EDBT 2026 Demo / reviewers in the wild / expert
Tristan Hornetz
dblp:408/0622
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
0009-0007-2295-7814ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software Emulation
Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001 |
SP | 1 |
| 2026 | TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads
Tristan Hornetz, Hosein Yavarzadeh, Albert Cheu, Adrià Gascón, Lukas Gerlach 0001, Daniel Moghimi, Phillipp Schoppmann, Michael Schwarz 0001, Ruiyi Zhang 0001 |
SP | 1 |
| 2025 | Taming the Linux Memory Allocator for Rapid Prototyping
Ruiyi Zhang 0001, Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001 |
DIMVA (2) | 2 |
| 2025 | Lixom: Protecting Encryption Keys with Execute-Only Memory
Tristan Hornetz, Lukas Gerlach 0001, Michael Schwarz 0001 |
FC | 1 |
| 2025 | Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address LeakageabstractMicroarchitectural attacks are a growing threat to modern computing systems. CPU caches are an essential but complex element in many microarchitectural attacks, making it crucial to understand the inner workings. Despite progress in reverse-engineering techniques, non-linear cache-slice functions remain challenging to analyze, especially in recent Intel hybrid microarchitectures. In this paper, we introduce a novel approach towards reverse-engineering complex, non-linear cache-slice functions, particularly on modern Intel CPUs with hybrid microarchi-tectures. Our method significantly advances prior work by understanding the specific structure of microarchitectural hash functions, reducing the time required for reverse-engineering from days to minutes. In contrast to prior work, our technique successfully handles systems with 512 GB of memory and diverse slice configurations. We present 13 newly identified functions used for cache-slice addressing and extend existing functions to support systems with more DRAM for multiple CPU generations. Additionally, we introduce an unprivileged virtual-to-physical address oracle that is a direct consequence of the complexity of the non-linear slice functions. Our method is particularly effective on modern Intel hybrid CPUs, in-cluding Alder Lake and Meteor Lake, where previously used methods for measuring slices or leaking physical addresses are unavailable. In 3 case studies, we validate our approach, demonstrating its effectiveness in executing targeted Spectre attacks on non-attacker-mapped memory, enabling DRAMA attacks, and creating cache eviction sets. Our findings em-phasize the increased attack surface introduced by complex cache-slice functions in modern CPU s. Mikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz, Leon Trampert, Lukas Gerlach 0001, Michael Schwarz 0001 |
SP | 4 |