EDBT 2026 Demo / reviewers in the wild / expert
Mengjia Yan 0001
dblp:137/0590
· DBLP profile ↗
31ranked-venue papers
7as first author
18since 2021 · last 2026
0000-0002-6206-9674ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 20 · 5 first-author · 9 since 2021Security and privacy · 11 · 2 first-author · 9 since 2021Software engineering, systems software and programming languages · 11 · 2 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Compass: Navigating the Design Space of Taint Schemes for RTL Security VerificationabstractHardware information flow tracking (IFT) using taint analysis provides a methodology to check whether a hardware design satisfies certain security properties. Previous work has shown a broad trade-off space between precision and complexity when using different taint analysis schemes. A careful investigation of this space has led to the insight that applying different taint schemes to different components of a hardware design can improve overall efficiency. Qinhan Tan, Thomas Bourgeat, Sharad Malik, Mengjia Yan 0001 |
ASPLOS (2) | 5 |
| 2026 | Interplay of Efficient Model Checking and Secure Processor Design: A Case Study on Secure Speculation
Tingzhen Dong, Qinhan Tan, Thomas Bourgeat, Sharad Malik, Yu-Wei Fan, Mengjia Yan 0001 |
SP | 8 |
| 2026 | Fractal: An Operating System Designed for Microarchitecture Reverse Engineering
Joseph Ravichandran, Mengjia Yan 0001 |
SP | 2 |
| 2026 | Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFI
Daniël Trujillo, Jagadish Kotra, Mengjia Yan 0001 |
SP | 4 |
| 2026 | INSIGHT: Automatic Generation of Explanations for Efficient Identification of Hardware Bugs and Underspecifications
Vincent Ulitzsch, Alessandro Bertani, Peter W. Deutsch, David Langus Rodriguez, Kelly Xu, Aarti Gupta, Sharad Malik, Mengjia Yan 0001 |
SP | 8 |
| 2025 | RTL Verification for Secure Speculation Using Contract Shadow LogicabstractModern out-of-order processors face speculative execution attacks. Despite various proposed software and hardware mitigations to prevent such attacks, new attacks keep arising from unknown vulnerabilities. Thus, a formal and rigorous evaluation of the ability of hardware designs to deal with speculative execution attacks is urgently desired. Qinhan Tan, Thomas Bourgeat, Sharad Malik, Mengjia Yan 0001 |
ASPLOS (1) | 5 |
| 2025 | Securing Cryptographic Software via Typed Assembly LanguageabstractAuthors of cryptographic software are well aware that their code should not leak secrets through its timing behavior, and, until 2018, they believed that following industry-standard constant-time coding guidelines was sufficient. However, the revelation of the Spectre family of speculative execution attacks injected new complexities. Shixin Song, Tingzhen Dong, Kosi Nwabueze, Julian Zanders, Andres Erbsen, Adam Chlipala, Mengjia Yan 0001 |
CCS | 7 |
| 2025 | Oreo: Protecting ASLR Against Microarchitectural Attacks
Shixin Song, Joseph Zhang, Mengjia Yan 0001 |
NDSS | 3 |
| 2024 | SoK: Understanding Design Choices and Pitfalls of Trusted Execution EnvironmentsabstractTrusted execution environment (TEE) is a revolutionary technology that enables secure remote execution (SRE) of cloud workloads on untrusted server-side computing platforms. Both commercial and academic TEEs have been proposed in the past few years, including Intel's SGX and TDX, AMD's SEV, ARM's CCA, IBM's PEF, and their academic counterparts built atop open-source RISC-V processors, such as Keystone, Sanctum, CURE, and Penglai. While great efforts from both sides have been made in developing a confidential computing ecosystem, the existence of server-side TEEs with drastically different designs and the presence of various known attacks have significantly increased the difficulty of understanding TEE designs and the reasons behind existing attacks. Mengyuan Li 0004, Guoxing Chen, Mengjia Yan 0001, Yinqian Zhang |
AsiaCCS | 4 |
