetchers can act as a side channel, leaking information across security boundaries such as processes, user and kernel space, and even trusted execution environments.
Lorenz Hetterich, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Nils Bernsdorf, Eduard Ebert, Michael Schwarz 0001
ASPLOS (2)4
2025 RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs
abstract
The open and extensible RISC-V instruction set has enabled many new CPU vendors and implementations, but most commercial CPUs are closed-source, significantly hindering vulnerability analysis—especially for bugs exploitable from unprivileged user space.
Fabian Thomas, Eric García Arribas, Lorenz Hetterich, Daniel Weber 0007, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
CCS6
2025 Taming the Linux Memory Allocator for Rapid Prototyping
Ruiyi Zhang 0001, Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001
DIMVA (2)1
2024 CacheWarp: Software-based Fault Injection using Selective State Reset
Ruiyi Zhang 0001, Lukas Gerlach 0001, Daniel Weber 0007, Lorenz Hetterich, Youheng Lü, Andreas Kogler, Michael Schwarz 0001
USENIX Security Symposium1
2023 Indirect Meltdown: Building Novel Side-Channel Attacks from Transient-Execution Attacks
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
ESORICS (3)4
2023 Reviving Meltdown 3a
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
ESORICS (3)4
2023 A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs
abstract
Microarchitectural attacks threaten the security of computer systems even in the absence of software vulnerabilities. Such attacks are well explored on x86 and ARM CPUs, with a wide range of proposed but not-yet deployed hardware countermeasures. With the standardization of the RISC-V instruction set architecture and the announcement of support for the architecture by major processor vendors, RISC-V CPUs are on the verge of becoming ubiquitous. However, the microarchitectural attack surface of the first commercially-available RISC-V hardware CPUs still needs to be explored.This paper analyzes the two commercially-available off-the-shelf 64-bit RISC-V (hardware) CPUs used in most RISC-V systems running a full-fledged commodity Linux system. We evaluate the microarchitectural attack surface and introduce 3 new microarchitectural attack techniques: Cache+Time, a novel cache-line-granular cache attack without shared memory, Flush+Fault exploiting the Harvard cache architecture for Flush+Reload, and CycleDrift exploiting unprivileged access to instruction-retirement information. We also show that many known attacks apply to these RISC-V CPUs, mainly due to non-existing hardware countermeasures and instruction-set subtleties that do not consider the microarchitectural attack surface. We demonstrate our attacks in 6 case studies, including the first RISC-V-specific microarchitectural KASLR break and a CycleDrift-based method for detecting kernel activity. Based on our analysis, we stress the need to consider the microarchitectural attack surface during every step of a CPU design, including custom ISA extensions.
Lukas Gerlach 0001, Daniel Weber 0007, Ruiyi Zhang 0001, Michael Schwarz 0001
SP3
2023 (M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels
Ruiyi Zhang 0001, Daniel Weber 0007, Michael Schwarz 0001
USENIX Security Symposium1
2021 EOSAFE: Security Analysis of EOSIO Smart Contracts
Ningyu He, Ruiyi Zhang 0001, Haoyu Wang 0001, Lei Wu 0012, Xiapu Luo, Yao Guo 0001, Ting Yu 0001, Xuxian Jiang
USENIX Security Symposium2