EDBT 2026 Demo / reviewers in the wild / expert
Matthew Hicks
dblp:09/2334
· DBLP profile ↗
39ranked-venue papers
4as first author
26since 2021 · last 2026
0000-0002-3639-4342ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 18 · 2 first-author · 12 since 2021Security and privacy · 18 · 1 first-author · 13 since 2021Software engineering, systems software and programming languages · 16 · 2 first-author · 9 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Sheriff: Arresting the Confused Deputy Undermining Ultra-low SWaP Device Trusted Execution EnvironmentsabstractAn often overlooked consequence of the emerging era of smart dust enabled by Ultra-low Size, Weight, and Power (UlSWaP) Internet-of-Things devices is managing software complexity. UlSWaP devices help solve many important societal problems across disparate domains, but this requires software support. Managing the demands of software complexity forces smart dust vendors to turn to third-party software libraries that solve common concerns. This opens the door to a new problem, where third-party library vendors must protect their Intellectual Property and secret data (e.g., keys) from end-users and competitors alike. Device vendors attempt to address this security need through the addition of on-chip Trusted Execution Environments (TEEs) in their latest UlSWaP chips. While these TEEs successfully protect against untrusted software, they fail to protect against attacks that coopt trusted software as an indirect means of attack: Confused Deputy attacks. Prakhar Sah, Matthew Hicks |
AsiaCCS | 2 |
| 2026 | Signal Breaker: Fuzzing Digital Signal ProcessorsabstractFuzzing is one of the most effective techniques for discovering software vulnerabilities. Fuzzers use feedback from prior executions to generate new test cases via random mutation,executing these inputs to uncover bugs. Fuzzing has been successfully applied to applications, operating systems, processors, and network protocols, making it one of the most widely adopted software testing methodologies. Despite this success, fuzzing has seen little adoption for Digital Signal Processor (DSP) software. DSPs occupy a unique position at the boundary of hardware and software: they ingest signals from the physical world, execute software instructions, and are tightly integrated into data-processing pipelines. Many safety- and security-critical domains, including telecommunications, transportation, and defense, rely heavily on DSPs, making robust DSP testing essential. To address this gap, we introduce SBFUZZ, a coverage-guided fuzzer designed specifically for DSP software. SBFUZZ is driven by three key observations: (1) DSPs expose limited and high-latency execution control and communication interfaces, and (2) DSPs have unique architectures that necessitate new instrumentation and mutation routines, and (3) DSP fuzzing must detect both traditional software bugs manifested as crashes and hardware-style bugs manifested as divergent yet continuing execution. Based on these insights, SBFUZZ advocates a DSP-centric fuzzer decomposition, where the DSP executes most fuzzing tasks autonomously while periodically leveraging a more powerful host for coordination, analysis, and storage. This design allows a single host to concurrently fuzz multiple end devices and supports both physical DSPs and simulated DSPs for re-hosted fuzzing. We implement SBFUZZ on a Texas Instruments TMS320C5515 DSP and evaluate it on 15 DSP benchmark programs.Our results show that SBFUZZ achieves 17.4x higher throughput and 2.6x greater code coverage than prior embedded fuzzing approaches applied to DSPs, uncovering 2491 unique crashes, yielding 34 unique bugs Cameron Santiago Garcia, Matthew Hicks |
ASPLOS (2) | 2 |
| 2026 | $\mu$RNG: A Framework for Assessing Randomness in Intermittent Computing Devices
Prakhar Sah, Matthew Hicks |
ISCA | 2 |
| 2025 | Retain the Date: Detecting Recycled Chips in the Supply Chain Through SRAM's Data Retention BehaviorabstractThe life cycle of an Integrated Circuit (IC) involves a global network of stakeholders—designers, manufacturers, suppliers, and system integrators—introducing inherent opacity into the supply chain. This complexity is exacerbated by IC shortages, lingering effects of the global pandemic, and rising geopolitical tensions, all of which increase the risk of counterfeit infiltration. Among these, the most prevalent threat is the recycled chip: a used IC that is repackaged and sold as new. These recycled devices, while functionally equivalent, suffer from degraded reliability, which poses a serious challenge to system integrity and long-term dependability. We present Retain The Date (RTD), a hardware-overhead-free method for detecting recycled ICs that exploits Static Random Access Memory's (SRAM) data retention voltage to identify previously-used devices. RTD exploits an observation that SRAM—the most ubiquitous form of computer memory—retains data at just a fraction of its nominal voltage; and as SRAM cells age, statistical properties over whole-SRAM data retention voltage change in a way that differentiates it from the statistical properties of new devices. We design a variable-resolution time-analog of data retention voltage to measure aging-induced statistical asymmetry that forgoes specialized or expensive measurement equipment. RTD detects previously-used commercial ICs with 97% accuracy, preventing recycled counterfeits from affecting the availability of critical systems. Jubayer Mahmod, Matthew Hicks |