| 2024 | DelayAVF: Calculating Architectural Vulnerability Factors for Delay FaultsabstractReliability is a key design consideration for modern microprocessors. A surge of reports from major cloud vendors describing new silent data corruption (SDC) behaviours at scale suggest a recent change in the nature of faults in the wild. Recent publications have suggested that one root cause of these SDCs may be small delay faults (SDFs) induced by marginal defects that increase a circuit's propagation time by a small (sub-cycle) delay. Reasoning about the effects of these faults early in the design of a processor is thus of increasing importance for reliability at-scale. Computer architects currently reason about the resilience of microarchitectures against particle strike induced faults using Architectural Vulnerability Factor (AVF) which describes the probability that a particle strike impacting a particular microar-chitectural structure results in a program-visible failure. In this paper, we develop an AVF-like metric to quantify a processor's vulnerability to SDFs. We conduct a systematic analysis of the potential impacts of SDFs and determine that particle strike AVF is insufficient to reason about SDFs. Considering SDFs requires additional reasoning about the timing characteristics of a circuit, the state element(s) that experience an error due to a fault, and whether the resulting state element errors cause a program-visible failure. In this paper we present DelayAVF, a metric that quantifies microarchitectural vulnerability to small delay faults. We develop a two-step methodology to analyze the DelayAVF of a hardware design. We then analyze the DelayAVF of an open-source RISC-V core, finding new architectural reliability insights that do not present themselves through traditional AVF analysis. Finally, we provide approximations for DelayAVF that allow for the reuse of particle strike AVF data (for instance, from existing fault injection studies). Peter W. Deutsch, Vincent Ulitzsch, Sudhanva Gurumurthi, Vilas Sridharan, Joel S. Emer, Mengjia Yan 0001 |
MICRO | 6 |
| 2023 | Metior: A Comprehensive Model to Evaluate Obfuscating Side-Channel Defense SchemesabstractMicroarchitectural side-channels enable an attacker to exfiltrate information via the observable side-effects of a victim's execution. Obfuscating mitigation schemes have recently gained in popularity for their appealing performance characteristics. These schemes, including randomized caches and DRAM traffic shapers, limit, but do not completely eliminate, side-channel leakage. An important (yet under-explored) research challenge is the quantitative study of the security effectiveness of these schemes, identifying whether these obfuscating schemes help increase the security level of a system, and if so, by how much. Peter W. Deutsch, Weon Taek Na, Thomas Bourgeat, Joel S. Emer, Mengjia Yan 0001 |
ISCA | 5 |
| 2023 | Pensieve: Microarchitectural Modeling for Security EvaluationabstractTraditional modeling approaches in computer architecture aim to obtain an accurate estimation of performance, area, and energy of a processor design. With the advent of speculative execution attacks and their security concerns, these traditional modeling techniques fall short when used for security evaluation of defenses against these attacks. Thomas Bourgeat, Stella Lau, Mengjia Yan 0001 |
ISCA | 4 |
| 2023 | SecureLoop: Design Space Exploration of Secure DNN AcceleratorsabstractDeep neural networks (DNNs) are gaining popularity in a wide range of domains, ranging from speech and video recognition to healthcare. With this increased adoption comes the pressing need for securing DNN execution environments on CPUs, GPUs, and ASICs. While there are active research efforts in supporting a trusted execution environment (TEE) on CPUs, the exploration in supporting TEEs on accelerators is limited, with only a few solutions available [18, 19, 27]. A key limitation along this line of work is that these secure DNN accelerators narrowly consider a few specific architectures. The design choices and the associated cost for securing these architectures do not transfer to other diverse architectures. Kyungmi Lee, Mengjia Yan 0001, Joel S. Emer, Anantha P. Chandrakasan |
MICRO | 2 |
| 2022 | DAGguise: mitigating memory timing side channelsabstractThis paper studies the mitigation of memory timing side channels, where attackers utilize contention within DRAM controllers to infer a victim’s secrets. Already practical, this class of channels poses an important challenge to secure computing in shared memory environments. Peter W. Deutsch, Thomas Bourgeat, Jules Drean, Joel S. Emer, Mengjia Yan 0001 |
