Lukas Gerlach 0001

dblp:156/3555 · DBLP profile ↗
← Back
25ranked-venue papers
5as first author
20since 2021 · last 2026
0000-0001-5467-237XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 4 first-author · 18 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software Emulation
Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001
SP2
2026 TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads
Tristan Hornetz, Hosein Yavarzadeh, Albert Cheu, Adrià Gascón, Lukas Gerlach 0001, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz 0001, Ruiyi Zhang 0001
SP5
2025 ShadowLoad: Injecting State into Hardware Prefetchers
abstract
Hardware prefetchers are an optimization in modern CPUs that predict memory accesses and preemptively load the corresponding value into the cache. Previous work showed that the internal state of hardware prefetchers can act as a side channel, leaking information across security boundaries such as processes, user and kernel space, and even trusted execution environments.
Lorenz Hetterich, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Nils Bernsdorf, Eduard Ebert, Michael Schwarz 0001
ASPLOS (2)3
2025 RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs
abstract
The open and extensible RISC-V instruction set has enabled many new CPU vendors and implementations, but most commercial CPUs are closed-source, significantly hindering vulnerability analysis—especially for bugs exploitable from unprivileged user space.
Fabian Thomas, Eric García Arribas, Lorenz Hetterich, Daniel Weber 0007, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
CCS5
2025 Taming the Linux Memory Allocator for Rapid Prototyping
Ruiyi Zhang 0001, Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001
DIMVA (2)3
2025 Do Compilers Break Constant-Time Guarantees?
Lukas Gerlach 0001, Robert Pietsch, Michael Schwarz 0001
FC (2)1
2025 Lixom: Protecting Encryption Keys with Execute-Only Memory
Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001
FC2
2025 Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting
Leon Trampert, Daniel Weber 0007, Lukas Gerlach 0001, Christian Rossow, Michael Schwarz 0001
NDSS3
2025 Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage
abstract
Microarchitectural attacks are a growing threat to modern computing systems. CPU caches are an essential but complex element in many microarchitectural attacks, making it crucial to understand the inner workings. Despite progress in reverse-engineering techniques, non-linear cache-slice functions remain challenging to analyze, especially in recent Intel hybrid microarchitectures. In this paper, we introduce a novel approach towards reverse-engineering complex, non-linear cache-slice functions, particularly on modern Intel CPUs with hybrid microarchi-tectures. Our method significantly advances prior work by understanding the specific structure of microarchitectural hash functions, reducing the time required for reverse-engineering from days to minutes. In contrast to prior work, our technique successfully handles systems with 512 GB of memory and diverse slice configurations. We present 13 newly identified functions used for cache-slice addressing and extend existing functions to support systems with more DRAM for multiple CPU generations. Additionally, we introduce an unprivileged virtual-to-physical address oracle that is a direct consequence of the complexity of the non-linear slice functions. Our method is particularly effective on modern Intel hybrid CPUs, in-cluding Alder Lake and Meteor Lake, where previously used methods for measuring slices or leaking physical addresses are unavailable. In 3 case studies, we validate our approach, demonstrating its effectiveness in executing targeted Spectre attacks on non-attacker-mapped memory, enabling DRAMA attacks, and creating cache eviction sets. Our findings em-phasize the increased attack surface introduced by complex cache-slice functions in modern CPU s.
Mikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz, Leon Trampert, Lukas Gerlach 0001, Michael Schwarz 0001
SP6
2025 SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution
Daniel Weber 0007, Lukas Gerlach 0001, Leon Trampert, Youheng Lü, Jo Van Bulck, Michael Schwarz 0001
USENIX Security Symposium2
2025 Confusing Value with Enumeration: Studying the Use of CVEs in Academia
Moritz Schloegel, Daniel Klischies, Simon Koch 0001, David Klein 0001, Lukas Gerlach 0001, Malte Wessels, Leon Trampert, Martin Johns, Mathy Vanhoef, Michael Schwarz 0001, Thorsten Holz, Jo Van Bulck
USENIX Security Symposium5
2025 Peripheral Instinct: How External Devices Breach Browser Sandboxes
abstract
Browser APIs such as WebHID, WebUSB, Web Serial, and Web MIDI enable web applications to interact directly with external devices. The support of such APIs in Chromium-based browsers, such as Chrome and Edge, radically changes the threat model for peripherals and increases the attack surface. In the past, devices could assume a trusted host, i.e., the operating system. Now, the host is a potentially malicious website and cannot be trusted.