ACSAC | 2 |
| 2025 | PhasePrint: Exposing Cloud FPGA Fingerprints by Inducing Timing Faults at RuntimeabstractCloud FPGAs, with their scalable and flexible nature, are rapidly gaining traction as go-to hardware acceleration platforms for compute-intensive workloads. However, their increasing adoption introduces unique security challenges. The hardware-level access that FPGAs provide leads to many vulnerabilities, including the leakage of sensitive information through data remanence and the creation of analog-domain covert channels among users. A foundational requirement in these scenarios is the ability to target an individual FPGA; knowing this, cloud vendors prevent FPGA localization by restricting access to low-level information of the underlying hardware. Beyond aiding adversaries, FPGA localization enables defenders to strategically rotate FPGA usage, preventing prolonged exposure that can lead to confidential data leakage due to long-term data remanence. Jubayer Mahmod, Matthew Hicks |
ASPLOS (2) | 2 |
| 2025 | ClosureX: Compiler Support for Correct Persistent FuzzingabstractFuzzing is a widely adopted and pragmatic methodology for bug hunting as a means of software hardening. Research reveals that increasing fuzzing throughput directly increases bug discovery rate. The highest performance fuzzing strategy is persistent fuzzing, which reuses a single process for all test cases by looping back to the start upon completion, instead of exiting. This eliminates all process creation, initialization, and tear-down costs---which are on-par with execution cost. Unfortunately, persistent fuzzing leads to semantically inconsistent program states because process state changes from one test case remain for subsequent test cases. This semantic inconsistency results in missed crashes, false crashes, and overall incorrectness that undermines fuzzer effectiveness. Rishi Ranjan, Ian Paterson, Matthew Hicks |
ASPLOS (1) | 3 |
| 2025 | A Bio-Inspired Goal-Directed Cognitive Map Approach to Robot Navigation and MappingabstractThis paper presents a cognitive map (CM) model fused with a histogram-based reactive local navigator algorithm for real-time robot mapping and navigation. Drawing inspiration from biological navigation, the CM model integrates elements like landmarks, Euclidean distance, exploratory movement, and reward-driven actions. Key features of the model include types of cognitive mapping cells designed to replicate their biological functions in a computationally efficient manner. Built on cognitive map concepts used to explain mammalian navigation, this CM model enables robots to navigate complex environments without needing complete environmental exploration. Additionally, an enhanced ℬ-spline curve scheme ensures a smoother, safer trajectory. After planning a global route, the model utilizes a histogram-based local navigation algorithm to dynamically avoid obstacles while creating real-time maps as the robot follows its path. Simulation and comparison results validate that this integrated approach supports real-time navigation and mapping in unknown environments, offering significant improvements in robotic spatial navigation and real-time map building. Matthew Hicks, Tingjun Lei, Chaomin Luo, Lantao Liu, Zhuming Bi |
CEC | 1 |
| 2024 | SRAM Imprinting for System Protection and DifferentiationabstractThe foundation of trusted computation depends on the ability to verify the authenticity of the underlying hardware. This need is further compounded by the presence of counterfeit components in the market, highlighting the necessity for pre-deployment and run-time chip identification techniques. Current solutions involve burning authentication information in physical fuses or creating a unique mask for each integrated circuit, which are either costly or susceptible to forgery. While many solutions have been proposed to prevent chip counterfeiting at design time, no accurate, reference-free, and cost-effective solutions exist for chip buyers to authenticate their purchases in the pre-deployment phase and enable software-level verification at runtime. The lack of industry-standard authentication methods forces chip buyers to either adopt expensive solutions, such as X-Ray imaging, or simply rely on blind faith. Jubayer Mahmod, Matthew Hicks |
AsiaCCS | 2 |
| 2024 | Energy-Adaptive Buffering for Efficient, Responsive, and Persistent Batteryless SystemsabstractBatteryless energy harvesting systems enable a wide array of new sensing, computation, and communication platforms untethered by power delivery or battery maintenance demands. Energy harvesters charge a buffer capacitor from an unreliable environmental source until enough energy is stored to guarantee a burst of operation despite changes in power input. Current platforms use a fixed-size buffer chosen at design time to meet constraints on charge time or application longevity, but static energy buffers are a poor fit for the highly volatile power sources found in real-world deployments: fixed buffers waste energy both as heat when they reach capacity during a power surplus and as leakage when they fail to charge the system during a power deficit. Harrison Williams, Matthew Hicks |
ASPLOS (3) | 2 |