ASPLOS | 6 |
| 2022 | There's always a bigger fish: a clarifying analysis of a machine-learning-assisted side-channel attackabstractMachine learning has made it possible to mount powerful attacks through side channels that have traditionally been seen as challenging to exploit. However, due to the black-box nature of machine learning models, these attacks are often difficult to interpret correctly. Models that detect correlations cannot be used to prove causality or understand an attack's various sources of information leakage. Jack Cook, Jules Drean, Jonathan Behrens, Mengjia Yan 0001 |
ISCA | 4 |
| 2022 | PACMAN: attacking ARM pointer authentication with speculative executionabstractThis paper studies the synergies between memory corruption vulnerabilities and speculative execution vulnerabilities. We leverage speculative execution attacks to bypass an important memory protection mechanism, ARM Pointer Authentication, a security feature that is used to enforce pointer integrity. We present PACMAN, a novel attack methodology that speculatively leaks PAC verification results via micro-architectural side channels without causing any crashes. Our attack removes the primary barrier to conducting control-flow hijacking attacks on a platform protected using Pointer Authentication. Joseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia Yan 0001 |
ISCA | 4 |
| 2022 | Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh Interconnects
Miles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John D. McCalpin, Mengjia Yan 0001 |
USENIX Security Symposium | 5 |
| 2021 | SpecTaint: Speculative Taint Analysis for Discovering Spectre Gadgets
Zhenxiao Qi, Yueqiang Cheng, Mengjia Yan 0001, Heng Yin 0001, Tao Wei 0002 |
NDSS | 4 |
| 2020 | CaSA: End-to-end Quantitative Security Analysis of Randomly Mapped CachesabstractIt is well known that there are micro-architectural vulnerabilities that enable an attacker to use caches to exfiltrate secrets from a victim. These vulnerabilities exploit the fact that the attacker can detect cache lines that were accessed by the victim. Therefore, architects have looked at different forms of randomization to thwart the attacker's ability to communicate using the cache. The security analysis of those randomly mapped caches is based upon the increased difficulty for the attacker to determine the addresses that touch the same cache line that the victim has accessed. In this paper, we show that the analyses used to evaluate those schemes were incomplete in various ways. For example, they were incomplete because they only focused on one of the steps used in the exfiltration of secrets. Specifically, the step that the attacker uses to determine the set of addresses that can monitor the cache lines used by the transmitter address. Instead, we broaden the analysis of micro-architecture side channels by providing an overall view of the communication process. This allows us to identify the existence of other communication steps that can also affect the security of randomly mapped caches, but have been ignored by prior work. We design an analysis framework, CaSA, to comprehensively and quantitatively analyze the security of these randomly mapped caches. We comprehensively consider the end-to-end communication steps and study the statistical relationship between different steps. In addition, to perform quantitative analysis, we leverage the concepts from the field of telecommunications to formulate the security analysis into a statistical problem. We use CaSA to evaluate a wide range of attack strategies and cache configurations. Our result shows that the randomization mechanisms used in the state-of-the-art randomly mapped caches are insecure. Thomas Bourgeat, Jules Drean, Lillian Tsai, Joel S. Emer, Mengjia Yan 0001 |
MICRO | 6 |
