EDBT 2026 Demo / reviewers in the wild / expert
Maria Mendez Real
dblp:175/4712 · also Maria Méndez Real
· DBLP profile ↗
13ranked-venue papers
2as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 10 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AudioGap: An AirGapped Covert Channel Exploiting the Frequency Diversity of Audio IC Electromagnetic LeakageabstractThis paper presents AudioGap, a novel Electromagnetic (EM) covert channel that exfiltrates data from airgapped systems by exploiting System Signals Auto Modulation (SSAM), a passive modulation phenomenon inherent in digital circuitry. Unlike conventional EM attacks that require fine control over hardware, AudioGap passively leverages SSAM interactions between a Local Oscillator (Lo) and nearby digital circuit to exfiltrate data.We demonstrate a covert channel based on Comb Frequency Division Multiplexing (CFDM) that achieves 2-bit-per-symbol-period transmission, effectively doubling the throughput of traditional On-Off Keying (OOK) and Binary Amplitude Shift Keying (B-ASK). Furthermore, we develop a harmonic-based frequency detection technique that reduces the search space by a factor of 30 compared to brute-force methods, significantly improving receiver frequency search.Experimental validation using a Realtek ALC3220 audio chip and Software Defined Radio (SDR) demonstrates data transmission up to 28 cm, with up to 25.8% lower Bit Error Rate (BER) compared to state-of-the-art modulation. Mohamed Alla Eddine Bahi, Maria Mendez Real, Erwan Nogues, Maxime Pelcat |
COMPSAC | 2 |
| 2025 | Comb Frequency Division Multiplexing: A Non-Binary Modulation for AirGap Covert Channel TransmissionabstractIsolated networks ensure the confidentiality of sensitive data on a system by eliminating all physical connections to public networks or external devices, making the system air-gapped. However, previous work has shown that Electromagnetic (EM) emanations when correlated with secret data, can lead to side or covert channels. Specifically, EM emissions caused by clocks can modulate high-frequency signals, enabling unauthorized data transmission to cross the air-gap. This work focuses on covert channels where a software or hardware Trojan inserted in the victim system induces side channel emissions that the attacker can recover through the covert channel, producing an intentional transmission and leakage of sensitive information. This paper introduces a novel encoding method for covert channels called Comb Frequency Division Multiplexing (CFDM). CFDM leverages modulated signals emitted by the victim system, which are evenly spaced across the frequency spectrum, creating a comb-like pattern. Moreover, the uncontrolled nature of the side channel modulation can make each subcarrier carry different information. Unlike traditional methods such as Frequency Shift Keying (FSK) and Amplitude Shift Keying (ASK), CFDM encodes information in both the frequency and amplitude dimensions of the covert channel harmonic sub-carriers. Mohamed Alla Eddine Bahi, Maria Mendez Real, Maxime Pelcat |
DATE | 2 |
| 2025 | Do Not Trust Power Management: A Survey on Internal Energy-based Attacks Circumventing Trusted Execution Environments Security PropertiesabstractOver the past few years, several research groups have introduced innovative hardware designs for Trusted Execution Environments (TEEs), aiming to secure applications against potentially compromised privileged software, including the kernel [ 10 , 63 ]. Since 2015 [ 94 ], a new class of software-enabled hardware attacks leveraging energy management mechanisms has emerged. These internal energy-based attacks comprise fault [ 86 ], side-channel [ 46 ], and covert channel attacks [ 28 ]. Their aim is to bypass TEE security guarantees and expose sensitive information such as cryptographic keys. They have increased in prevalence in the past few years [ 9 , 24 , 40 ]. Popular TEE implementations, such as ARM TrustZone and Intel SGX, incorporate countermeasures against these attacks. However, these countermeasures either hinder the capabilities of the power management mechanisms or have been shown to provide insufficient system protection [ 9 , 55 ]. This article presents the first comprehensive knowledge survey of these attacks, along with an evaluation of literature countermeasures. We believe that this study will spur further community efforts toward this increasingly important type of attacks. Owen Le Gonidec, Guillaume Bouffard, Jean-Christophe Prévotet, Maria Mendez Real |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2025 | DynHaMo: Dynamic Hardware-Based Monitoring Dedicated to Attacks DetectionabstractNumerous attacks compromising processor security have been developed over decades, including some targeting the microarchitecture, such as side-channel or transient attacks, or control-flow hijacking attacks. As these attacks target processor microarchitectural features and bypass software-level mitigation techniques, they are considered a serious threat. In order to mitigate these attacks while limiting the impact on performance, various detection methods have been proposed. Indeed, detection techniques offer solutions to limit the execution of costly countermeasures, only after attacks detection, limiting the induced performance overhead. However, detection techniques in the literature suffer from several drawbacks, including non-real-time detection, significant increase in execution time, or make the hypothesis of a trusted