| 2024 | A Software Caching Runtime for Embedded NVRAM SystemsabstractIncreasingly sophisticated low-power microcontrollers are at the heart of millions of IoT and edge computing deployments, with developers pushing large-scale data collection, processing, and inference to end nodes. Advanced workloads on resource-constrained systems depend on emerging technologies to meet performance and lifetime demands. High-performance Non-Volatile RAMs (NVRAMs) are one such technology enabling a new class of systems previously made impossible by memory limitations, including ultra-low-power designs using program state non-volatility and sensing systems storing and processing large blocks of data. Harrison Williams, Matthew Hicks |
ASPLOS (4) | 2 |
| 2024 | UnTrustZone: Systematic Accelerated Aging to Expose On-chip SecretsabstractAs technology scaling brings society closer to the vision of smart dust, system designers must address the threat of physical attacks. To address the threat of physical access to computing devices, defenders move secrets on the chip, keeping them out of reach of non-nation-state-level attackers. Modern systems allow hardware-backed security enclaves called Trusted Execution Environments (TEEs); TEEs add hardware-level protections on top of keeping secrets on chips that extend protection against privileged software and flaws within the untrusted parts of the software. While the best TEEs protect against concurrent and temporally recent attacks (e.g., the cold boot attack), we uncover a new threat to all forms of on-chip crypto: long-term data remanence.We show that the most ubiquitous form of on-chip memory, Static Random-Access Memory (SRAM), changes at the analog-domain-level in a data-dependent way as software uses it. Under normal conditions, these changes occur gradually over a device’s lifetime, but we show how an attacker can systematically accelerate this data imprinting on SRAM’s analog domain to effectively burn-in on-chip secrets. We then reveal the imprinted secrets through measurements of SRAM’s power-on state. We use this capability to demonstrate three attacks: one that reveals an AES key protected by TrustZone, proprietary firmware protected by TrustZone, and secrets stored in cache memory. Overall, we show that it is possible to imprint and exfiltrate secrets from a range of SRAM-based memories across 13 devices, from 8 manufacturers, produced across three decades—with up to 98% accuracy. To address this threat, we provide guidance to chip vendors and programmers on the defensive trade space. Jubayer Mahmod, Matthew Hicks |
SP | 2 |
| 2024 | A Difference World: High-performance, NVM-invariant, Software-only Intermittent Computation
Harrison Williams, Saim Ahmad, Matthew Hicks |
USENIX ATC | 3 |
| 2023 | T-TER: Defeating A2 Trojans with Targeted Tamper-Evident RoutingabstractSince the inception of the Integrated Circuit (IC), the size of the transistors used to construct them has continually shrunk. While this advancement significantly improves computing capability, fabrication costs have skyrocketed. As a result, most IC designers must now outsource fabrication. Outsourcing, however, presents a security threat: comprehensive post-fabrication inspection is infeasible given the size of modern ICs, so it is nearly impossible to know if the foundry has altered the original design during fabrication (i.e., inserted a hardware Trojan). Defending against a foundry-side adversary is challenging because—even with as few as two gates—hardware Trojans can completely undermine software security. Researchers have attempted to both detect and prevent foundry-side attacks, but all existing defenses are ineffective against additive Trojans with footprints of a few gates or less. Timothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew Hicks |
AsiaCCS | 4 |
| 2023 | RF Energy Harvesting in Minimization of Age of Information with Updating ErasuresabstractThis paper presents an investigation into practical considerations in the minimization of Age of Information (AoI) for the system architectures with and without updating feedback. To study the impact of the critical characteristics of the energy harvesters on the computing accuracy of the average AoI, an RF energy harvester with a half-wavelength patch antenna array along with a 3-stage voltage rectifier is designed and prototyped with the center frequency of 2.655 GHz. A cryptography algorithm is also implemented on a$\mu$-controller unit to imitate the behavior of a practical processing unit. The paper shows measurement results and discusses the impact of the non-idealities in the energy harvester on the average AoI of the system. It also shows that the nonlinear power conversion profile of the energy harvester can increase the average AoI to over 300% compared to an ideal and linear energy harvester. Fariborz Lohrabi Pour, Harrison Williams, Matthew Hicks, Dong Sam Ha |
ISCAS | 3 |
| 2023 | Not All Data are Created Equal: Data and Pointer Prioritization for Scalable Protection Against Data-Oriented Attacks
Salman Ahmed 0001, Hans Liljestrand, Hani Jamjoom, Matthew Hicks, N. Asokan, Danfeng Yao |
USENIX Security Symposium | 4 |
| 2023 | No Linux, No Problem: Fast and Correct Windows Binary Fuzzing via Target-embedded Snapshotting
Leo Stone, Rishi Ranjan, Stefan Nagy, Matthew Hicks |
USENIX Security Symposium | 4 |
