EDBT 2026 Demo / reviewers in the wild / expert
Jeferson González-Gómez
dblp:296/1383
· DBLP profile ↗
12ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0002-4200-2632ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 3 first-author · 11 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Federated Learning with Low-Rank Updates under Homomorphic EncryptionabstractFederated Learning has been widely adopted for its ability to collaboratively train models without exposing raw data. However, the server-side aggregation process may still leak sensitive information about client data. Homomorphic Encryption enables privacy-preserving aggregation, but it introduces substantial communication overhead for clients and high computational costs for the server. To address these challenges, we propose HEAL-FL, a federated learning framework that is based on low-rank shared basis vectors across clients. Instead of transmitting full encrypted model updates, clients send only encrypted low-rank coefficients, thereby reducing both communication costs and server-side aggregation overhead. Furthermore, HEAL-FL incorporates a communication-efficient basis update scheme that relies exclusively on homomorphic addition at the server. Our evaluation across various homomorphic encryption schemes shows that HEAL-FL reduces client communication and server aggregation costs, leading to improved efficiency of Federated Learning systems. Notably, these savings translate into up to a significant reduction of 38.6% in total training time compared to conventional homomorphic FedAvg with full model parameter transmission, demonstrating the practical benefits of our approach. Mohamed Aboelenien Ahmed, Mohamed Alsharkawy, Hassan Nassar, Heba Khdr, Jeferson González-Gómez, Jörg Henkel |
DATE | 5 |
| 2026 | TrustSeed: Lightweight Attestation Protocol for Ensuring LLM IntegrityabstractOver the last couple of years, large language models have increasingly been integrated into many computing applications. For privacy preservation, they are now deployed on edge devices. However, these deployments are vulnerable to bit flip attacks and backdoor attacks that compromise the integrity of the model. Traditional remote attestation techniques fail to detect such manipulations due to the large model size and the stealthiness of the attacks.In this paper, we present TrustSeed, a lightweight functional attestation protocol that uses a single inference to ensure large language models’ integrity. TrustSeed verifies integrity by applying deterministic, seed-based modifications to model weights within a Trusted Execution Environment and comparing the last intermediate activations and output distribution against a golden reference on the verifier. This approach prevents precomputed or forged responses, ensuring freshness and unpredictability in each attestation round. Our analysis shows that output distribution and last intermediate activations are effective indicators of integrity. We test TrustSeed against bit-flip, data poisoning, and weight poisoning attacks, reliably detecting even single-bit alterations. Extensive evaluations on edge platforms and an HPC system demonstrate minimal overhead and up to 127× faster attestation compared to state-of-the-art full-model hashing. Mohamed Alsharkawy, Mohamed Aboelenien Ahmed, Hassan Nassar, Jeferson González-Gómez, Heba Khdr, Osama Abboud, Xun Xiao, Jörg Henkel |
DATE | 4 |
| 2026 | ARDiS: A Portable and Unified Resource Management Framework in Real Hardware SystemsabstractDesigning efficient RM strategies is a cornerstone of modern computing, driving innovations in performance optimization, energy efficiency, and security. While simulators have long been the go-to tools for RM research, they fail to balance accuracy and practicality: high-fidelity simulators are excruciatingly slow, and low-fidelity ones compromise on reliability. Real hardware offers unparalleled precision and accuracy but remains underutilized due to significant barriers, including fragmented implementations, lack of portability, and prohibitive development overhead. We present ARDiS, the first open-source 1 and portable framework to provide a unified, architecture-agnostic platform for running system-level resource management (RM) techniques directly on real hardware. ARDiS eliminates the need to “reinvent the wheel,” enabling researchers to design, implement, and evaluate sophisticated RM strategies—including machine learning-based approaches—with minimal effort and maximum reproducibility. To demonstrate its versatility, we evaluate ARDiS on two real-world hardware platforms: a server-grade heterogeneous processor (Intel i9-12900) and a resource-constrained embedded system (NVIDIA Jetson TX2). Through extensive experimentation, we validate the ability of ARDiS to deliver accurate, scalable, and reproducible results across diverse platforms and application domains. By lowering the barriers to hardware-based RM research, ARDiS empowers the design automation community to explore new frontiers in system-level optimization and innovation. Mohammed Bakr Sikal, Jeferson González-Gómez, Andreas Noebel, Heba Khdr, Jörg Henkel |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2025 | Through Fabric: A Cross-world Thermal Covert Channel on TEE-enhanced FPGA-MPSoC SystemsabstractThe ever-evolving computing landscape gets more complex in every moment and the need for heterogeneous compute systems becomes more relevant. As the usability of such systems grew, finding methods for securing them became more relevant. Commercial vendors already introduced Trusted Execution Environments (TEEs) for those systems. TEEs serve the need for isolation, where sensitive data are processed in a secure world, and non-trusted applications are executed in the normal world. In this paper, we introduce Through Fabric: a novel attack against TEE-enhanced FPGA-MPSoCs. We show that existing benign hardware accelerators can be manipulated from the secure world to implement a temperature-based covert channel. We successfully run this attack on a commercial FPGA-MPSoC within the OP-TEE environment without additional access rights. We use an open-source implementation of AES for the accelerator and we reach a transmission speed of 2 bits per second with bit error rate of 1.9% and packet error rate of 4.3%. We are the first to show that a TEE can be bypassed on FPGA-MPSoCs via temperature-based covert channel communication. Hassan Nassar, Jeferson González-Gómez, Varun Manjunath, Lars Bauer, Jörg Henkel |