Operating System (OS). In this work, we introduce DynHaMo that addresses these issues by detecting attacks targeting the microarchitecture, such as Cache-based Side-Channel Attacks (CSCAs) and Return-Oriented Programming (ROP) attacks, at run-time by taking advantage of dynamic instruction insertion at the hardware level. DynHaMo, is a light-weight hardware micro-decoding unit capable of monitoring microarchitectural events on the fly. For evaluation purposes, DynHaMo has been integrated into a RISC-V core, assessed through multiple benchmarks and attack codes, and implemented on an FPGA platform. We evaluated our solution under high workloads to demonstrate the efficiency of the approach and its robustness to noise. The evaluation results show a detection accuracy of 99.3% on average, with 0.7% false negative and 1.2% false positive on average. Juliette Pottier, Maria Mendez Real, Bertrand Le Gal, Sébastien Pillement |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2023 | You Only Get One-Shot: Eavesdropping Input Images to Neural Network by Spying SoC-FPGA Internal BusabstractDeep learning is currently integrated into edge devices with strong energy consumption and real-time constraints. To fulfill such requirements, high hardware performances can be provided by hardware acceleration of heterogeneous integrated circuits (IC) such as System-on-Chip (SoC)-field programmable gate arrays (FPGAs). With the rising popularity of hardware accelerators for artificial intelligence (AI), more and more neural networks are employed in a variety of domains, involving computer vision applications. Autonomous driving, defence and medical domains are well-known examples from which the latter two in particular require processing sensitive and private data. Security issues of such systems should be addressed to prevent the breach of privacy and unauthorised exploitation of systems. In this paper, we demonstrate a confidentiality vulnerability in a SoC-based FPGA binarized neural network (BNN) accelerator implemented with a recent mainstream framework, FINN, and successfully extract the secret BNN input image by using an electromagnetic (EM) side-channel attack. Experiments demonstrate that with the help of a near-field magnetic probe, an attacker can, with only one inference, directly retrieve sensitive information from EM emanations produced by the internal bus of the SoC-FPGA. Our attack reconstructs SoC-FPGA internal images and recognizes a handwritten digit image with an average accuracy of 89% using a non-retrained MNIST classifier. Such vulnerability jeopardizes the confidentiality of SoC-FPGA embedded AI systems by exploiting side-channels that withstand the protection of chip I/Os through cryptographic methods. May Myat Thu, Maria Mendez Real, Maxime Pelcat, Philippe Besnier |
ARES | 2 |
| 2023 | Securing a RISC-V architecture: A dynamic approachabstractThe SecureV (also known as SecV) project offers an innovative, open-source hardware, secure, and high-performance processor core based on the RISC-V ISA. The originality of the approach lies in the integration of a complete solution to increase security based on dynamic code transformation, covering 4 of the 5 NIST11National Institute of Standards and Technology functions of cybersecurity via monitoring (identify, detect), obfuscation (protect), and dynamic adaptation (react). Sébastien Pillement, Maria Mendez Real, J. Pottier, T. Nieddu, Bertrand Le Gal, Sébastien Faucou, Jean-Luc Béchennec, Mikaël Briday, Sylvain Girbal, Jimmy Le Rhun, Olivier Gilles, Daniel Gracia Pérez, André Sintzoff, Jean-Roch Coulon |
DATE | 2 |
| 2021 | 0-1 ILP-based run-time hierarchical energy optimization for heterogeneous cluster-based multi/many-core systems
Simei Yang, Sébastien Le Nours, Maria Mendez Real, Sébastien Pillement |
J. Syst. Archit. | 3 |
| 2020 | Towards Malicious Exploitation of Energy Management MechanismsabstractArchitectures are becoming more and more complex to keep up with the increase of algorithmic complexity. To fully exploit those architectures, dynamic resources managers are required. The goal of dynamic managers is either to optimize the resource usage (e.g. cores, memory) or to reduce energy consumption under performance constraints. However, performance optimization being their main goal, they have not been designed to be secure and present vulnerabilities. Recently, it has been proven that energy managers can be exploited to cause faults within a processor allowing to steal information from a user device. However, this exploitation is not often possible in current commercial devices. In this work, we show current security vulnerabilities through another type of malicious usage of energy management, experimentation shows that it is possible to remotely lock out a device, denying access to all services and data, requiring for example the user to pay a ransom to unlock it. The main target of this exploit are embedded systems and we demonstrate this work by its implementation on two different commercial ARM-based devices. Safouane Noubir, Maria Mendez Real, Sébastien Pillement |
DATE | 2 |
