EDBT 2026 Demo / reviewers in the wild / expert
Flavien Solt
dblp:264/9973
· DBLP profile ↗
17ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0002-0872-5562ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 3 first-author · 11 since 2021Systems, architecture and hardware · 6 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VerIFI: Formal Verification of Microarchitectural Information-Flow Integrity
Katharina Ceesay-Seitz, Flavien Solt, Mengyuan Yin, Kaveh Razavi |
EuroS&P | 2 |
| 2026 | HARTBREAKER: Deterministic Fuzzing of Multi-Hart RISC-V CPUs with Non-Deterministic Programs
Quentin Bordier, Tobias Kovats, Flavien Solt, Kaveh Razavi |
ISCA | 3 |
| 2025 | MileSan: Detecting Exploitable Microarchitectural Leakage via Differential Hardware-Software Taint Tracking
Tobias Kovats, Flavien Solt, Katharina Ceesay-Seitz, Kaveh Razavi |
CCS | 2 |
| 2025 | Pathfinder: Constructing Cycle-accurate Taint Graphs for Analyzing Information Flow TracesabstractHardware Information Flow Tracking (IFT) is gaining traction for detecting security vulnerabilities in hardware designs. Analyzing IFT violation traces can be extremely time-consuming since they often contain hundreds, if not thousands, of signals that need to be manually analyzed to establish the root cause behind the unexpected information flow. To resolve this problem, we introduce taint graphs that provide context as to where, when, and why information flows. To generalize to different IFT verification methods, we first develop a theoretical foundation for unifying taint tracking and self-composition under a common abstraction. Relying on this abstraction, we then build Pathfinder for automatically generating taint graphs from a given Hardware Description Language (HDL) design and a trace of the information flow violation given either by simulators or formal model checkers. We demonstrate the effectiveness of taint graphs in simplifying root cause analysis of information flows through multiple case studies that involve constant-time violations, temporal fencing, hardware Trojans, and Spectre. By extracting only the relevant signals on a path, Pathfinder reduces the number of signals that need to be manually analyzed between 1.6 and 769.9 times in these case studies. Katharina Ceesay-Seitz, Flavien Solt, Alexander Klukas, Kaveh Razavi |
ICCAD | 2 |
| 2025 | Encarsia: Evaluating CPU Fuzzers via Automatic Bug Injection
Matej Bölcskei, Flavien Solt, Katharina Ceesay-Seitz, Kaveh Razavi |
USENIX Security Symposium | 2 |
| 2025 | McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis
Patrick Jattke, Michele Marazzi, Flavien Solt, Max Wipfli, Stefan Gloor, Kaveh Razavi |
USENIX Security Symposium | 3 |
| 2025 | Lost in Translation: Enabling Confused Deputy Attacks on EDA Software with TransFuzz
Flavien Solt, Kaveh Razavi |
USENIX Security Symposium | 1 |
| 2024 | μCFI: Formal Verification of Microarchitectural Control-flow Integrity
Katharina Ceesay-Seitz, Flavien Solt, Kaveh Razavi |
CCS | 2 |
| 2024 | HybriDIFT: Scalable Memory-Aware Dynamic Information Flow Tracking for HardwareabstractDesigning correct and secure hardware is challenging. Dynamic information flow tracking (DIFT) enhances RTL testing flows, for example, by providing formal guarantees on detecting information leakage. However, existing DIFT solutions do not scale to large memories encountered in complex processors. A formal analysis of existing DIFT mechanisms reveals the two factors that fundamentally limit the scalability of instrumenting memories: existing mechanisms enforce that all memory words must be accessible simultaneously, and dependent reads and writes must happen concurrently. These aspects that are detrimental to scalability are all due to precise tracking of implicit flows for every memory word, which is not required in many scenarios of interest. Based on this insight, we design HybriDIFT, a module-level DIFT memory instrumentation based on SRAM deduplication and on a single state bit that tracks implicit information flows. HybriDIFT can automatically identify memories and their protocols by combining static and dynamic analysis. HybriDIFT is precise in practice and scalable to RTL designs that feature large memories. We evaluate HybriDIFT by automatically instrumenting a set of open-source hardware designs. With Verilator, HybriDIFT accelerates build time by 1.06× to 3.5× and simulation by 2.6× to 5.1× on default target configurations, and instruments a larger OpenC910 configuration that was out of reach for the state-of-the-art DIFT mechanisms, while preserving sufficient precision for all known applications. Flavien Solt, Kaveh Razavi |
