EDBT 2026 Demo / reviewers in the wild / expert
Yossef Oren
dblp:69/39 · also Yossi Oren
· DBLP profile ↗
32ranked-venue papers
10as first author
15since 2021 · last 2026
0000-0002-0423-802XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 9 first-author · 11 since 2021Computer networks · 4 · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Leaky Apps: Targeted Deanonymization on Mobile PhonesabstractTargeted Deanonymization attacks allow an attacker who controls a website to infer the identity of specific target users browsing that website. They are a severe privacy risk, as they can then be used to carry out highly-targeted attacks against the inferred identities. Robert Blacha, Yossef Oren, Reza Curtmola |
CODASPY | 2 |
| 2026 | Understanding and addressing concept drift in website fingerprintingabstractWebsite fingerprinting attacks let attackers determine which websites a user visits, posing a significant risk to online privacy. Website fingerprinting attacks have been demonstrated both in the network-based setting, where the adversary is able to observe the network traffic between the user and the secure network, and in the cache-based setting, where the adversary injects malicious JavaScript code into the user’s browser and observes memory activity. In both of these settings, previous research has demonstrated that state-of-the-art website fingerprinting attacks can succeed even in highly-constrained environments, for example when attacking the privacy-enhanced Tor browser. One known limitation of website fingerprinting attacks, however, is their sensitivity to concept drift — as the time difference between the training period and the actual attack grows, the accuracy of the model used in the fingerprinting attack degrades due to changes in webpage content, network conditions, and the software implementation of the browser. This phenomenon is a known challenge in website fingerprinting. This study provides a quantitative analysis of the effect on website fingerprinting attacks of concept drift in both the network-based and cache-based settings, based on a website fingerprinting trace dataset collected over a period of several months. It examines the effect on accuracy of changes both to the browser version and to the website content. It then investigates multiple approaches for addressing concept drift, assuming the attacker can add a limited amount of fresh data to his training dataset. Our evaluation shows that using advanced machine learning techniques can significantly reduce the effect of concept drift on website fingerprinting attacks, and that, specifically, an incremental learning approach nearly maintains the model’s accuracy over time, while requiring only 2 % of the data needed for full retraining. This finding demonstrates the practicality of long-term website fingerprinting attacks in the real world. Anatoly Shusterman, Roie David, Yossef Oren |
Comput. Networks | 3 |
| 2025 | Contention-Based Side Channels Enable Faster and Stealthier Browsing History SniffingabstractWeb browsers are implicitly trusted to handle a large amount of private user information. One such piece of private information, a user's browsing history, is maintained by browsers and is used to provide a popular usability feature: Web links are rendered using different styles depending on whether the URLs they point to have been visited or not. Unfortunately, this feature can be abused by malicious webpages in order to extract users’ browsing history. We present new browsing history sniffing attacks through two contention-based side channels which are new in this context: Last-level CPU cache contention, and GPU execution unit contention. The attacks are robust and can be executed successfully against the popular Chrome browser. Compared to prior work which uses the rendering performance as a side channel, our work achieves an attack rate increase of up to 30x. The new attacks are stealthier, because the side channels we use do not slow down the browser's rendering rate. In addition, we revisit the existing sniffing attacks based on the rendering performance side channel, and show how their attack rate can also be increased by a significant amount. Finally, we discuss the root cause of history sniffing attacks and point out solutions. Mojtaba Zaheri, Yossef Oren, Reza Curtmola |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Two's Complement: Monitoring Software Control Flow Using Both Power and Electromagnetic Side ChannelsabstractEmbedded devices leak information about their inner activity through power and EM side channels. A defender who measures this leakage can thus use it to monitor the device and ensure its control-flow integrity. Previous works have investigated the use of power and EM side channels for control-flow monitoring, but they have only used a single side channel at a time. In this paper, we propose an approach that integrates both power and EM side channels to detect deviations from the device's normal