| 2022 | One Fuzz Doesn't Fit All: Optimizing Directed Fuzzing via Target-tailored Program State RestrictionabstractFuzzing is the de-facto default technique to discover software flaws, randomly testing programs to discover crashing test cases. Yet, a particular scenario may only care about specific code regions (for, e.g., bug reproduction, patch or regression testing)—spurring the adoption of directed fuzzing. Given a set of pre-determined target locations, directed fuzzers drive exploration toward them through distance minimization strategies that (1) isolate the closest-reaching test cases and (2) mutate them stochastically. However, these strategies are applied onto every explored test case—irrespective of whether they ever reach the targets—stalling progress on the paths where targets are unreachable. Accelerating directed fuzzing requires prioritizing target-reachable paths. Prashast Srivastava, Stefan Nagy, Matthew Hicks, Antonio Bianchi, Mathias Payer |
ACSAC | 3 |
| 2022 | SRAM has no chill: exploiting power domain separation to steal on-chip secretsabstractThe abundance of embedded systems and smart devices increases the risk of physical memory disclosure attacks. One such classic non-invasive attack exploits dynamic RAM's temperature-dependent ability to retain information across power cycles---known as a cold boot attack. When exposed to low temperatures, DRAM cells preserve their state for a short time without power, mimicking non-volatile memories in that time frame. Attackers exploit this physical phenomenon to gain access to a system's secrets, leading to data theft from encrypted storage. To prevent cold boot attacks, programmers hide secrets on-chip in Static Random-Access Memory (SRAM); by construction, on-chip SRAM is isolated from external probing and has little intrinsic capacitance, making it robust against cold boot attacks. Jubayer Mahmod, Matthew Hicks |
ASPLOS | 2 |
| 2022 | Invisible bits: hiding secret messages in SRAM's analog domainabstractElectronic devices are increasingly the subject of inspection by authorities. While encryption hides secret messages, it does not hide the transmission of those secret messages---in fact, it calls attention to them. Thus, an adversary, seeing encrypted data, turns to coercion to extract the credentials required to reveal the secret message. Steganographic techniques hide secret messages in plain sight, providing the user with plausible deniability, removing the threat of coercion. Jubayer Mahmod, Matthew Hicks |
ASPLOS | 2 |
| 2022 | Self-Reinforcing Memoization for Cryptography Calculations in Secure Memory SystemsabstractModern memory systems use encryption and message authentication codes to ensure confidentiality and integrity. Encryption and integrity verification rely on cryptography calculations, which are slow. To hide the latency of cryptography calculations, prior works exploit the fact that many cryptography steps only require a memory block’s write counter (i.e., a value that increases whenever the block is written to memory), but not the block itself. As such, memory controller (MC) caches counters so that MC can start calculating before missing blocks arrive from memory.Irregular workloads suffer from high counter miss rates, however, just like they suffer from high miss rates of page table entries. Many prior works have looked at the problem of page table entry misses for irregular workloads, but not the problem of counter misses for the irregular workloads.This paper addresses the memory latency overheads that irregular workloads suffer due to their high counter miss rate. We observe many (e.g., unlimited number of) counters can have the same value. As such, we propose memoizing cryptography calculations for hot counter values. When a counter arrives from memory, MC can use the counter value to look up a memoization table to quickly obtain the counter’s memoized results instead of slowly recalculating them. To maximize memoization table hit rate, we observe whenever writing a block to memory, increasing its counter to any value higher than the current counter value can satisfy the security requirement of always using different counter values to encrypt the same block. As such, we also propose a memoization-aware counter update: when writing a block to memory, increase its counter to a value whose cryptography calculation is currently memoized. We refer to memoizing the calculation results of counters and the corresponding memoization-aware counter update collectively as Self-Reinforcing Memoization for Cryptography Calculations (RMCC). Our evaluations show that RMCC improves average performance by 6% compared to the state-of-the-art. On average across the lifetimes of different workloads, RMCC accelerates decryption and verification for 92% of counter misses. Daulet Talapkaliyev, Matthew Hicks, Xun Jian 0002 |
MICRO | 3 |
| 2022 | Fuzzing Hardware Like Software
Timothy Trippel, Kang G. Shin, Alex Chernyakhovsky, Garret Kelly, Dominic Rizzo, Matthew Hicks |
USENIX Security Symposium | 6 |
| 2021 | RingRAM: A Unified Hardware SecurityPrimitive for IoT Devices that Gets Better with AgeabstractAs security grows in importance, system designers turn to hardware support for security. Hardware’s unique properties enable functionality and performance levels not available with software alone. One unique property of hardware is non-determinism. Unlike software, which is inherently deterministic (e.g., the same inputs produce the same outputs), hardware encompasses an abundance of non-determinism; non-determinism born out of manufacturing and operational chaos. While hardware designers focus on hiding the effects of such chaos behind voltage and clock frequency guard bands, security practitioners embrace the chaos as a source of randomness. Michael Moukarzel, Matthew Hicks |
ACSAC | 2 |
