EDBT 2026 Demo / reviewers in the wild / expert
Adam Caulfield
dblp:322/1174 · also Adam Ilyas Caulfield
· DBLP profile ↗
11ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-5631-7328ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 6 first-author · 8 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RESPEC-CFA: Representation-Aware Speculative Control Flow Attestation
Liam Tyler, Adam Caulfield, Ivan Oliveira Nunes |
ACNS (3) | 2 |
| 2025 | RAP-Track: Efficient Control Flow Attestation via Parallel Tracking in Commodity MCUsabstractControl Flow Attestation (CFA) has emerged as an important security service to enable remote verification of control flow paths in safety-critical embedded systems. However, current CFA for commodity devices suffers performance penalties due to code instrumentation and frequent context switches required to securely log control flow paths at runtime. Our work introduces RAP-Track, a technique leveraging commodity hardware extensions, namely Micro Trace Buffer and Data Watchpoint and Trace Unit, to track control flow paths in parallel with the execution of the attested program, thus avoiding aforementioned overheads present in state-of-the-art CFA. Our evaluation (based on an open-source prototype of RAP-Track) demonstrates substantial performance gains, enhancing practicality and security of CFA. Antonio Joia, Adam Caulfield, Ivan Oliveira Nunes |
DAC | 2 |
| 2025 | SoK: Integrity, Attestation, and Auditing of Program ExecutionabstractThis paper provides a systematic exploration of Control Flow Integrity (CFI) and Control Flow Attestation (CFA) mechanisms, examining their differences and relationships. It addresses crucial questions about the goals, assumptions, features, and design spaces of CFI and CFA, including their potential coexistence on the same platform. Through a comprehensive review of existing defenses, this paper positions CFI and CFA within the broader landscape of runtime defenses, critically evaluating their strengths, limitations, and trade-offs. The findings emphasize the importance of further research to bridge the gaps in CFI and CFA and thus advance the field of runtime defenses. Mahmoud Ammar, Adam Caulfield, Ivan Oliveira Nunes |
SP | 2 |
| 2025 | Run-time Attestation and Auditing: The Verifier's PerspectiveabstractIn run-time attestation schemes, including Control Flow Attestation (CFA) and Data Flow Attestation (DFA), a remote Verifier (Vrf) requests a potentially compromised Prover device (Prv) to generate evidence of its execution control flow path (in CFA) and optionally execution data inputs (in DFA). Recent advances in this space also guarantee that Vrf eventually receives run-time evidence from Prv, even when Prv is fully compromised. Reliable delivery, in theory, enables run-time auditing in addition to attestation, allowing Vrf to examine run-time compromise traces to pinpoint/remediate attack root causes. However, Vrf's perspective in this security service remains unexplored, with most prior work focusing on the secure generation of authentic run-time evidence on Prv. Adam Caulfield, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
WISEC | 1 |
| 2024 | TRACES: TEE-based Runtime Auditing for Commodity Embedded SystemsabstractControl Flow Attestation (CFA) offers a means to detect control flow hijacking attacks on remote devices, enabling verification of their runtime trustworthiness. CFA generates a trace (CFLog) containing the destination of all branching instructions executed. This allows a remote Verifier (Vrf) to inspect the execution control flow on a potentially compromised Prover (Prv) before trusting that a value/action was correctly produced/performed by Prv. However, while CFA can be used to detect runtime compromises, it cannot guarantee the eventual delivery of the execution evidence (CFLog) to Vrf. In turn, a compromised Prv may refuse to send CFLogto Vrf, preventing its analysis to determine the exploit’s root cause and appropriate remediation actions.In this work, we propose TRACES: TEE-based Runtime Auditing for Commodity Embedded Systems. TRACES guarantees reliable delivery of periodic runtime reports even when Prv is compromised. This enables secure runtime auditing in addition to best-effort delivery of evidence in CFA. TRACES also supports a guaranteed remediation phase, triggered upon compromise detection to ensure that identified runtime vulnerabilities can be reliably patched. To the best of our knowledge, TRACES is the first system to provide this functionality on commodity devices (i.e., without requiring custom hardware modifications). To that end, TRACES leverages support from the ARM TrustZone-M Trusted Execution Environment (TEE). To assess practicality, we implement and evaluate a fully functional (open-source) prototype of TRACES atop the commodity ARM Cortex-M33 micro-controller unit. Adam Caulfield, Antonio Joia, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
ACSAC | 1 |
| 2024 | SpecCFA: Enhancing Control Flow Attestation/Auditing via Application-Aware Sub-Path SpeculationabstractAt the edge of modern cyber-physical systems, Micro-Controller Units (MCUs) are responsible for safety-critical sensing/actuation. However, MCU cost constraints rule out the usual security mechanisms of general-purpose computers. Thus, various low-cost security architectures have been proposed to remotely verify MCU software integrity. Control Flow Attestation (CFA) enables a Verifier $(\mathcal{V}{\text{rf}})$ to remotely assess the run-time behavior of a prover MCU $(\mathcal{P}rv)$, generating an authenticated trace of all of $\mathcal{P}{\text{rv}}$ control flow transfers (CFLog). Further, Control Flow Auditing architectures augment CFA by guaranteeing the delivery of evidence to $\mathcal{V}{\text{rf}}$.Unfortunately, a limitation of existing CFA lies in the cost to store and transmit CFLog, as even simple MCU software may generate large traces. Given these issues, prior work has proposed static (context-insensitive) optimizations. However, they do not support configurable program-specific optimizations. In this work, we note that programs may produce unique predictable control flow sub-paths and argue that program-specific predictability can be leveraged to dynamically optimize CFA while retaining all security guarantees. Therefore, we propose SpecCFA: an approach for dynamic sub-path speculation in CFA. SpecCFA allows $\mathcal{V}{\text{rf}}$ to securely speculate on likely control flow sub-paths for each attested program. At run-time, when a sub-path in CFLogmatches a pre-defined speculation, the entire sub-path is replaced by a reserved symbol. SpecCFA can speculate on multiple variable-length control flow sub-paths simultaneously. We implement SpecCFA atop two open-source control flow auditing architectures: one based on a custom hardware design [1] and one based on a commodity Trusted Execution Environment (ARM TrustZone-M) [2]. In both cases, SpecCFA significantly lowers storage/performance costs that are critical to resource-constrained MCUs. Adam Caulfield, Liam Tyler, Ivan Oliveira Nunes |
