EDBT 2026 Demo / reviewers in the wild / expert
Iaroslav Gridin
dblp:238/9967
· DBLP profile ↗
5ranked-venue papers
3as first author
2since 2021 · last 2025
0000-0002-1239-1841ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Sound of Reduction: Minimal Inputs, Maximal CoverageabstractGuaranteeing the security of cryptographic constructions requires not only theoretically sound designs but also correct and robust implementations. Among the various software testing techniques, fuzz testing is a technique commonly used to automatically verify computer programs that accept user input, by observing its behavior upon receiving diverse inputs. While fuzz testing has proven effective in identifying implementation issues, the structural complexity and input constraints of cryptographic software is one of the big hurdles that existing fuzzers are wrestling with. In this work, we introduce The Sound of Reduction (SoR), a novel fuzzing framework that combines complexity reduction with coverage guidance to improve the effectiveness of fuzzers when applied in cryptographic software. At the core of SoR is an enhanced version of Proptest testing library, that can perform efficient input minimization while leveraging runtime coverage feedback to explore deeper execution paths. We evaluate our approach across a broad range of Post-Quantum Cryptography implementations, including lattice, code, and multivariate-based schemes. Our results demonstrate significant improvements in code coverage and input corpus quality compared to state-of-the-art coverage-guided fuzzers. Iaroslav Gridin, Antonis Michalas, Alejandro Cabrera Aldaya |
TrustCom | 1 |
| 2024 | Point Intervention: Improving ACVP Test Vector Generation Through Human Assisted Fuzzing
Iaroslav Gridin, Antonis Michalas |
ICICS (2) | 1 |
| 2020 | Déjà Vu: Side-Channel Analysis of Mozilla's NSSabstractRecent work on Side Channel Analysis (SCA) targets old, well-known vulnerabilities, even previously exploited, reported, and patched in high-profile cryptography libraries. Nevertheless, researchers continue to find and exploit the same vulnerabilities in old and new products, highlighting a big issue among vendors: effectively tracking and fixing security vulnerabilities when disclosure is not done directly to them. In this work, we present another instance of this issue by performing the first library-wide SCA security evaluation of Mozilla's NSS security library. We use a combination of two independently-developed SCA security frameworks to identify and test security vulnerabilities. Our evaluation uncovers several new vulnerabilities in NSS affecting DSA, ECDSA, and RSA cryptosystems. We exploit said vulnerabilities and implement key recovery attacks using signals---extracted through different techniques such as timing, microarchitecture, and EM---and improved lattice methods. Sohaib ul Hassan, Iaroslav Gridin, Ignacio M. Delgado-Lozano, Cesar Pereida García, Jesús-Javier Chi-Domínguez, Alejandro Cabrera Aldaya, Billy Bob Brumley |
CCS | 2 |
| 2020 | Certified Side Channels
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin, Alejandro Cabrera Aldaya, Billy Bob Brumley |
USENIX Security Symposium | 4 |
| 2019 | Triggerflow: Regression Testing by Advanced Execution Path Inspection
Iaroslav Gridin, Cesar Pereida García, Nicola Tuveri, Billy Bob Brumley |
DIMVA | 1 |