Leon Trampert, Lorenz Hetterich, Lukas Gerlach 0001, Mona Schappert, Christian Rossow, Michael Schwarz 0001
WWW3
2024 No Leakage Without State Change: Repurposing Configurable CPU Exceptions to Prevent Microarchitectural Attacks
abstract
Microarchitectural side-channel attacks have become significant threats to computer system security. While writing side-channel-resistant code can mitigate these attacks, it is time-consuming and error-prone. Detection approaches provide an alternative by monitoring the system for signs of ongoing attacks. However, distinguishing between malicious and benign processes is complex, error-prone, and ineffective against sophisticated attacks.In this paper, we propose a novel approach, IRQGuard, which shifts the focus to proactive mitigation. IRQGuard enables the victim to monitor its own microarchitectural events resulting from microarchitectural state changes. Leveraging existing CPU features, IRQGuard uses interrupt requests (IRQs) triggered by victim-specific microarchitectural state changes within predefined code regions. This self-monitoring eliminates noise of unrelated applications, enabling immediate detection and response to potential attacks. Our proof-of-concept implementation demonstrates that IRQGuard stops information leakage in under 200 CPU cycles, outperforming current methods significantly. We evaluate IRQGuard on both cryptographic (OpenSSL) and non-cryptographic (toilet command-line utility) applications. We demonstrate IRQGuard’s real-world viability by protecting an OpenSSH server from cache attacks. IRQGuard offers a practical, low-overhead solution for mitigating a wide range of microarchitectural attacks on Intel, AMD, and Arm CPUs.
Daniel Weber 0007, Leonard Niemann, Lukas Gerlach 0001, Jan Reineke 0001, Michael Schwarz 0001
ACSAC3
2024 Efficient and Generic Microarchitectural Hash-Function Recovery
abstract
Modern CPUs use a variety of undocumented microarchitectural hash functions to efficiently distribute data within microarchitectural structures such as caches. A well-known function is the cache slice function that distributes cache lines to the slices of the last-level cache. Knowing these functions considerally improves microarchitectural attacks, such as Prime+Probe or Rowhammer. However, while several such linear functions have been reverse-engineered, there is no generic or automated approach for reverse-engineering non-linear functions, which are common with modern CPUs.In this paper, we introduce a novel generic approach for automatically reverse-engineering a wide range of microarchitectural hash functions. Our approach combines techniques initially used for logic-gate minimization and from computer algebra to infer the hash functions based on input-output pairs observed via side channels. With our framework, we infer 3 previously unknown non-linear hash functions on both AMD and Intel CPUs, including the new Alder Lake hybrid-CPU architecture. We verify our approach by reproducing known hash functions and evaluating side-channel attacks that rely on these functions, resulting in success rates above 97.65 %. We stress the need to design such functions with both performance and security in mind and discuss alternative designs that can be used in future CPUs.
Lukas Gerlach 0001, Simon Schwarz 0001, Nicolas Faroß, Michael Schwarz 0001
SP1
2024 CacheWarp: Software-based Fault Injection using Selective State Reset
Ruiyi Zhang 0001, Lukas Gerlach 0001, Daniel Weber 0007, Lorenz Hetterich, Youheng Lü, Andreas Kogler, Michael Schwarz 0001
USENIX Security Symposium2
2023 A Rowhammer Reproduction Study Using the Blacksmith Fuzzer
Lukas Gerlach 0001, Fabian Thomas, Robert Pietsch, Michael Schwarz 0001
ESORICS (3)1
2023 Indirect Meltdown: Building Novel Side-Channel Attacks from Transient-Execution Attacks
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
ESORICS (3)3
2023 Reviving Meltdown 3a
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
ESORICS (3)3
2023 A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs
abstract
Microarchitectural attacks threaten the security of computer systems even in the absence of software vulnerabilities. Such attacks are well explored on x86 and ARM CPUs, with a wide range of proposed but not-yet deployed hardware countermeasures. With the standardization of the RISC-V instruction set architecture and the announcement of support for the architecture by major processor vendors, RISC-V CPUs are on the verge of becoming ubiquitous. However, the microarchitectural attack surface of the first commercially-available RISC-V hardware CPUs still needs to be explored.This paper analyzes the two commercially-available off-the-shelf 64-bit RISC-V (hardware) CPUs used in most RISC-V systems running a full-fledged commodity Linux system. We evaluate the microarchitectural attack surface and introduce 3 new microarchitectural attack techniques: Cache+Time, a novel cache-line-granular cache attack without shared memory, Flush+Fault exploiting the Harvard cache architecture for Flush+Reload, and CycleDrift exploiting unprivileged access to instruction-retirement information. We also show that many known attacks apply to these RISC-V CPUs, mainly due to non-existing hardware countermeasures and instruction-set subtleties that do not consider the microarchitectural attack surface. We demonstrate our attacks in 6 case studies, including the first RISC-V-specific microarchitectural KASLR break and a CycleDrift-based method for detecting kernel activity. Based on our analysis, we stress the need to consider the microarchitectural attack surface during every step of a CPU design, including custom ISA extensions.