behavior. Our model takes inspiration from multimodal machine learning used in image and speech recognition, and uses an intermediate integration design which passes multiple input modalities in parallel through a single self-attention transformer network. We evaluate our model on an off-the-shelf device at multiple noise levels, and show that it outperforms models that use only a single channel as input. In particular, we show how the multimodal approach can improve trace classification and anomaly detection accuracies by up to 18% and 11 %, respectively, compared to power/EM-only approaches. Additionally, we show that our approach is superior over the early and late integration approaches currently used in multimodal side channel analysis work. We release our machine-learning architecture, including trained models based on real-world data, as an open-source repository. Our work highlights how advances in the wider field of machine learning can be used to improve the security of embedded systems. Michael Amar, Lojenaa Navanesan, Asanka P. Sayakkara, Yossef Oren |
DSD | 4 |
| 2024 | Pixel Thief: Exploiting SVG Filter Leakage in Firefox and Chrome
Sioli O'Connell, Lishay Aben Sour, Ron Magen, Daniel Genkin, Yossef Oren, Hovav Shacham, Yuval Yarom |
USENIX Security Symposium | 5 |
| 2023 | The Finger in the Power: How to Fingerprint PCs by Monitoring Their Power Consumption
Marina Botvinnik, Tomer Laor, Thomas Rokicki, Clémentine Maurice, Yossef Oren |
DIMVA | 5 |
| 2023 | Characterization and Detection of Cross-Router Covert ChannelsabstractIn covert channel attacks, an adversary seeks various means to influence a tangible characteristic of a system, and then makes the systems leak information by measuring this characteristic. Covert channels are, by nature, very elusive. This makes it very difficult to identify them and defend against attacks that use these channels to leak sensitive information . Thus, they are a serious threat to the security of many systems. In this paper, we present two network timing covert channel attacks, and a defense mechanism against them. The purpose of the proposed attacks is to leak sensitive information between two logically separated (or isolated) networks that are hosted by a single router – one that is connected to the Internet, and another that is isolated and contains sensitive information. The attacks build on the fact that the response time of the router for a specific type of packet sent from a device that is connected to it is usually predictable, given the network topology . By interacting with the single shared router in a specific manner, an attacker can increase the router’s packet response time. The interaction is determined based on the information to be leaked, so the receiver (a computer located on the Internet-connected network) can measure the delayed packet response times and decode the sender’s signals (which operates from the isolated network) to receive classified information. The two classes of attacks presented in this work differ in the way that the delay is caused. In the cross-router covert channel (CRCC) attack, the sender overloads the router with control-plane packets; in the Wi-Fi micro-jamming attack, the sender uses a pre-installed implant to transmit single-tone signals in the 2.4GHz frequency range, disturbing the router’s packet transmissions . We showed that both attacks can influence a wide range of router brands and Wi-Fi capable devices and evaluated the optimal settings for both attacks when using different types of packets, transmission power, and data transmission rates. Our proposed defense mechanism is based on semi-supervised machine learning and deep learning algorithms , which are both used for novelty detection in network traffic. By detecting unusual traffic, we can identify the disturbances needed to leak the information. The system can then respond by blocking the suspicious devices that are involved in the attack. We evaluated the attacks in noisy and noise-free environments, successfully detecting both attacks in both environments. All the data and code, which includes the implementation of the attacks and the defense mechanism, is published as a benefit to the research community. Oren Shvartzman, Adar Ovadya, Kfir Zvi, Omer Shwartz, Rom Ogen, Yakov Mallah, Niv Gilboa, Yossef Oren |
Comput. Secur. | 8 |