ASP-DAC | 2 |
| 2025 | Late Breaking Results: Decentralized Voting-Based Attestation for IoT DevicesabstractRemote Attestation (RA) has become a valuable security service for Internet of Things (IoT) devices, as the security of these devices is often not prioritized during the manufacturing process. However, traditional RA schemes suffer from a single point of failure because they rely on a trusted verifier. To address this issue, we propose a voting-based blockchain attestation protocol that provides a reliable solution by eliminating the single point of failure through distributed verification across all nodes. In addition, it offers a traceable and immutable public history of the attestation results, which can be verified by external auditors at any time. Finally, we verify our proposed protocol on three NVIDIA Jetson embedded devices hosting up to 15 attestation nodes. Mohamed Alsharkawy, Eren Sönmez, Jeferson González-Gómez, Hassan Nassar, Jörg Henkel |
DAC | 3 |
| 2025 | Late Breaking Results: The Hidden Risks of Activation Duration in PLPUFsabstractThe security of Internet of Things (IoT) devices is crucial to protect the vast amounts of data exposed due to their widespread adoption. Authentication is one of the key aspects of IoT security, but it becomes increasingly challenging, especially for resource-constrained devices that require lightweight and efficient solutions. Physical Unclonable Functions (PUFs) have emerged as a promising lightweight solution by using the unique physical properties of Integrated Circuits (ICs). Pseudo Liner Feedback Shift Register PUF (PLPUF) is one of the state-of-the-art implementations known for its flexibility in altering the challenge-response space by changing the activation duration. In this work, we demonstrate that selecting an appropriate activation duration for PLPUF is critical, as improper choices can compromise security. By analyzing the linear dependency between the responses of different PLPUF pairs, our results reveal that predictability can reach up to $96 \%$ when an unsuitable activation duration is chosen. Mohamed Alsharkawy, Jan Zwerschke, Hassan Nassar, Jeferson González-Gómez, Jörg Henkel |
DAC | 4 |
| 2025 | Contention-Aware Forecasting of Energy Efficiency through Sequence-Based Models in Modern Heterogeneous ProcessorsabstractWe present EffiCast, the first methodology for contentionaware energy efficiency forecasting in clustered heterogeneous processors using sequence-based models. Through extensive experimental analysis of energy efficiency sensitivities across core types, voltage/frequency (V/f) levels, application phases, and resource contention scenarios, EffiCast uncovers key factors driving energy efficiency variability in modern heterogeneous processors. Leveraging structured data generation and advanced LSTM- and Transformer-based models, EffiCast achieves unprecedented accuracy while outperforming state-of-the-art predictive techniques. Deployed on a real heterogenous processor with Intel’s oneDNN acceleration, EffiCast delivers inference latencies as low as 1.82 ms per sequence, enabling seamless integration into proactive resource management frameworks. With the ability to forecast future system states under dynamic workloads, EffiCast sets a new standard for energy efficiency optimization in energy-constrained application domains. Mohammed Bakr Sikal, Jeferson González-Gómez, Heba Khdr, Jörg Henkel |
DAC | 2 |
| 2025 | DPReF: Decentralized Key Generation Using Physical-Related FunctionsabstractPhysical Unclonable Functions (PUFs) serve as a lightweight source to generate cryptographic keys utilizing the inherent physical device properties, making them particularly suitable for resource-constrained environments such as Internet of Things (IoT) devices. Recently, Physical-Related Functions (PReFs) extended PUFs to enable multiple devices to generate similar keys without the need to exchange or store them, improving security. However, state-of-the-art PReF implementations rely on a Trusted Third Party (TTP) to identify relative challenges, introducing a potential vulnerability if the TTP is compromised. In this work, we propose the first decentralized PReF protocol, removing reliance on the TTP and mitigating associated security risks. The proposed protocol allows relative challenges to be identified directly between devices in a decentralized manner. Additionally, we formalize a mathematical model to estimate the minimum number of devices required to build a network, based on the sizes of the PUF and the shared Challenge-Response Pair (CRP).. We demonstrate the generality of our model by verifying it across different types of state-of-the-art PUFs (Arbiter-based Non-Volatile Memory PUF (ANV-PUF) and Pseudo Linear Feedback Shift Register PUF (PLPUF).). We establish a 128 bit cryptographic key using the proposed protocol that matches the state-of-the-art but in a decentralized manner. Moreover, we prove that our protocol can be used to construct hardware-assisted attestation networks using ANV-PUF and PLPUF implementations with a shared secret of 16 bit that allows for both integrity and identity verification. Mohamed Alsharkawy, Hassan Nassar, Jeferson González-Gómez, Xun Xiao, Osama Abboud, Jörg Henkel |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2024 | Balancing Security and