| 2021 | Same Coverage, Less Bloat: Accelerating Binary-only Fuzzing with Coverage-preserving Coverage-guided TracingabstractCoverage-guided fuzzing's aggressive, high-volume testing has helped reveal tens of thousands of software security flaws. While executing billions of test cases mandates fast code coverage tracing, the nature of binary-only targets leads to reduced tracing performance. A recent advancement in binary fuzzing performance is Coverage-guided Tracing (CGT), which brings orders-of-magnitude gains in throughput by restricting the expense of coverage tracing to only when new coverage is guaranteed. Unfortunately, CGT suits only a basic block coverage granularity---yet most fuzzers require finer-grain coverage metrics: edge coverage and hit counts. It is this limitation which prohibits nearly all of today's state-of-the-art fuzzers from attaining the performance benefits of CGT. Stefan Nagy, Anh Nguyen-Tuong, Jason Hiser, Jack W. Davidson, Matthew Hicks |
CCS | 5 |
| 2021 | Failure Sentinels: Ubiquitous Just-in-time Intermittent Computation via Low-cost Hardware Support for Voltage MonitoringabstractEnergy harvesting systems support the deployment of low-power microcontrollers untethered by constant power sources or batteries, enabling long-lived deployments in a variety of applications previously limited by power or size constraints. However, the limitations of harvested energy mean that even the lowest-power microcontrollers operate intermittently—waiting for the harvester to slowly charge a buffer capacitor and rapidly discharging the capacitor to support a brief burst of computation. The challenges of the intermittent operation brought on by harvested energy drive a variety of hardware and software techniques that first enabled long-running computation, then focused on improving performance. Many of the most promising systems demand dynamic updates of available energy to inform checkpointing and mode decisions.Unfortunately, existing energy monitoring solutions based on analog circuits (e.g., analog-to-digital converters) are ill-matched for the task because their signal processing focus sacrifices power efficiency for increased performance—performance not required by current or future intermittent computation systems. This results in existing solutions consuming as much energy as the microcontroller, stealing energy from useful computation. To create a low-power energy monitoring solution that provides just enough performance for intermittent computation use cases, we design and implement Failure Sentinels, an on-chip, fully-digital energy monitor. Failure Sentinels leverages the predictable propagation delay response of digital logic gates to supply voltage fluctuations to measure available energy. Our design space exploration shows that Failure Sentinels provides 30–50mV of resolution at sample rates up to 10kHz, while consuming less than 2µA of current. Experiments show that Failure Sentinels increases the energy available for software computation by up to 77%, compared to current solutions. We also implement a RISC-V-based FPGA prototype that validates our design space exploration and shows the overheads of incorporating Failure Sentinels into a system-on-chip. Harrison Williams, Michael Moukarzel, Matthew Hicks |
ISCA | 3 |
| 2021 | Bomberman: Defining and Defeating Hardware Ticking Timebombs at Design-timeabstractTo cope with ever-increasing design complexities, integrated circuit designers increase both the size of their design teams and their reliance on third-party intellectual property (IP). Both come at the expense of trust: it is computationally infeasible to exhaustively verify that a design is free of all possible malicious modifications (i.e., hardware Trojans). Making matters worse, unlike software, hardware modifications are permanent: there is no "patching" mechanism for hardware; and powerful: they serve as a foothold for subverting software that sits above.To counter this threat, prior work uses both static and dynamic analysis techniques to verify hardware designs are Trojan-free. Unfortunately, researchers continue to reveal weaknesses in these "one-size-fits-all", heuristic-based approaches. Instead of attempting to detect all possible hardware Trojans, we take the first step in addressing the hardware Trojan threat in a divide-and-conquer fashion: defining and eliminating Ticking Timebomb Trojans (TTTs), forcing attackers to implement larger Trojan designs detectable via existing verification and side-channel defenses. Like many system-level software defenses (e.g., Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP)), our goal is to systematically constrict the hardware attacker’s design space.First, we construct a definition of TTTs derived from their functional behavior. Next, we translate this definition into fundamental components required to realize TTT behavior in hardware. Using these components, we expand the set of all known TTTs to a total of six variants—including unseen variants. Leveraging our definition, we design and implement a TTT-specific dynamic verification toolchain extension, called Bomber-man. Using four real-world hardware designs, we demonstrate Bomberman’s ability to detect all TTT variants, where previous defenses fail, with <1.2% false positives. Timothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew Hicks |
SP | 4 |
| 2021 | Breaking Through Binaries: Compiler-quality Instrumentation for Better Binary-only Fuzzing
Stefan Nagy, Anh Nguyen-Tuong, Jason Hiser, Jack W. Davidson, Matthew Hicks |
USENIX Security Symposium | 5 |
