EDBT 2026 Demo / reviewers in the wild / expert
Ruiyi Zhang 0001
dblp:08/7975-1
· DBLP profile ↗
12ranked-venue papers
4as first author
12since 2021 · last 2026
0009-0007-9094-6412ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 11 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMs
Ruiyi Zhang 0001, Albert Cheu, Adrià Gascón, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz 0001, Octavian Suciu |
NDSS | 1 |
| 2026 | TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads
Tristan Hornetz, Hosein Yavarzadeh, Albert Cheu, Adrià Gascón, Lukas Gerlach 0001, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz 0001, Ruiyi Zhang 0001 |
SP | 9 |
| 2026 | Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution Vulnerabilities
Daniel Weber 0007, Fabian Thomas, Leon Trampert, Ruiyi Zhang 0001, Michael Schwarz 0001 |
SP | 4 |
| 2025 | ShadowLoad: Injecting State into Hardware PrefetchersabstractHardware prefetchers are an optimization in modern CPUs that predict memory accesses and preemptively load the corresponding value into the cache. Previous work showed that the internal state of hardware prefetchers can act as a side channel, leaking information across security boundaries such as processes, user and kernel space, and even trusted execution environments. Lorenz Hetterich, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Nils Bernsdorf, Eduard Ebert, Michael Schwarz 0001 |
ASPLOS (2) | 4 |
| 2025 | RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUsabstractThe open and extensible RISC-V instruction set has enabled many new CPU vendors and implementations, but most commercial CPUs are closed-source, significantly hindering vulnerability analysis—especially for bugs exploitable from unprivileged user space. Fabian Thomas, Eric García Arribas, Lorenz Hetterich, Daniel Weber 0007, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001 |
CCS | 6 |
| 2025 | Taming the Linux Memory Allocator for Rapid Prototyping
Ruiyi Zhang 0001, Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001 |
DIMVA (2) | 1 |
| 2024 | CacheWarp: Software-based Fault Injection using Selective State Reset
Ruiyi Zhang 0001, Lukas Gerlach 0001, Daniel Weber 0007, Lorenz Hetterich, Youheng Lü, Andreas Kogler, Michael Schwarz 0001 |
USENIX Security Symposium | 1 |
| 2023 | Indirect Meltdown: Building Novel Side-Channel Attacks from Transient-Execution Attacks
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001 |
ESORICS (3) | 4 |
| 2023 | Reviving Meltdown 3a
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001 |
ESORICS (3) | 4 |
| 2023 | A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUsabstractMicroarchitectural attacks threaten the security of computer systems even in the absence of software vulnerabilities. Such attacks are well explored on x86 and ARM CPUs, with a wide range of proposed but not-yet deployed hardware countermeasures. With the standardization of the RISC-V instruction set architecture and the announcement of support for the architecture by major processor vendors, RISC-V CPUs are on the verge of becoming ubiquitous. However, the microarchitectural attack surface of the first commercially-available RISC-V hardware CPUs still needs to be explored.This paper analyzes the two commercially-available off-the-shelf 64-bit RISC-V (hardware) CPUs used in most RISC-V systems running a full-fledged commodity Linux system. We evaluate the microarchitectural attack surface and introduce 3 new microarchitectural attack techniques: Cache+Time, a novel cache-line-granular cache attack without shared memory, Flush+Fault exploiting the Harvard cache architecture for Flush+Reload, and CycleDrift exploiting unprivileged access to instruction-retirement information. We also show that many known attacks apply to these RISC-V CPUs, mainly due to non-existing hardware countermeasures and instruction-set subtleties that do not consider the microarchitectural attack surface. We demonstrate our attacks in 6 case studies, including the first RISC-V-specific microarchitectural KASLR break and a CycleDrift-based method for detecting kernel activity. Based on our analysis, we stress the need to consider the microarchitectural attack surface during every step of a CPU design, including custom ISA extensions. Lukas Gerlach 0001, Daniel Weber 0007, Ruiyi Zhang 0001, Michael Schwarz 0001 |
SP | 3 |
| 2023 | (M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels
Ruiyi Zhang 0001, Daniel Weber 0007, Michael Schwarz 0001 |
USENIX Security Symposium | 1 |
| 2021 | EOSAFE: Security Analysis of EOSIO Smart Contracts
Ningyu He, Ruiyi Zhang 0001, Haoyu Wang 0001, Lei Wu 0012, Xiapu Luo, Yao Guo 0001, Ting Yu 0001, Xuxian Jiang |
USENIX Security Symposium | 2 |