Efficiency: System-Informed Mitigation of Power-Based Covert ChannelsabstractAs the digital landscape continues to evolve, the security of computing systems has become a critical concern. Power-based covert channels (e.g., thermal covert channel s (TCCs)), a form of communication that exploits the system resources to transmit information in a hidden or unintended manner, have been recently studied as an effective mechanism to leak information between malicious entities via the modulation of CPU power. To this end, dynamic voltage and frequency scaling (DVFS) has been widely used as a countermeasure to mitigate TCCs by directly affecting the communication between the actors. Although this technique has proven effective in neutralizing such attacks, it introduces significant performance and energy penalties, that are particularly detrimental to energy-constrained embedded systems. In this article, we propose different system-informed countermeasures to power-based covert channels from the heuristic and machine learning (ML) domains. Our proposed techniques leverage task migration and DVFS to jointly mitigate the channels and maximize energy efficiency. Our extensive experimental evaluation on two commercial platforms: 1) the NVIDIA Jetson TX2 and 2) Jetson Orin shows that our approach significantly improves the overall energy efficiency of the system compared to the state-of-the-art solution while nullifying the attack at all times. Jeferson González-Gómez, Mohammed Bakr Sikal, Heba Khdr, Lars Bauer, Jörg Henkel |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2023 | Smart Detection of Obfuscated Thermal Covert Channel Attacks in Many-core ProcessorsabstractIn thermal covert channel (TCC) attacks, malicious applications seek to leak private information in a stealthy and hard-to-detect manner. State-of-the-art approaches for TCC detection employ the Discrete Fourier Transform (DFT) combined with heuristics to identify possible channels. However, as we demonstrate in this paper, these approaches are limited when detecting short-duration attacks, where an attacker intentionally halts the transmission for a time interval to avoid the detection. In order to overcome this limitation of the state-of-the-art solutions, we propose the first detection method for short-duration TCC attacks. Our solution, Dotecca, is a machine learning-based technique that employs short windows of time-domain measurements instead of the DFT to detect TCCs. To evaluate our solution, we introduce a new obfuscated short-duration attack that disguises as a regular application from the perspective of a DFT spectrum. Our experiments show that the new obfuscated attack is able to remain undetected even under advanced DFT-based state-of-the-art detection approaches, reducing their detection accuracy to about 18 %. In contrast, our smart detection approach is able to detect state-of-the-art and new obfuscated attacks with an accuracy of 99 %. Moreover, our solution reduces the overhead of the DFT-based state-of-the-art solution by more than 14 ×. Jeferson González-Gómez, Mohammed Bakr Sikal, Heba Khdr, Lars Bauer, Jörg Henkel |
DAC | 1 |
| 2023 | The First Concept and Real-world Deployment of a GPU-based Thermal Covert Channel: Attack and CountermeasuresabstractThermal covert channel (TCC) attacks have been studied as a threat to CPU-based systems over recent years. In this paper, we propose a new type of TCC attack that for the first time leverages the Graphics Processing Unit (GPU) of a system to create a stealthy communication channel between two malicious applications. We evaluate our new attack on two different real-world platforms: a GPU-dedicated general computing platform and a GPU-integrated embedded platform. Our results are the first to show that a GPU-based thermal covert channel attack is possible. From our experiments, we obtain a transmission rate of up to 8.75 bps with a very low error rate of less than 2 % for a 12-bit packet size, which is comparable to CPU-based TCCs in the state of the art. Moreover, we show how existing state-of-the-art countermeasures for TCCs need to be extended to tackle the new GPU-based attack at the cost of added overhead. To reduce this overhead, we propose our own DVFS-based countermeasure which mitigates the attack, while causing$2\times$less performance loss than the state-of-the-art countermeasure on a set of compute-intensive GPU benchmark applications. Jeferson González-Gómez, Kevin Cordero-Zuñiga, Lars Bauer, Jörg Henkel |
DATE | 1 |
| 2023 | Cache-Based Side-Channel Attack Mitigation for Many-Core Distributed Systems via Dynamic Task MigrationabstractSide-channel attacks (SCA) are a serious threat to cryptographic systems due to mostly unavoidable information leakage. Cache-based SCAs take advantage of cache inherent timing properties on shared memory systems to extract security-critical information. In this paper, we present a novel approach to mitigate cache-based SCAs on distributed many-core systems, based on a resource management technique. Our solution leverages dynamic task migration as a mechanism to ensure a secure execution scenario for security-critical applications. Additionally, we propose a resource-management-based mechanism to ensure a secure execution when migration is not possible due to a lack of available resources. We evaluate our solution in terms of gained security and performance impact using the Sniper simulator for different configurations. Results show that our technique effectively develops resilience against SCAs, while causing a low performance slowdown (1.6% on average, 9% worst case). For all tested benchmarks, our worst-case performance slowdown is 20% less than a state-of-the-art countermeasure. Moreover, our solution utilizes less than 1 ms of system run-time overhead for a 64 core platform with 100% utilization. Jeferson González-Gómez, Lars Bauer, Jörg Henkel |
IEEE Trans. Inf. Forensics Secur. | 1 |