| 2020 | Forget Failure: Exploiting SRAM Data Remanence for Low-overhead Intermittent ComputationabstractEnergy harvesting is a promising solution to power billions of ultra-low-power Internet-of-Things devices to enable ubiquitous computing. However, energy harvesters typically output tiny amounts of energy and, therefore, cannot continuously power devices; this leads to intermittent computing, where the energy harvester periodically charges a capacitor to sufficient voltage to power brief computation, until the capacitor's charge is drained, and the cycle repeats. To retain program state across frequent power failures, prior work proposes checkpointing program state to Non-Volatile Memory (NVM) before a power failure. Unfortunately, the most widely deployed, highest performance, and lowest cost devices employ Flash as their NVM, but the power, time, and endurance limitations of Flash writes are incompatible with the frequent NVM checkpoints of intermittent computation. Harrison Williams, Xun Jian 0002, Matthew Hicks |
ASPLOS | 3 |
| 2020 | ICAS: an Extensible Framework for Estimating the Susceptibility of IC Layouts to Additive TrojansabstractThe transistors used to construct Integrated Circuits (ICs) continue to shrink. While this shrinkage improves performance and density, it also reduces trust: the price to build leading-edge fabrication facilities has skyrocketed, forcing even nation states to outsource the fabrication of high-performance ICs. Outsourcing fabrication presents a security threat because the black-box nature of a fabricated IC makes comprehensive inspection infeasible. Since prior work shows the feasibility of fabrication-time attackers' evasion of existing post-fabrication defenses, IC designers must be able to protect their physical designs before handing them off to an untrusted foundry. To this end, recent work suggests methods to harden IC layouts against attack. Unfortunately, no tool exists to assess the effectiveness of the proposed defenses, thus leaving defensive gaps.This paper presents an extensible IC layout security analysis tool called IC Attack Surface (ICAS) that quantifies defensive coverage. For researchers, ICAS identifies gaps for future defenses to target, and enables the quantitative comparison of existing and future defenses. For practitioners, ICAS enables the exploration of the impact of design decisions on an IC's resilience to fabrication-time attack. ICAS takes a set of metrics that encode the challenge of inserting a hardware Trojan into an IC layout, a set of attacks that the defender cares about, and a completed IC layout and reports the number of ways an attacker can add each attack to the design. While the ideal score is zero, practically, we find that lower scores correlate with increased attacker effort.To demonstrate ICAS' ability to reveal defensive gaps, we analyze over 60 layouts of three real-world hardware designs (a processor, AES and DSP accelerators), protected with existing defenses. We evaluate the effectiveness of each circuit-defense combination against three representative attacks from the literature. Results show that some defenses are ineffective and others, while effective at reducing the attack surface, leave 10's to 1000's of unique attack implementations that an attacker can exploit. Timothy Trippel, Kang G. Shin, Kevin B. Bush, Matthew Hicks |
SP | 4 |
| 2019 | Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingabstractCoverage-guided fuzzing is one of the most successful approaches for discovering software bugs and security vulnerabilities. Of its three main components: (1) test case generation, (2) code coverage tracing, and (3) crash triage, code coverage tracing is a dominant source of overhead. Coverage-guided fuzzers trace every test case's code coverage through either static or dynamic binary instrumentation, or more recently, using hardware support. Unfortunately, tracing all test cases incurs significant performance penalties--even when the overwhelming majority of test cases and their coverage information are discarded because they do not increase code coverage. To eliminate needless tracing by coverage-guided fuzzers, we introduce the notion of coverage-guided tracing. Coverage-guided tracing leverages two observations: (1) only a fraction of generated test cases increase coverage, and thus require tracing; and (2) coverage-increasing test cases become less frequent over time. Coverage-guided tracing encodes the current frontier of coverage in the target binary so that it self-reports when a test case produces new coverage--without tracing. This acts as a filter for tracing; restricting the expense of tracing to only coverage-increasing test cases. Thus, coverage-guided tracing trades increased time handling coverage-increasing test cases for decreased time handling non-coverage-increasing test cases. To show the potential of coverage-guided tracing, we create an implementation based on the static binary instrumentor Dyninst called UnTracer. We evaluate UnTracer using eight real-world binaries commonly used by the fuzzing community. Experiments show that after only an hour of fuzzing, UnTracer's average overhead is below 1%, and after 24-hours of fuzzing, UnTracer approaches 0% overhead, while tracing every test case with popular white- and black-box-binary tracers AFL-Clang, AFL-QEMU, and AFL-Dyninst incurs overheads of 36%, 612%, and 518%, respectively. We further integrate UnTracer with the state-of-the-art hybrid fuzzer QSYM and show that in 24-hours of fuzzing, QSYM-UnTracer executes 79% and 616% more test cases than QSYM-Clang and QSYM-QEMU, respectively. Stefan Nagy, Matthew Hicks |