| 2023 | Juliet-PUF: Enhancing the Security of IoT-Based SRAM-PUFs Using the Remanence Decay EffectabstractThe cloud-based Internet of Things (IoT) enables the creation of innovative computer applications based on sensing, analyzing, and controlling the physical world. IoT deployments, however, are at a particular risk of counterfeiting, through which an adversary can corrupt the entire ecosystem. Therefore, entity authentication of edge devices is considered an essential part of the security of IoT systems. This research addresses the challenge of generating a unique ID in IoT devices. Unique IDs allow the IoT system maker to identify each edge device, and to ensure that only genuine devices can upload data to the cloud. Traditional ID mechanisms are not feasible in IoT, due to the edge device’s constrained runtime environment, or the additional costs and the deployment difficulties that they introduce. In this work, we present JULIET-PUF, a novel PUF-based method for IoT identification, which relies on SRAM content retrieval after power glitches with time differences. Our scheme comes with no added hardware cost on the edge device. We evaluate JULIET-PUF using a data set of 24 units of a popular commercial IoT device, and show that it is on average 95.58 times more secure than the common use of SRAM-PUF. Amit Kama, Michael Amar, Snir Gaaton, Kang Wang 0015, Yifan Tu, Yossef Oren |
IEEE Internet Things J. | 6 |
| 2022 | Port Contention Goes Portable: Port Contention Side Channels in Web BrowsersabstractMicroarchitectural side-channel attacks can derive secrets from the execution of vulnerable programs. Their implementation in web browsers represents a considerable extension of their attack surface, as a user simply browsing a malicious website, or even a malicious third-party advertisement in a benign cross-origin isolated website, can be a victim. Thomas Rokicki, Clémentine Maurice, Marina Botvinnik, Yossef Oren |
AsiaCCS | 4 |
| 2022 | HammerScope: Observing DRAM Power Consumption Using RowhammerabstractThe constant reduction in memory cell sizes has increased memory density and reduced power consumption, but has also affected its reliability. The Rowhammer attack exploits this reduced reliability to induce bit flips in memory, without directly accessing these bits. Most Rowhammer attacks target software integrity, but some recent attacks demonstrated its use for compromising confidentiality. Yaakov Cohen, Kevin Sam Tharayil, Arie Haenel, Daniel Genkin, Angelos D. Keromytis, Yossef Oren, Yuval Yarom |
CCS | 6 |
| 2022 | DRAWN APART: A Device Identification Technique based on Remote GPU Fingerprinting
Tomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk, Pierre Laperdrix, Clémentine Maurice, Yossef Oren, Romain Rouvoy, Walter Rudametkin, Yuval Yarom |
NDSS | 7 |
| 2022 | Targeted Deanonymization via the Cache Side Channel: Attacks and Defenses
Mojtaba Zaheri, Yossef Oren, Reza Curtmola |
USENIX Security Symposium | 2 |
| 2021 | Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses
Anatoly Shusterman, Ayush Agarwal, Sioli O'Connell, Daniel Genkin, Yossef Oren, Yuval Yarom |
USENIX Security Symposium | 5 |
| 2021 | Cache-based characterization: A low-infrastructure, distributed alternative to network-based traffic and application characterization
Anatoly Shusterman, Chen Finkelstein, Ofir Gruner, Yarin Shani, Yossef Oren |
Comput. Networks | 5 |
| 2021 | Website Fingerprinting Through the Cache Occupancy Channel and its Real World PracticalityabstractWebsite fingerprinting attacks use statistical analysis on network traffic to compromise user privacy. The classical attack model used to evaluate website fingerprinting attacks assumes an on-path adversary, who observes traffic traveling between the user's computer and the network. In this article we investigate a different attack model, in which the adversary sends JavaScript code to the target user's computer. This code mounts a cache side-channel attack to identify other websites being browsed. Using machine learning techniques to classify traces of cache activity, we achieve high classification accuracy in both the open-world and the closed-world models. Our attack is more resistant than network-based fingerprinting to the effects of response caching, and resilient both to network-based defenses and to side-channel countermeasures. We carry out a real-world evaluation of several aspects of our attack, exploring the impact of the changes in websites and browsers over time, as well as of the attacker's ability to guess the software and hardware configuration of the target user's computer. To protect against cache-based website fingerprinting, new defense mechanisms must be introduced to privacy-sensitive browsers and websites. We investigate one such mechanism, and show that it reduces the effectiveness of the attack and completely eliminates it when used in the Tor Browser. Anatoly Shusterman, Zohar Avraham, Eliezer Croitoru, Yarden Haskal, Lachlan Kang, Dvir Levi, Yosef Meltser, Prateek Mittal, Yossef Oren, Yuval Yarom |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2020 | Inner conflict: How smart device components can cause harm
Omer Shwartz, Amir Cohen, Asaf Shabtai, Yossef Oren |
Comput. Secur. | 4 |
| 2020 | Sensor Defense In-Software (SDI): Practical software based detection of spoofing attacks on position sensors
Kevin Sam Tharayil, Benyamin Farshteindiker, Shaked Eyal, Nir Hasidim, Roy Hershkovitz, Shani Houri, Ilia Yoffe, Michal Oren, Yossef Oren |
Eng. Appl. Artif. Intell. | 9 |
| 2019 | Robust Website Fingerprinting Through the Cache Occupancy Channel
Anatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser, Prateek Mittal, Yossef Oren, Yuval Yarom |
USENIX Security Symposium | 6 |
| 2018 | Reverse Engineering IoT Devices: Effective Techniques and MethodsabstractRecent Internet of Things (IoT) botnet attacks have called the attention to the fact that there are many vulnerable IoT devices connected to the Internet today. Some of these Web-connected devices lack even basic security practices such as strong password authentication. As a consequence, many IoT devices are already infected with malware and many more are vulnerable to exploitation. In this paper we analyze the security level of 16 popular IoT devices. We evaluate several low-cost black-box techniques for reverse engineering these devices, including software and fault injection-based techniques used to bypass password protection. We use these techniques to recover device firmware and passwords. We also discover several common design flaws which lead to previously unknown vulnerabilities. We demonstrate the effectiveness of our approach by modifying a laboratory version of the Mirai botnet to automatically add these devices to a botnet. We also discuss how to improve the security of IoT devices without significantly increasing their cost or affecting their usability. Omer Shwartz, Yael Mathov, Michael Bohadana, Yuval Elovici, Yossef Oren |
IEEE Internet Things J. | 5 |
| 2017 | Opening Pandora's Box: Effective Techniques for Reverse Engineering IoT Devices
Omer Shwartz, Yael Mathov, Michael Bohadana, Yuval Elovici, Yossef Oren |
CARDIS | 5 |
| 2016 | ANVIL: Software-Based Protection Against Next-Generation Rowhammer AttacksabstractEnsuring the integrity and security of the memory system is critical. Recent studies have shown serious security concerns due to "rowhammer" attacks, where repeated accesses to a row of memory cause bit flips in adjacent rows. Recent work by Google's Project Zero has shown how to leverage rowhammer-induced bit-flips as the basis for security exploits that include malicious code injection and memory privilege escalation. Being an important security concern, industry has attempted to defend against rowhammer attacks. Deployed defenses employ two strategies: (1) doubling the system DRAM refresh rate and (2) restricting access to the CLFLUSH instruction that attackers use to bypass the cache to increase memory access frequency (i.e., the rate of rowhammering). We demonstrate that such defenses are inadequte: we implement rowhammer attacks that both avoid using the CLFLUSH instruction and cause bit flips with a doubled refresh rate. Our next-generation CLFLUSH-free rowhammer attack bypasses the cache by manipulating cache replacement state to allow frequent misses out of the last-level cache to DRAM rows of our choosing. Zelalem Birhanu Aweke, Salessawi Ferede Yitbarek, Rui Qiao 0002, Reetuparna Das, Matthew Hicks, Yossef Oren, Todd M. Austin |
ASPLOS | 6 |
| 2016 | Remanence Decay Side-Channel: The PUF CaseabstractWe present a side-channel attack based on remanence decay in volatile memory and show how it can be exploited effectively to launch a noninvasive cloning attack against SRAM physically unclonable functions (PUFs) - an important class of PUFs typically proposed as lightweight security primitives, which use existing memory on the underlying device. We validate our approach using SRAM PUFs instantiated on two 65-nm CMOS devices. We discuss countermeasures against our attack and propose the constructive use of remanence decay to improve the cloning resistance of SRAM PUFs. Moreover, as a further contribution of independent interest, we show how to use our evaluation results to significantly improve the performance of the recently proposed TARDIS scheme, which is based on remanence decay in SRAM memory and used as a time-keeping mechanism for low-power clockless devices. Shaza Zeitouni, Yossef Oren, Christian Wachsmann, Patrick Koeberl, Ahmad-Reza Sadeghi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | The Spy in the Sandbox: Practical Cache Attacks in JavaScript and their ImplicationsabstractWe present a micro-architectural side-channel attack that runs entirely in the browser. In contrast to previous work in this genre, our attack does not require the attacker to install software on the victim's machine; to facilitate the attack, the victim needs only to browse to an untrusted webpage that contains attacker-controlled content. This makes our attack model highly scalable, and extremely relevant and practical to today's Web, as most desktop browsers currently used to access the Internet are affected by such side channel threats. Our attack, which is an extension to the last-level cache attacks of Liu et al., allows a remote adversary to recover information belonging to other processes, users, and even virtual machines running on the same physical host with the victim web browser. We describe the fundamentals behind our attack, and evaluate its performance characteristics. In addition, we show how it can be used to compromise user privacy in a common setting, letting an attacker spy after a victim that uses private browsing. Defending against this side channel is possible, but the required countermeasures can exact an impractical cost on benign uses of the browser. Yossef Oren, Vasileios P. Kemerlis, Simha Sethumadhavan, Angelos D. Keromytis |