ICCAD | 1 |
| 2024 | HiFi-DRAM: Enabling High-fidelity DRAM Research by Uncovering Sense Amplifiers with IC ImagingabstractDRAM vendors do not disclose the architecture of the sense amplifiers deployed in their chips. Unfortunately, this hinders academic research that focuses on studying or improving DRAM. Without knowing the circuit topology, transistor dimensions, and layout of the sense amplifiers, researchers are forced to rely on best guesses, impairing the fidelity of their studies. We aim to fill this gap between academia and industry for the first time by performing Scanning Electron Microscopy (SEM) with Focused Ion Beam (FIB) on recent commodity DDR4 and DDR5 DRAM chips from the three major vendors. This required us to adequately prepare the samples, identify the sensing area, and align images from the different FIB slices. Using the acquired images, we reverse engineer the circuits, measure transistor dimensions and extract physical layouts of sense amplifiers - all previously unavailable to researchers. Our findings show that the commonly assumed classical sense amplifier topology has been replaced with the more sophisticated offset-cancellation design by two of the three major DRAM vendors. Furthermore, the transistor dimensions of sense amplifiers and their revealed physical layouts are significantly different than what is assumed in existing literature. Given commodity DRAM, our analysis shows that the public DRAM models are up to 9 x inaccurate, and existing research has up to $175 x$ error when estimating the impact of the proposed changes. To enable high-fidelity DRAM research in the future, we open source our data, including the reverse engineered circuits and layouts. Michele Marazzi, Tristan Sachsenweger, Flavien Solt, Kubo Takashi, Maksym Yarema, Kaveh Razavi |
ISCA | 3 |
| 2024 | ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms
Patrick Jattke, Max Wipfli, Flavien Solt, Michele Marazzi, Matej Bölcskei, Kaveh Razavi |
USENIX Security Symposium | 3 |
| 2024 | Cascade: CPU Fuzzing via Intricate Program Generation
Flavien Solt, Katharina Ceesay-Seitz, Kaveh Razavi |
USENIX Security Symposium | 1 |
| 2023 | REGA: Scalable Rowhammer Mitigation with Refresh-Generating ActivationsabstractMitigating Rowhammer requires performing additional refresh operations to recharge DRAM rows before bits start to flip. These refreshes are scarce and can only happen periodically, impeding the design of effective mitigations as newer DRAM substrates become more vulnerable to Rowhammer, and more "victim" rows are affected by a single "aggressor" row.We introduce REGA, the first in-DRAM mechanism that can generate extra refresh operations each time a row is activated. Since row activations are the sole cause of Rowhammer, these extra refreshes become available as soon as the DRAM device faces Rowhammer-inducing activations. Refresh operations are traditionally performed using sense amplifiers. Sense amplifiers, however, are also in charge of handling the read and write operations. Consequently, the sense amplifiers cannot be used for refreshing rows during data transfers. To enable refresh operations in parallel to data transfers, REGA uses additional low-overhead buffering sense amplifiers for the sole purpose of data transfers. REGA can then use the original sense amplifiers for parallel refresh operations of other rows during row activations.The refreshes generated by REGA enable the design of simple and scalable in-DRAM mitigations with strong security guarantees. As an example, we build REGAM, the first deterministic in-DRAM mitigation that scales to small Rowhammer thresholds while remaining agnostic to the number of victims per aggressor. REGAMhas a constant 2.1% area overhead, and can protect DDR5 devices with Rowhammer thresholds as small as 261, 517, and 1029 with 23.9%, 11.5%, and 4.7% more power, and 3.7%, 0.8% and 0% performance overhead. Michele Marazzi, Flavien Solt, Patrick Jattke, Kubo Takashi, Kaveh Razavi |
SP | 2 |
