EDBT 2026 Demo / reviewers in the wild / expert
Merve Gülmez
dblp:158/1692 · also Merve Turan, Merve Turhan
· DBLP profile ↗
7ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0002-3150-0687ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Do We Still Need Canaries in the Coal Mine? Measuring Shadow Stack Effectiveness in Countering Stack Smashing
Hugo Depuydt, Merve Gülmez, Thomas Nyman, Jan Tobias Mühlberg |
ARES (2) | 2 |
| 2025 | BLACKOUT: Data-Oblivious Computation with Blinded CapabilitiesabstractLack of memory-safety and exposure to side channels are two prominent, persistent challenges for the secure implementation of software. Memory-safe programming languages promise to significantly reduce the prevalence of memory-safety bugs, but make it more difficult to implement side-channel-resistant code. We aim to address both memory-safety and side-channel resistance by augmenting memory-safe hardware with the ability for data-oblivious programming. We describe an extension to the CHERI capability architecture to provide blinded capabilities that allow data-oblivious computation to be carried out by userspace tasks. We also present BLACKOUT, our realization of blinded capabilities on a FPGA softcore based on the speculative out-of-order CHERI-Toooba processor and extend the CHERI-enabled Clang/LLVM compiler and the CheriBSD operating system with support for blinded capabilities. BLACKOUT makes writing side-channel-resistant code easier by making non-data-oblivious operations via blinded capabilities explicitly fault. Through rigorous evaluation we show that BLACKOUT ensures memory operated on through blinded capabilities is securely allocated, used, and reclaimed and demonstrate that, in benchmarks comparable to those used by previous work, BLACKOUT imposes only a small performance degradation (1.5% geometric mean) compared to the baseline CHERI-Toooba processor. Hossam ElAtali, Merve Gülmez, Thomas Nyman, N. Asokan |
CCS | 2 |
| 2025 | Mon CHERI: Mitigating Uninitialized Memory Access with Conditional CapabilitiesabstractUp to 10% of memory-safety vulnerabilities in languages like C and C++ stem from uninitialized variables. This work addresses the prevalence and lack of adequate software mitigations for uninitialized memory issues, proposing architectural protections in hardware. Capability-based addressing, such as the University of Cambridge's CHERI, mitigates many memory defects, including spatial and temporal safety violations at an architectural level. CHERI, however, does not handle undefined behavior from uninitialized variables. We extend the CHERI capability model to include “conditional capabilities”, enabling memory-access policies based on prior operations. This allows enforcement of policies that satisfy memory-safety objectives such as “no reads to memory without at least one prior write” (Write-before-Read). We present our architecture extension, compiler support, and detailed evaluation of our approach on the QEMU full-system simulator and a modified FPGA-based CHERI-RISCV softcore. Our evaluation shows conditional capabilities are practical, with high detection accuracy while adding a small (≈3.5%) overhead which is comparable to the cost of baseline CHERI capabilities. Merve Gülmez, Håkan Englund, Jan Tobias Mühlberg, Thomas Nyman |
SP | 1 |
| 2024 | System Call Interposition Without CompromiseabstractSyscall interposition is crucial for tools that monitor/modify application behavior. Mainstream OSes have, therefore, provided syscall interposition APIs for years, but these often incur prohibitive performance penalties in syscall-intensive applications. Recent work showed how to reduce this overhead by rewriting syscall instructions11Throughout this paper, we will use the term “syscall instruction” to refer to both the x86 SYSCALL and SYSENTER instructions. to invoke the interposer directly, avoiding expensive mode/context switches. However, these methods may not locate/rewrite all relevant instructions, which is essential for many applications. Our key insight is to combine the aforementioned techniques to efficiently intercept all system calls. We present lazypoline, a tool that uses slow kernel interfaces to exhaustively locate valid syscall instructions upon their first use, and then lazily rewrites them to invoke the interposer directly in all subsequent executions. We extensively evaluate lazypoline on micro- and macrobenchmarks and show that it is non-intrusive, fully exhaustive, and it achieves the efficiency of pure rewriting, even for datacenter-scale syscall-intensive workloads. Adriaan Jacobs, Merve Gülmez, Alicia Andries, Stijn Volckaert, Alexios Voulimeneas |
DSN | 2 |
| 2023 | Rewind & Discard: Improving Software Resilience using Isolated DomainsabstractWell-known defenses exist to detect and mitigate common faults and memory safety vulnerabilities in software. Yet, many of these mitigations do not address the challenge of software resilience and availability, i.e., whether a system can continue to carry out its function and remain responsive, while being under attack and subjected to malicious inputs. In this paper we propose secure rewind and discard of isolated domains as an efficient and secure method of improving the resilience of software that is targeted by run-time attacks. In difference to established approaches, we rely on compartmentalization instead of replication and checkpointing. We show the practicability of our methodology by realizing a software library for Secure Domain Rewind and Discard (SDRaD) and demonstrate how SDRaD can be applied to real-world software. Merve Gülmez, Thomas Nyman, Christoph Baumann, Jan Tobias Mühlberg |
DSN | 1 |
| 2019 | Deep Convolutional Learning-Aided Detector for Generalized Frequency Division Multiplexing with Index ModulationabstractIn this paper, a deep convolutional neural network-based symbol detection and demodulation is proposed for generalized frequency division multiplexing with index modulation (GFDM-IM) scheme in order to improve the error performance of the system. The proposed method first pre-processes the received signal by using a zeroforcing (ZF) detector and then uses a neural network consisting of a convolutional neural network (CNN) followed by a fully-connected neural network (FCNN). The FCNN part uses only two fully-connected layers, which can be adapted to yield a trade-off between complexity and bit error rate (BER) performance. This two-stage approach prevents the getting stuck of neural network in a saddle point and enables IM blocks processing independently. It has been demonstrated that the proposed deep convolutional neural network-based detection and demodulation scheme provides better BER performance compared to ZF detector with a reasonable complexity increase. We conclude that non-orthogonal waveforms combined with IM schemes with the help of deep learning is a promising physical layer (PHY) scheme for future wireless networks. Merve Gülmez, Ersin Öztürk, Hakan A. Çirpan |
PIMRC | 1 |
| 2015 | Space Time Block Code classification for MIMO signals exploiting cyclostationarityabstractBlind and noncooperative identification of the transmission parameters of unknown communication signals has been employed both in military and civilian applications. Multiple-Input-Multiple-Output (MIMO) transmission systems emerging in the last decade pose new challenges to the signal identification systems, one of which is the identification of the Space-Time Block Code (STBC) used in the transmission. In this work, we present a novel STBC classification algorithm that exploits the joint wide sense cyclostationary characteristics of the coded transmit signals as discriminating features. Compared to existing algorithms, the proposed method can discriminate between a large number of different STBCs. Merve Gülmez, Mengüç Öner, Hakan A. Çirpan |
ICC | 1 |