CCS | 1 |
| 2015 | Attacking the Internet Using Broadcast Digital TelevisionabstractIn the attempt to bring modern broadband Internet features to traditional broadcast television, the Digital Video Broadcasting (DVB) consortium introduced a specification called Hybrid Broadcast-Broadband Television (HbbTV), which allows broadcast streams to include embedded HTML content that is rendered by the television. This system is already in very wide deployment in Europe and has recently been adopted as part of the American digital television standard. Our analyses of the specifications, and of real systems implementing them, show that the broadband and broadcast systems are combined insecurely. This enables a large-scale exploitation technique with a localized geographical footprint based on Radio Frequency (RF) injection, which requires a minimal budget and infrastructure and is remarkably difficult to detect. In this article, we present the attack methodology and a number of follow-on exploitation techniques that provide significant flexibility to attackers. Furthermore, we demonstrate that the technical complexity and required budget are low, making this attack practical and realistic, especially in areas with high population density: In a dense urban area, an attacker with a budget of about 450 can target more than 20,000 devices in a single attack. A unique aspect of this attack is that, in contrast to most Internet of Things/Cyber-Physical System threat scenarios, where the attack comes from the data network side and affects the physical world, our attack uses the physical broadcast network to attack the data network. Yossef Oren, Angelos D. Keromytis |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2014 | A New Framework for Constraint-Based Probabilistic Template Side Channel Attacks
Yossef Oren, Ofir Weisse, Avishai Wool |
CHES | 1 |
| 2014 | From the Aether to the Ethernet - Attacking the Internet using Broadcast Digital Television
Yossef Oren, Angelos D. Keromytis |
USENIX Security Symposium | 1 |
| 2013 | On the Effectiveness of the Remanence Decay Side-Channel to Clone Memory-Based PUFs
Yossef Oren, Ahmad-Reza Sadeghi, Christian Wachsmann |
CHES | 1 |
| 2013 | Range Extension Attacks on Contactless Smart Cards
Yossef Oren, Dvir Schirman, Avishai Wool |
ESORICS | 1 |
| 2012 | Algebraic Side-Channel Attacks Beyond the Hamming Weight Leakage Model
Yossef Oren, Mathieu Renauld, François-Xavier Standaert, Avishai Wool |
CHES | 1 |
| 2010 | Algebraic Side-Channel Analysis in the Presence of Errors
Yossef Oren, Mario Kirschbaum, Thomas Popp, Avishai Wool |
CHES | 1 |
| 2009 | A low-resource public-key identification scheme for RFID tags and sensor nodesabstractWe revisit a public key scheme presented by Shamir in [19] (and simultaneously by Naccache in [15]) and examine its applicability for general-purpose RFID tags in the supply chain. Using a combination of new and established space-saving methods, we present a full-fledged public key identification scheme, which is secure yet highly efficient. The 1024-bit scheme fits completely (including RAM) into 4682 gate equivalents and has a mean current consumption of 14.2μA. The main novelty in our implementation is the replacement of the long pseudo-random sequence, originally stored on 260 bytes of EEPROM in [19], by a reversible stream cipher using less than 300 bits of RAM. We show how our scheme offers tag-to-reader and reader-to-tag authentication and how it can be fit into the existing RFID supply chain infrastructure. Yossef Oren, Martin Feldhofer |
WISEC | 1 |
| 2007 | Remote Password Extraction from RFID TagsabstractSide-channel attacks are used by cryptanalysts to compromise the implementation of secure systems. One very powerful class of side-channel attacks is power analysis, which tries to extract cryptographic keys and passwords by examining the power consumption of a device. We examine the applicability of this threat to electromagnetically coupled RFID tags. Compared to standard power analysis attacks, our attack is unique in that it requires no physical contact with the device under attack. Power analysis can be carried out even if both the tag and the attacker are passive and transmit no data, making the attack very hard to detect. As a proof of concept, we describe a password extraction attack on Class 1 Generation 1 EPC tags. We also show how the privacy of Class 1 Generation 2 tags can be compromised by this attack. Finally, we examine possible modifications to the tag and its RF front end which help protect against power analysis attacks. Yossef Oren, Adi Shamir |
IEEE Trans. Computers | 1 |