IEEE Symposium on Security and Privacy | 2 |
| 2017 | Clank: Architectural Support for Intermittent ComputationabstractThe processors that drive embedded systems are getting smaller; meanwhile, the batteries used to provide power to those systems have stagnated. If we are to realize the dream of ubiquitous computing promised by the Internet of Things, processors must shed large, heavy, expensive, and high maintenance batteries and, instead, harvest energy from their environment. One challenge with this transition is that harvested energy is insufficient for continuous operation. Unfortunately, existing programs fail miserably when executed intermittently. Matthew Hicks |
ISCA | 1 |
| 2016 | ANVIL: Software-Based Protection Against Next-Generation Rowhammer AttacksabstractEnsuring the integrity and security of the memory system is critical. Recent studies have shown serious security concerns due to "rowhammer" attacks, where repeated accesses to a row of memory cause bit flips in adjacent rows. Recent work by Google's Project Zero has shown how to leverage rowhammer-induced bit-flips as the basis for security exploits that include malicious code injection and memory privilege escalation. Being an important security concern, industry has attempted to defend against rowhammer attacks. Deployed defenses employ two strategies: (1) doubling the system DRAM refresh rate and (2) restricting access to the CLFLUSH instruction that attackers use to bypass the cache to increase memory access frequency (i.e., the rate of rowhammering). We demonstrate that such defenses are inadequte: we implement rowhammer attacks that both avoid using the CLFLUSH instruction and cause bit flips with a doubled refresh rate. Our next-generation CLFLUSH-free rowhammer attack bypasses the cache by manipulating cache replacement state to allow frequent misses out of the last-level cache to DRAM rows of our choosing. Zelalem Birhanu Aweke, Salessawi Ferede Yitbarek, Rui Qiao 0002, Reetuparna Das, Matthew Hicks, Yossef Oren, Todd M. Austin |
ASPLOS | 5 |
| 2016 | Intermittent Computation without Hardware Support or Programmer Intervention
Joel van der Woude, Matthew Hicks |
OSDI | 2 |
| 2016 | A2: Analog Malicious HardwareabstractWhile the move to smaller transistors has been a boon for performance it has dramatically increased the cost to fabricate chips using those smaller transistors. This forces the vast majority of chip design companies to trust a third party -- often overseas -- to fabricate their design. To guard against shipping chips with errors (intentional or otherwise) chip design companies rely on post-fabrication testing. Unfortunately, this type of testing leaves the door open to malicious modifications since attackers can craft attack triggers requiring a sequence of unlikely events, which will never be encountered by even the most diligent tester. In this paper, we show how a fabrication-time attacker can leverage analog circuits to create a hardware attack that is small (i.e., requires as little as one gate) and stealthy (i.e., requires an unlikely trigger sequence before effecting a chip's functionality). In the open spaces of an already placed and routed design, we construct a circuit that uses capacitors to siphon charge from nearby wires as they transition between digital values. When the capacitors fully charge, they deploy an attack that forces a victim flip-flop to a desired value. We weaponize this attack into a remotely-controllable privilege escalation by attaching the capacitor to a wire controllable and by selecting a victim flip-flop that holds the privilege bit for our processor. We implement this attack in an OR1200 processor and fabricate a chip. Experimental results show that our attacks work, show that our attacks elude activation by a diverse set of benchmarks, and suggest that our attacks evade known defenses. Kaiyuan Yang 0001, Matthew Hicks, Qing Dong 0001, Todd M. Austin, Dennis Sylvester |
IEEE Symposium on Security and Privacy | 2 |
| 2015 | SPECS: A Lightweight Runtime Mechanism for Protecting Software from Security-Critical Processor BugsabstractProcessor implementation errata remain a problem, and worse, a subset of these bugs are security-critical. We classified 7 years of errata from recent commercial processors to understand the magnitude and severity of this problem, and found that of 301 errata analyzed, 28 are security-critical. We propose the SECURITY-CRITICAL PROCESSOR ER- RATA CATCHING SYSTEM (SPECS) as a low-overhead solution to this problem. SPECS employs a dynamic verification strategy that is made lightweight by limiting protection to only security-critical processor state. As a proof-of- concept, we implement a hardware prototype of SPECS in an open source processor. Using this prototype, we evaluate SPECS against a set of 14 bugs inspired by the types of security-critical errata we discovered in the classification phase. The evaluation shows that SPECS is 86% effective as a defense when deployed using only ISA-level state; incurs less than 5% area and power overhead; and has no software run-time overhead. Matthew Hicks, Cynthia Sturton, Samuel T. King, Jonathan M. Smith |
ASPLOS | 1 |