| 2020 | Speculation Invariance (InvarSpec): Faster Safe Execution Through Program AnalysisabstractMany hardware-based defense schemes against speculative execution attacks use special mechanisms to protect instructions while speculative, and lift the mechanisms when the instructions turn non-speculative. In this paper, we observe that speculative instructions can sometimes become Speculation Invariant before turning non-speculative. Speculation invariance means that (i) whether the instruction will execute and (ii) the instruction's operands are not a function of speculative state. Hence, we propose to lift the protection mechanisms on these instructions early, when they become speculation invariant, and issue them without protection. As a result, we improve the performance of the defense schemes without changing their security properties. To exploit speculation invariance, we present the InvarSpec framework. InvarSpec includes a program analysis pass that identifies, for each relevant instruction i, the set of older instructions that are Safe for i-i.e., those that do not prevent i from becoming speculation invariant. At runtime, the InvarSpec micro-architecture loads this information and uses it to determine when speculative instructions can be issued without protection. InvarSpec is one of the first defense schemes for speculative execution that combines cooperative compiler and hardware mechanisms. Our evaluation shows that InvarSpec effectively reduces the execution overhead of hardware defense schemes. For example, on SPEC17, it reduces the average execution overhead of fence protections from 195.3% to 108.2%, of Delay-On-Miss from 39.5% to 24.4%, and of InvisiSpec from 15.4% to 10.9%. Zirui Neil Zhao, Houxiang Ji, Mengjia Yan 0001, Jiyong Yu, Christopher W. Fletcher, Adam Morrison 0001, Darko Marinov, Josep Torrellas |
MICRO | 3 |
| 2020 | Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures
Mengjia Yan 0001, Christopher W. Fletcher, Josep Torrellas |
USENIX Security Symposium | 1 |
| 2019 | MicroScope: enabling microarchitectural replay attacksabstractThe popularity of hardware-based Trusted Execution Environments (TEEs) has recently skyrocketed with the introduction of Intel's Software Guard Extensions (SGX). In SGX, the user process is protected from supervisor software, such as the operating system, through an isolated execution environment called an enclave. Despite the isolation guarantees provided by TEEs, numerous microarchitectural side channel attacks have been demonstrated that bypass their defense mechanisms. But, not all hope is lost for defenders: many modern fine-grain, high-resolution side channels---e.g., execution unit port contention---introduce large amounts of noise, complicating the adversary's task to reliably extract secrets. Dimitrios Skarlatos 0002, Mengjia Yan 0001, Bhargava Gopireddy, Read Sprabery, Josep Torrellas, Christopher W. Fletcher |
ISCA | 2 |
| 2019 | SecDir: a secure directory to defeat directory side-channel attacksabstractDirectories for cache coherence have been recently shown to be vulnerable to conflict-based side-channel attacks. By forcing directory conflicts, an attacker can evict victim directory entries, which in turn trigger the eviction of victim cache lines from private caches. This evidence strongly suggests that directories need to be redesigned for security. The key to a secure directory is to block interference between processes. Sadly, in an environment with many cores, this is hard or expensive to do. Mengjia Yan 0001, Jen-Yang Wen, Christopher W. Fletcher, Josep Torrellas |
ISCA | 1 |
| 2019 | InvisiSpec: Making Speculative Execution Invisible in the Cache Hierarchy (Corrigendum)abstractNo abstract available. Mengjia Yan 0001, Jiho Choi, Dimitrios Skarlatos 0002, Adam Morrison 0001, Christopher W. Fletcher, Josep Torrellas |
MICRO | 1 |
| 2019 | Speculative Taint Tracking (STT): A Comprehensive Protection for Speculatively Accessed DataabstractSpeculative execution attacks present an enormous security threat, capable of reading arbitrary program data under malicious speculation, and later exfiltrating that data over microarchitectural covert channels. Since these attacks first rely on being able to read arbitrary data (potential secrets), a conservative approach to defeat all attacks is to delay the execution of instructions that read those secrets, until those instructions become non-speculative. Jiyong Yu, Mengjia Yan 0001, Artem Khyzha, Adam Morrison 0001, Josep Torrellas, Christopher W. Fletcher |
MICRO | 2 |