| 2018 | Hardware/Software Co-Design of an Accelerator for FV Homomorphic Encryption Scheme Using Karatsuba AlgorithmabstractSomewhat Homomorphic Encryption (SHE) schemes allow to carry out operations on data in the cipher domain. In a cloud computing scenario, personal information can be processed secretly, inferring a high level of confidentiality. For many years, practical parameters of SHE schemes were overestimated, leading to only consider the FFT algorithm to accelerate SHE in hardware. Nevertheless, recent work demonstrates that parameters can be lowered without compromising the security [1]. Following this trend, this work investigates the benefits of using Karatsuba algorithm instead of FFT for the Fan-Vercauteren (FV) Homomorphic Encryption scheme. The proposed accelerator relies on an hardware/software co-design approach, and is designed to perform fast arithmetic operations on degree 2,560 polynomials with 135 bits coefficients, allowing to compute small algorithms homomorphically. Compared to a functionally equivalent design using FFT, our accelerator performs an homomorphic multiplication in 11.9 ms instead of 15.46 ms, and halves the size of logic utilization and registers on the FPGA. Vincent Migliore, Maria Mendez Real, Vianney Lapotre, Arnaud Tisserand, Caroline Fontaine, Guy Gogniat |
IEEE Trans. Computers | 2 |
| 2018 | Application Deployment Strategies for Spatial Isolation on Many-Core AcceleratorsabstractCurrent cache Side-Channel Attacks (SCAs) countermeasures have not been designed for many-core architectures and need to be revisited in order to be practical for these new technologies. Spatial isolation of resources for sensitive applications has been proposed taking advantage of the large number of resources offered by these architectures. This solution avoids cache sharing with sensitive processes. Consequently, their cache activity cannot be monitored and cache SCAs cannot be performed. This work focuses on the implementation of this technique in order to minimize the induced performance overhead. Different strategies for the management of isolated secure zones are implemented and compared. Maria Mendez Real, Philipp Wehner, Vianney Lapotre, Diana Göhringer, Guy Gogniat |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2017 | A High-Speed Accelerator for Homomorphic Encryption using the Karatsuba AlgorithmabstractSomewhat Homomorphic Encryption (SHE) schemes can be used to carry out operations on ciphered data. In a cloud computing scenario, personal information can be processed secretly, inferring a high level of confidentiality. The principle limitation of SHE is the size of ciphertext compared to the size of the message. This issue can be addressed by using a batching technique that “packs” several messages into one ciphertext. However, this method leads to important drawbacks in standard implementations. This paper presents a fast hardware/software co-design implementation of an encryption procedure using the Karatsuba algorithm. Our hardware accelerator is 1.5 times faster than the state of the art for 1 encryption and 4 times faster for 4 encryptions. Vincent Migliore, Cédric Seguin, Maria Mendez Real, Vianney Lapotre, Arnaud Tisserand, Caroline Fontaine, Guy Gogniat, Russell Tessier |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2016 | Fast polynomial arithmetic for Somewhat Homomorphic Encryption operations in hardware with Karatsuba algorithmabstractSomewhat Homomorphic Encryption (SHE) schemes allow to carry out operations on data in the cipher domain. In a cloud computing scenario, personal information can be processed secretly, inferring a high level of confidentiality. Most practical Somewhat Homomorphic Encryption (SHE) schemes require the implementation of fast polynomial arithmetic, that is why hardware accelerators usually target the FFT/NTT algorithm. This paper proposes a co-design hardware/software approach to accelerate SHE using Karatsuba algorithm. Depending on the needs, Karatsuba algorithm allows to implement additional computations to the hardware in order to reduce software computation time. Our accelerator is designed to speed up arithmetic on degree 2560 polynomials with 125 bits coefficients. We provide 3 different approaches: An area efficient design, a balanced design, and a performance-oriented design. Our accelerator performs a polynomial multiplication in respectively 2.46 ms, 1.70 ms and 1.24 ms, and a relinearization operation in 2.28 ms, 1.53 ms and 1.1 ms, while a functionally equivalent design using the FFT [1] performs the multiplication in 1.96 ms and the relinearization in 4.79 ms for hardware resources consumption equivalent to the balanced design. Vincent Migliore, Maria Mendez Real, Vianney Lapotre, Arnaud Tisserand, Caroline Fontaine, Guy Gogniat |
FPT | 2 |
| 2016 | ALMOS Many-Core Operating System Extension with New Secure-Enable Mechanisms for Dynamic Creation of Secure ZonesabstractMany-core architectures are becoming a major execution platform in order to face the increasing number of applications to be executed in parallel. Such an approach is very attractive in order to offer users with high performance. However it introduces some key challenges in terms of security as some malicious applications may compromise the whole system. A defense-in-depth approach relying on hardware and software mechanisms is thus mandatory to increase the level of protection. This work focuses on the Operating System (OS) level and proposes a set of operating system services able to dynamically create physical isolated secure zones for sensitive applications in many-core platforms. These services are integrated into the ALMOS OS deployed in the TSAR many-core architecture, and evaluated in terms of security level and induced performance overhead. Maria Mendez Real, Vincent Migliore, Vianney Lapotre, Guy Gogniat |
PDP | 1 |