IEEE ICCADCountermeasuresFormal verification

Flavien Solt
Assistant Professor
Department of Computer Science · School of Computing, National University of Singapore
Office: COM2-02-07
Bio
Flavien Solt is an Assistant Professor in the Department of Computer Science at the National University of Singapore (NUS) and leads the ChocoLab. Flavien's research centers on the correctness and security of the lower levels of computers: offensive methods that uncover and exploit vulnerabilities deep in the computing stack, and defenses that protect systems against them. The work combines dynamic techniques such as hardware fuzzing and information-flow tracking with formal verification and AI-driven methods, to make hardware security analysis more scalable and effective.
Before joining NUS, Flavien was a postdoctoral researcher at UC Berkeley, collaborating with Christopher Fletcher's research group. Flavien completed a PhD in 2024 in the Computer Security Group (COMSEC) at ETH Zurich, advised by Kaveh Razavi. The thesis received the ETH Medal.
Research interests
- Hardware security
- Fuzzing
- Applications of formal methods
- Electronic design automation
- Machine learning applications to hardware
- AI for security
Education
- PhD, ETH Zurich, 2024. Advisor: Kaveh Razavi.
- MSc in Electrical Engineering and Information Technology, ETH Zurich
- Ingénieur Polytechnicien (X2016), École Polytechnique, France
Awards
- ETH Medal for the PhD thesis
- CCS 2025 Top Reviewer Award
Teaching
- NUS: CS3235 Computer Security and CS6230 Topics in Information Security
- ETH Zurich, as teaching assistant: Computer Engineering (2022 to 2024) and VLSI 1: HDL Based Design for FPGAs (2020)
Service
- Reviewer: ISCA '26, USENIX Security '26, CCS '26, CCS '25, Top Picks in Hardware and Embedded Security '24
- Subreviewer: DIMVA '23, USENIX ATC '22, CCS '21
Mentoring
Students supervised since 2022
NUS, 2026
- Lu Kun, research assistant
- Rayan Mellouk, Éric Ordoquy, Francois Loning, Jules Bioulac, and Émilien Garnier: master's theses, visiting from École Polytechnique
- Ayush Raina, intern, visiting from the Indian Institute of Science, Bangalore
- Zhenyu Lei, intern, visiting from Southeast University
UC Berkeley, 2025
- Benjamin Lang, Zhenrong Lang, Florian Chivé, Rémi Germe, and Jean-Nicolas Strauss: master's theses
- Chaitanya Gambali: bachelor's thesis
- Frank Jin and SooHyuk Cho: bachelor's projects
ETH Zurich, 2022 to 2024
- Matej Bölcskei: master's thesis, 2024 (ETH Medal)
- Tobias Kovats: master's thesis, 2024, and semester thesis, 2023
- Quentin Bordier: semester thesis, 2024, and bachelor's thesis, 2022
- Sandro Rüegge, Tristan Sachsenweger: master's theses, 2023
- Adriel Tan: master's thesis, 2023, and semester thesis, 2022
- Maximilian Sabayev, Stijn Gunther: master's theses, 2022
- Valentin Ogier, Guillaume Thivolet: semester theses, 2022
Publications
IEEE/ACM ISCAOffenseFuzzing & validation
HartBreaker: Deterministic Fuzzing of Multi-Hart RISC-V CPUs with Non-Deterministic Programs
IEEE EuroS&PCountermeasuresFormal verificationInformation-flow tracking
VerIFI: Formal Verification of Microarchitectural Information-Flow Integrity
IEEE Symposium on Security & PrivacyOffenseFuzzing & validation
Enter, Exit, Page Fault, Leak: Testing Isolation Boundaries for Microarchitectural Leaks
Distinguished Paper Award
IEEE ICCADTools & analysisInformation-flow tracking
Pathfinder: Constructing Cycle-accurate Taint Graphs for Analyzing Information Flow Traces
ACM CCSOffenseInformation-flow tracking
MileSan: Detecting Exploitable Microarchitectural Leakage via Differential Hardware–Software Taint Tracking
USENIX SecurityTools & analysisDRAM & Rowhammer
McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis
USENIX SecurityTools & analysisFuzzing & validation
Encarsia: Evaluating CPU Fuzzers via Automatic Bug Injection
Distinguished Artifact Award
USENIX SecurityOffenseFuzzing & validation
Lost in Translation: Enabling Confused Deputy Attacks on EDA Software with TransFuzz
ACM CCSCountermeasuresFormal verificationInformation-flow tracking
μCFI: Formal Verification of Microarchitectural Control-flow Integrity
IEEE/ACM ISCATools & analysisDRAM & Rowhammer
HiFi-DRAM: Enabling High-Fidelity DRAM Research by Uncovering Sense Amplifiers with IC Imaging
USENIX SecurityOffenseDRAM & Rowhammer
ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms
IEEE ICCADTools & analysisInformation-flow tracking
HybriDIFT: Scalable Memory-Aware Dynamic Information Flow Tracking for Hardware
USENIX SecurityOffenseFuzzing & validation
Cascade: CPU Fuzzing via Intricate Program Generation
IEEE Symposium on Security & PrivacyCountermeasuresDRAM & Rowhammer
Rega: Scalable Rowhammer Mitigation with Refresh-Generating Activations
IEEE/ACM MICROTools & analysisFuzzing & validation
RemembERR: Leveraging Microprocessor Errata for Design Testing and Validation
IEEE Symposium on Security & PrivacyCountermeasuresDRAM & Rowhammer
ProTRR: Principled Yet Optimal In-DRAM Target Row Refresh
USENIX SecurityTools & analysisInformation-flow tracking