| 2015 | Probable cause: the deanonymizing effects of approximate DRAMabstractApproximate computing research seeks to trade-off the accuracy of computation for increases in performance or reductions in power consumption. The observation driving approximate computing is that many applications tolerate small amounts of error which allows for an opportunistic relaxation of guard bands (e.g., clock rate and voltage). Besides affecting performance and power, reducing guard bands exposes analog properties of traditionally digital components. For DRAM, one analog property exposed by approximation is the variability of memory cell decay times. Amir Rahmati, Matthew Hicks, Daniel E. Holcomb, Kevin Fu |
ISCA | 2 |
| 2015 | Determining conserved metabolic biomarkers from a million database queriesabstractMOTIVATION: Metabolite databases provide a unique window into metabolome research allowing the most commonly searched biomarkers to be catalogued. Omic scale metabolite profiling, or metabolomics, is finding increased utility in biomarker discovery largely driven by improvements in analytical technologies and the concurrent developments in bioinformatics. However, the successful translation of biomarkers into clinical or biologically relevant indicators is limited. RESULTS: With the aim of improving the discovery of translatable metabolite biomarkers, we present search analytics for over one million METLIN metabolite database queries. The most common metabolites found in METLIN were cross-correlated against XCMS Online, the widely used cloud-based data processing and pathway analysis platform. Analysis of the METLIN and XCMS common metabolite data has two primary implications: these metabolites, might indicate a conserved metabolic response to stressors and, this data may be used to gauge the relative uniqueness of potential biomarkers. AVAILABILITY AND IMPLEMENTATION: METLIN can be accessed by logging on to: https://metlin.scripps.edu CONTACT: [email protected] SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Michael E. Kurczy, Julijana Ivanisevic, Caroline H. Johnson, Winnie Uritboonthai, Mingliang Fang, Matthew Hicks, Anthony Aldebot, Duane Rinehart, Lisa J. Mellander, Ralf Tautenhahn, Gary J. Patti, Mary E. Spilker, H. Paul Benton, Gary Siuzdak |
Bioinform. | 7 |
| 2011 | Defeating UCI: Building Stealthy and Malicious HardwareabstractIn previous work Hicks et al. proposed a method called Unused Circuit Identification (UCI) for detecting malicious backdoors hidden in circuits at design time. The UCI algorithm essentially looks for portions of the circuit that go unused during design-time testing and flags them as potentially malicious. In this paper we construct circuits that have malicious behavior, but that would evade detection by the UCI algorithm and still pass design-time test cases. To enable our search for such circuits, we define one class of malicious circuits and perform a bounded exhaustive enumeration of all circuits in that class. Our approach is simple and straight forward, yet it proves to be effective at finding circuits that can thwart UCI. We use the results of our search to construct a practical attack on an open-source processor. Our malicious backdoor allows any user-level program running on the processor to enter supervisor mode through the use of a secret â knock. We close with a discussion on what we see as a major challenge facing any future design-time malicious hardware detection scheme: identifying a sufficient class of malicious circuits to defend against. Cynthia Sturton, Matthew Hicks, David A. Wagner 0001, Samuel T. King |
IEEE Symposium on Security and Privacy | 2 |
| 2010 | Overcoming an Untrusted Computing Base: Detecting and Removing Malicious Hardware AutomaticallyabstractThe computer systems security arms race between attackers and defenders has largely taken place in the domain of software systems, but as hardware complexity and design processes have evolved, novel and potent hardware-based security threats are now possible. This paper presents a hybrid hardware/software approach to defending against malicious hardware. We propose BlueChip, a defensive strategy that has both a design-time component and a runtime component. During the design verification phase, BlueChip invokes a new technique, unused circuit identification (UCI), to identify suspicious circuitry-those circuits not used or otherwise activated by any of the design verification tests. BlueChip removes the suspicious circuitry and replaces it with exception generation hardware. The exception handler software is responsible for providing forward progress by emulating the effect of the exception generating instruction in software, effectively providing a detour around suspicious hardware. In our experiments, BlueChip is able to prevent all hardware attacks we evaluate while incurring a small runtime overhead. Matthew Hicks, Murph Finnicum, Samuel T. King, Milo M. K. Martin, Jonathan M. Smith |
IEEE Symposium on Security and Privacy | 1 |
| 2009 | Capo: a software-hardware interface for practical deterministic multiprocessor replayabstractWhile deterministic replay of parallel programs is a powerful technique, current proposals have shortcomings. Specifically, software-based replay systems have high overheads on multiprocessors, while hardware-based proposals focus only on basic hardware-level mechanisms, ignoring the overall replay system. To be practical, hardware-based replay systems need to support an environment with multiple parallel jobs running concurrently -- some being recorded, others being replayed and even others running without recording or replay. Moreover, they need to manage limited-size log buffers. Pablo Montesinos, Matthew Hicks, Samuel T. King, Josep Torrellas |
ASPLOS | 2 |