| 2019 | Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive WorldabstractAlthough clouds have strong virtual memory isolation guarantees, cache attacks stemming from shared caches have proved to be a large security problem. However, despite the past effectiveness of cache attacks, their viability has recently been called into question on modern systems, due to trends in cache hierarchy design moving away from inclusive cache hierarchies. In this paper, we reverse engineer the structure of the directory in a sliced, non-inclusive cache hierarchy, and prove that the directory can be used to bootstrap conflict-based cache attacks on the last-level cache. We design the first cross-core Prime+Probe attack on non-inclusive caches. This attack works with minimal assumptions: the adversary does not need to share any virtual memory with the victim, nor run on the same processor core. We also show the first high-bandwidth Evict+Reload attack on the same hardware. We demonstrate both attacks by extracting key bits during RSA operations in GnuPG on a state-of-the-art non-inclusive Intel Skylake-X server. Mengjia Yan 0001, Read Sprabery, Bhargava Gopireddy, Christopher W. Fletcher, Roy H. Campbell, Josep Torrellas |
IEEE Symposium on Security and Privacy | 1 |
| 2018 | Record-Replay Architecture as a General Security FrameworkabstractHardware security features need to strike a careful balance between design intrusiveness and completeness of methods. In addition, they need to be flexible, as security threats continuously evolve. To help address these requirements, this paper proposes a novel framework where Record and Deterministic Replay (RnR) is used to complement hardware security features. We call the framework RnR-Safe. RnR-Safe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. This is because it relies on on-the-fly replay that transparently verifies whether the alarm is a real attack or a false positive. RnR-Safe uses two replayers: an always-on, fast Checkpoint replayer that periodically creates checkpoints, and a detailed-analysis Alarm replayer that is triggered when there is a threat alarm. As an example application, we use RnR-Safe to thwart Return Oriented Programming (ROP) attacks, including on the Linux kernel. Our design augments the Return Address Stack (RAS) with relatively inexpensive hardware. We evaluate RnR-Safe using a variety of workloads on virtual machines running Linux. We find that RnR-Safe is very effective. Thanks to the judicious RAS hardware extensions and hypervisor changes, the checkpointing replayer has an execution speed comparable to the recorded execution. Also, the alarm replayer needs to handle very few false positives. Yasser Shalabi, Mengjia Yan 0001, Nima Honarmand, Ruby B. Lee, Josep Torrellas |
HPCA | 2 |
| 2018 | UCNN: Exploiting Computational Reuse in Deep Neural Networks via Weight RepetitionabstractConvolutional Neural Networks (CNNs) have begun to permeate all corners of electronic society (from voice recognition to scene generation) due to their high accuracy and machine efficiency per operation. At their core, CNN computations are made up of multi-dimensional dot products between weight and input vectors. This paper studies how weight repetition-when the same weight occurs multiple times in or across weight vectors-can be exploited to save energy and improve performance during CNN inference. This generalizes a popular line of work to improve efficiency from CNN weight sparsity, as reducing computation due to repeated zero weights is a special case of reducing computation due to repeated weights. To exploit weight repetition, this paper proposes a new CNN accelerator called the Unique Weight CNN Accelerator (UCNN). UCNN uses weight repetition to reuse CNN sub-computations (e.g., dot products) and to reduce CNN model size when stored in off-chip DRAM-both of which save energy. UCNN further improves performance by exploiting sparsity in weights. We evaluate UCNN with an accelerator-level cycle and energy model and with an RTL implementation of the UCNN PE. On three contemporary CNNs, UCNN improves throughput-normalized energy consumption by 1.2x ~ 4x, relative to a similarly provisioned baseline accelerator that uses Eyeriss-style sparsity optimizations. At the same time, the UCNN processing element adds only 17-24% area overhead relative to the same baseline. Kartik Hegde, Jiyong Yu, Rohit Agrawal 0001, Mengjia Yan 0001, Michael Pellauer, Christopher W. Fletcher |
ISCA | 4 |