ACSAC | 1 |
| 2024 | Towards Secure Runtime Auditing of Remote Embedded System SoftwareabstractLow-cost and energy-efficient microcontroller units (MCUs) increasingly perform critical tasks at the edge of modern systems despite their inherent vulnerabilities. To assess their security in remote deployments, Control Flow Attestation (CFA) offers a technique for a Verifier (Vrf) to remotely detect attacks that illegally alter the software or the runtime behavior of a Prover MCU (Prv) by producing a log of all control flow transfers during task execution (CFLog). Current CFA techniques cannot ensure Vrf receives CFLog from a compromised Prv, allowing it to ignore CFA requests and preventing Vrf vulnerability analysis. This dissertation proposal introduces architectures to achieve runtime auditing, guaranteeing the delivery of runtime evidence and enabling Vrf to remediate detected compromises. The first approach uses a hardware-software co-design, and the second approach leverages Trusted Execution Environments (TEEs) to provide the same guarantees without hardware modifications. Future work will focus on further challenges, such as enabling application-specific storage/latency optimizations and automated vulnerability analysis of runtime evidence. Adam Caulfield |
CCS | 1 |
| 2024 | X-Cipher: Achieving Data Resiliency in Homomorphic Ciphertexts
Adam Caulfield, Nabiha Raza, Peizhao Hu |
ICICS (2) | 1 |
| 2023 | $\mathcal{D}\mathsf{iCA}$: A Hardware-Software Co-Design for Differential Check-Pointing in Intermittently Powered DevicesabstractIntermittently powered devices rely on opportunistic energy-harvesting to function, leading to recurrent power interruptions. Therefore, check-pointing techniques are crucial for reliable device operation. Current strategies involve storing snapshots of the device's state at specific intervals or upon events. Time-based check-pointing takes check-points at regular intervals, providing a basic level of fault tolerance. However, frequent check-point generation can lead to excessive/unnecessary energy consumption. Event-based check-pointing, on the other hand, captures the device's state only upon specific trigger events or conditions. While the latter reduces energy usage, accurately detecting trigger events and determining optimal triggers can be challenging. Finally, differential check-pointing selectively stores state changes made since the last check-point, reducing storage and energy requirements for the check-point generation. However, current differential check-pointing strategies rely on software instrumentation, introducing challenges related to the precise tracking of modifications in volatile memory as well as added energy consumption (due to instrumentation overhead). This paper introduces$\mathcal{D}\mathsf{iCA}$, a proposal for a hardware/software co-design to create differential check-points in intermittent devices.$\mathcal{D}\mathsf{iCA}$leverages an affordable hardware module that simplifies the check-pointing process, reducing the check-point generation time and energy consumption. This hardware module continuously monitors volatile memory, efficiently tracking modifications and determining optimal check-point times. To minimize energy waste, the module dynamically estimates the energy required to create and store the check-point based on tracked memory modifications, triggering the check-pointing routine optimally via a non-maskable interrupt. Experimental results show the cost-effectiveness and energy efficiency of$\mathcal{D}\mathsf{iCA}$, enabling extended application activity cycles in intermittently powered embedded devices. Antonio Joia, Adam Caulfield, Chistabelle Alvares, Ivan Oliveira Nunes |
ICCAD | 2 |
| 2023 | ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow Attestation
Adam Caulfield, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
USENIX Security Symposium | 1 |
| 2022 | ASAP: reconciling asynchronous real-time operations and proofs of execution in simple embedded systemsabstractEmbedded devices are increasingly ubiquitous and their importance is hard to overestimate. While they often support safety-critical functions (e.g., in medical devices and sensor-alarm combinations), they are usually implemented under strict cost/energy budgets, using low-end microcontroller units (MCUs) that lack sophisticated security mechanisms. Motivated by this issue, recent work developed architectures capable of generating Proofs of Execution (PoX) for the correct/expected software in potentially compromised low-end MCUs. In practice, this capability can be leveraged to provide "integrity from birth" to sensor data, by binding the sensed results/outputs to an unforgeable cryptographic proof of execution of the expected sensing process. Despite this significant progress, current PoX schemes for low-end MCUs ignore the real-time needs of many applications. In particular, security of current PoX schemes precludes any interrupts during the execution being proved. We argue that lack of asynchronous capabilities (i.e., interrupts within PoX) can obscure PoX usefulness, as several applications require processing real-time and asynchronous events. To bridge this gap, we propose, implement, and evaluate an Architecture for Secure Asynchronous Processing in PoX (ASAP). ASAP is secure under full software compromise, enables asynchronous PoX, and incurs less hardware overhead than prior work. Adam Caulfield, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
DAC | 1 |