Lukas Gerlach 0001, Daniel Weber 0007, Ruiyi Zhang 0001, Michael Schwarz 0001
SP1
2023 Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels
Andreas Kogler, Jonas Juffinger, Lukas Giner, Lukas Gerlach 0001, Martin Schwarzl, Michael Schwarz 0001, Daniel Gruss, Stefan Mangard
USENIX Security Symposium4
2019 KAVUAKA: A Low Power Application Specific Hearing Aid Processor
abstract
The integration of application specific instruction set processors (ASIPs) in hearing aids requires various architectural customizations and software-side optimizations in order to meet the stringent power consumption constraints and processing performance demands. This paper presents the KAVUAKA application specific hearing aid processor and its ASIC integration as a system on chip (SoC). The final system contains four KAVUAKA processor cores and ten co-processors. Each of these processors and co-processors were individually customized and differ in their data path width. The processors are organized in two clusters, which share memories, an audio interface, co-processors and a serial interface. With this system, different hearing aid systems are evaluated in terms of performance, power and area by activating different processor and co-processor combinations. A 40 nm low power technology was used to build this research hearing aid system. The die size is 3.6 mm2with less than 1 mm2per core. The measured average power consumption is less than 1 mW per core.
Lukas Gerlach 0001, Guillermo Payá-Vayá, Holger Blume
VLSI-SoC1
2019 FLINT+: A runtime-configurable emulation-based stochastic timing analysis framework
Moritz Weißbrich, Lukas Gerlach 0001, Holger Blume, Ardalan Najafi, Alberto García Ortiz, Guillermo Payá-Vayá
Integr.2
2019 DNN-based performance measures for predicting error rates in automatic speech recognition and optimizing hearing aid parameters
Angel Mario Castro Martinez, Lukas Gerlach 0001, Guillermo Payá-Vayá, Hynek Hermansky, Jasper Ooster, Bernd T. Meyer
Speech Commun.2
2017 Real-time implementation of a GMM-based binaural localization algorithm on a VLIW-SIMD processor
abstract
Localization algorithms have become of considerable interest for robot audition, acoustic navigation, teleconferencing, speaker localization, and many other applications over the last decade. In this paper, we present a real-time implementation of a Gaussian mixture model (GMM) based probabilistic sound source localization algorithm for a low-power VLIW-SIMD processor for hearing devices. The algorithm has been proven to allow for robust localization of multiple sound sources simultaneously in reverberant and noisy environments. Real-time computation for audio frames of 512 samples at 16 kHz was achieved by introducing algorithmic optimizations and hardware customizations. To the best of our knowledge, this is the first real-time capable implementation of a computationally complex GMM-based sound source localization algorithm on a low-power processor. The resulting estimated core area without consideration of memory in 40nm low-power TSMC technology is 188,511 pm2.
Christopher Seifert, Joachim Thiemann, Lukas Gerlach 0001, Tobias Volkmar, Guillermo Payá-Vayá, Holger Blume, Steven van de Par
ICME3
2015 FLINT: layout-oriented FPGA-based methodology for fault tolerant ASIC design
Rochus Nowosielski, Lukas Gerlach 0001, Stephan Bieband, Guillermo Payá-Vayá, Holger Blume
DATE2