| 2018 | InvisiSpec: Making Speculative Execution Invisible in the Cache HierarchyabstractHardware speculation offers a major surface for micro-architectural covert and side channel attacks. Unfortunately, defending against speculative execution attacks is challenging. The reason is that speculations destined to be squashed execute incorrect instructions, outside the scope of what programmers and compilers reason about. Further, any change to micro-architectural state made by speculative execution can leak information. In this paper, we propose InvisiSpec, a novel strategy to defend against hardware speculation attacks in multiprocessors by making speculation invisible in the data cache hierarchy. InvisiSpec blocks micro-architectural covert and side channels through the multiprocessor data cache hierarchy due to speculative loads. In InvisiSpec, unsafe speculative loads read data into a speculative buffer, without modifying the cache hierarchy. When the loads become safe, InvisiSpec makes them visible to the rest of the system. InvisiSpec identifies loads that might have violated memory consistency and, at this time, forces them to perform a validation step. We propose two InvisiSpec designs: one to defend against Spectre-like attacks and another to defend against futuristic attacks, where any speculative load may pose a threat. Our simulations with 23 SPEC and 10 PARSEC workloads show that InvisiSpec is effective. Under TSO, using fences to defend against Spectre attacks slows down execution by 74% relative to a conventional, insecure processor; InvisiSpec reduces the execution slowdown to only 21%. Using fences to defend against futuristic attacks slows down execution by 208%; InvisiSpec reduces the slowdown to 72%. Mengjia Yan 0001, Jiho Choi, Dimitrios Skarlatos 0002, Adam Morrison 0001, Christopher W. Fletcher, Josep Torrellas |
MICRO | 1 |
| 2017 | Secure Hierarchy-Aware Cache Replacement Policy (SHARP): Defending Against Cache-Based Side Channel AttacksabstractIn cache-based side channel attacks, a spy that shares a cache with a victim probes cache locations to extract information on the victim's access patterns. For example, in evict+reload, the spy repeatedly evicts and then reloads a probe address, checking if the victim has accessed the address in between the two operations. While there are many proposals to combat these cache attacks, they all have limitations: they either hurt performance, require programmer intervention, or can only defend against some types of attacks. Mengjia Yan 0001, Bhargava Gopireddy, Thomas Shull, Josep Torrellas |
ISCA | 1 |
| 2016 | ReplayConfusion: Detecting cache-based covert channel attacks using record and replayabstractCache-based covert channel attacks use highly-tuned shared-cache conflict misses to pass information from a trojan to a spy process. Detecting such attacks is very challenging. State of the art detection mechanisms do not consider the general characteristics of such attacks and, instead, focus on specific communication protocols. As a result, they fail to detect attacks using different protocols and, hence, have limited coverage. In this paper, we make the following observation about these attacks: not only are the malicious accesses highly tuned to the mapping of addresses to the caches; they also follow a distinctive cadence as bits are being received. Changing the mapping of addresses to the caches substantially disrupts the conflict miss patterns, but retains the cadence. This is in contrast to benign programs. Based on this observation, we propose a novel, high-coverage approach to detect cache-based covert channel attacks. It is called ReplayConfusion, and is based on Record and deterministic Replay (RnR). After a program's execution is recorded, it is deterministically replayed using a different mapping of addresses to the caches. We then analyze the difference between the cache miss rate timelines of the two runs. If the difference function is both sizable and exhibits a periodic pattern, it indicates that there is an attack. This paper also introduces a new taxonomy of cache-based covert channel attacks, and shows that ReplayConfusion uncovers examples from all the categories. Finally, ReplayConfusion only needs simple hardware. Mengjia Yan 0001, Yasser Shalabi, Josep Torrellas |
MICRO | 1 |