| 2022 | RemembERR: Leveraging Microprocessor Errata for Design Testing and ValidationabstractMicroprocessors are constantly increasing in complexity, but to remain competitive, their design and testing cycles must be kept as short as possible. This trend inevitably leads to design errors that eventually make their way into commercial products. Major microprocessor vendors such as Intel and AMD regularly publish and update errata documents describing these errata after their microprocessors are launched. The abundance of errata suggests the presence of significant gaps in the design testing of modern microprocessors. We argue that while a specific erratum provides information about only a single issue, the aggregated information from the body of existing errata can shed light on existing design testing gaps. Unfortunately, errata documents are not systematically structured. We formalize that each erratum describes, in human language, a set of triggers that, when applied in specific contexts, cause certain observations that pertain to a particular bug. We present RemembERR, the first large-scale database of microprocessor errata collected among all Intel Core and AMD microprocessors since 2008, comprising 2,563 individual errata. Each RemembERR entry is annotated with triggers, contexts, and observations, extracted from the original erratum. To generalize these properties, we classify them on multiple levels of abstraction that describe the underlying causes and effects. We then leverage RemembERR to study gaps in design testing by making the key observation that triggers are conjunctive, while observations are disjunctive: to detect a bug, it is necessary to apply all triggers and sufficient to observe only a single deviation. Based on this insight, one can rely on partial information about triggers across the entire corpus to draw consistent conclusions about the best design testing and validation strategies to cover the existing gaps. As a concrete example, our study shows that we need testing tools that exert power level transitions under MSR-determined configurations while operating custom features. Flavien Solt, Patrick Jattke, Kaveh Razavi |
MICRO | 1 |
| 2022 | ProTRR: Principled yet Optimal In-DRAM Target Row RefreshabstractThe DRAM substrate is becoming increasingly more vulnerable to Rowhammer as we move to smaller technology nodes. We introduce ProTRR, the first principled in-DRAM Target Row Refresh mitigation with formal security guarantees and low bounds on overhead. Unlike existing proposals that require changes to the memory controllers, the in-DRAM nature of ProTRR enables its seamless integration. However, this means that ProTRR must respect the synchronous nature of the DRAM protocol, which limits the number of DRAM rows that can be protected at any given time. To overcome this challenge, ProTRR proactively refreshes each row that is most likely to observe bit flips in the future. While this strategy catches the rows that are hammered the most, some others may still fly under the radar. We use this observation to construct Feinting, a new Rowhammer attack that we formally prove to be optimal in this setting. We then conFigure ProTRR to be secure against Feinting. To achieve this, ProTRR should keep track of accesses to each row, which is prohibitively expensive to implement in hardware. Instead, ProTRR uses a new frequent item counting scheme that leverages Feinting to provide a provably optimal yet flexible trade-off between the tolerated DRAM vulnerability, the number of counters, and the number of additional refreshes. Our extensive evaluation using an ASIC implementation of ProTRR and cycle-accurate simulation shows that ProTRR can provide principled protection for current and future DRAM technologies with a negligible performance, power, and area impact. ProTRR is fully compatible with DDR4 and the new Refresh Management (RFM) extension in DDR5. Michele Marazzi, Patrick Jattke, Flavien Solt, Kaveh Razavi |
SP | 3 |
| 2022 | CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTL
Flavien Solt, Ben Gras, Kaveh Razavi |
USENIX Security Symposium | 1 |
| 2020 | Heartbeat-Based Synchronization Scheme for the Human Intranet: Modeling and AnalysisabstractSharing a common clock signal among the nodes is crucial for communication in synchronized networks. This work presents a heartbeat-based synchronization scheme for body-worn nodes. The principles of this coordination technique combined with a puncture-based communication method are introduced. Theoretical models of the hardware blocks are presented, outlining the impact of their specifications on the system. Moreover, we evaluate the synchronization efficiency in simulation and compare with a duty-cycled receiver topology. Improvement in power consumption of at least 26% and tight latency control are highlighted at no cost on the channel availability. Robin Benarrouch, Ali Moin, Flavien Solt, Antoine Frappé, Andreia Cathelin, Andreas Kaiser, Jan M. Rabaey |
ISCAS | 3 |