Publications

Theme
Kind Award
2022 2023 2024 2025 2026 Fuzzing &validation Information-flowtracking Formalverification DRAM & Rowhammer RemembERR: Leveraging Microprocessor Errata for Design Testing and Validation (IEEE/ACM MICRO 2022) RemembERR MICRO CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTL (USENIX Security 2022) CellIFT USENIX Sec ProTRR: Principled Yet Optimal In-DRAM Target Row Refresh (IEEE Symposium on Security & Privacy 2022) ProTRR S&P Rega: Scalable Rowhammer Mitigation with Refresh-Generating Activations (IEEE Symposium on Security & Privacy 2023) Rega S&P Cascade: CPU Fuzzing via Intricate Program Generation (USENIX Security 2024) Cascade USENIX Sec HybriDIFT: Scalable Memory-Aware Dynamic Information Flow Tracking for Hardware (IEEE ICCAD 2024) HybriDIFT ICCAD μCFI: Formal Verification of Microarchitectural Control-flow Integrity (ACM CCS 2024) μCFI CCS ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms (USENIX Security 2024) ZenHammer USENIX Sec HiFi-DRAM: Enabling High-Fidelity DRAM Research by Uncovering Sense Amplifiers with IC Imaging (IEEE/ACM ISCA 2024) HiFi-DRAM ISCA Lost in Translation: Enabling Confused Deputy Attacks on EDA Software with TransFuzz (USENIX Security 2025) TransFuzz USENIX Sec Encarsia: Evaluating CPU Fuzzers via Automatic Bug Injection (USENIX Security 2025), Distinguished Artifact Award Encarsia USENIX Sec MileSan: Detecting Exploitable Microarchitectural Leakage via Differential Hardware–Software Taint Tracking (ACM CCS 2025) MileSan CCS Pathfinder: Constructing Cycle-accurate Taint Graphs for Analyzing Information Flow Traces (IEEE ICCAD 2025) Pathfinder ICCAD McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis (USENIX Security 2025) McSee USENIX Sec Enter, Exit, Page Fault, Leak: Testing Isolation Boundaries for Microarchitectural Leaks (IEEE Symposium on Security & Privacy 2026), Distinguished Paper Award Enter, Exit,Page Fault, Leak S&P HartBreaker: Deterministic Fuzzing of Multi-Hart RISC-V CPUs with Non-Deterministic Programs (IEEE/ACM ISCA 2026) HartBreaker ISCA VerIFI: Formal Verification of Microarchitectural Information-Flow Integrity (IEEE EuroS&P 2026) VerIFI EuroS&P Inconstant: Refining Assumptions in Automated Formal Constant-Time CPU Verification (IEEE ICCAD 2026) Inconstant ICCAD

18 papers

2026

IEEE ICCADCountermeasuresFormal verification

Inconstant: Refining Assumptions in Automated Formal Constant-Time CPU Verification

Flavien Solt and Chris Fletcher

2026

IEEE/ACM ISCAOffenseFuzzing & validation

HartBreaker: Deterministic Fuzzing of Multi-Hart RISC-V CPUs with Non-Deterministic Programs

Quentin Bordier, Tobias Kovats, Flavien Solt, and Kaveh Razavi

2026

IEEE EuroS&PCountermeasuresFormal verificationInformation-flow tracking

VerIFI: Formal Verification of Microarchitectural Information-Flow Integrity

Katharina Ceesay-Seitz, Flavien Solt, Mengyuan Yin, and Kaveh Razavi

2026

IEEE Symposium on Security & PrivacyOffenseFuzzing & validation

Enter, Exit, Page Fault, Leak: Testing Isolation Boundaries for Microarchitectural Leaks

Oleksii Oleksenko, Flavien Solt, Cédric Fournet, Jana Hofmann, B. Köpf, and Stavros Volos

Distinguished Paper Award

2025

IEEE ICCADTools & analysisInformation-flow tracking

Pathfinder: Constructing Cycle-accurate Taint Graphs for Analyzing Information Flow Traces

Katharina Ceesay-Seitz, Flavien Solt, Alexander Klukas, and Kaveh Razavi

2025

ACM CCSOffenseInformation-flow tracking

MileSan: Detecting Exploitable Microarchitectural Leakage via Differential Hardware–Software Taint Tracking

T. Kovats, Flavien Solt, Katharina Ceesay-Seitz, and Kaveh Razavi

2025

USENIX SecurityTools & analysisDRAM & Rowhammer

McSee: Evaluating Advanced Rowhammer Attacks and Defenses via Automated DRAM Traffic Analysis

Patrick Jattke, Michele Marazzi, Flavien Solt, Max Wipfli, Stefan Gloor, and Kaveh Razavi

2025

USENIX SecurityTools & analysisFuzzing & validation

Encarsia: Evaluating CPU Fuzzers via Automatic Bug Injection

Matej Bölcskei, Flavien Solt, Katharina Ceesay-Seitz, and Kaveh Razavi

Distinguished Artifact Award

2025

USENIX SecurityOffenseFuzzing & validation

Lost in Translation: Enabling Confused Deputy Attacks on EDA Software with TransFuzz

Flavien Solt and Kaveh Razavi

2024

ACM CCSCountermeasuresFormal verificationInformation-flow tracking

μCFI: Formal Verification of Microarchitectural Control-flow Integrity

Katharina Ceesay-Seitz, Flavien Solt, and Kaveh Razavi

2024

IEEE/ACM ISCATools & analysisDRAM & Rowhammer

HiFi-DRAM: Enabling High-Fidelity DRAM Research by Uncovering Sense Amplifiers with IC Imaging

Michele Marazzi, Tristan Sachsenweger, Flavien Solt, Peng Zeng, Kubo Takashi, Maksym Yarema, et al.

2024

USENIX SecurityOffenseDRAM & Rowhammer

ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms

Patrick Jattke, M. Wipfli, Flavien Solt, Michele Marazzi, Matej Bölcskei, and Kaveh Razavi

2024

IEEE ICCADTools & analysisInformation-flow tracking

HybriDIFT: Scalable Memory-Aware Dynamic Information Flow Tracking for Hardware

Flavien Solt and Kaveh Razavi

2023

IEEE Symposium on Security & PrivacyCountermeasuresDRAM & Rowhammer

Rega: Scalable Rowhammer Mitigation with Refresh-Generating Activations

Michele Marazzi, Flavien Solt, Patrick Jattke, Kubo Takashi, and Kaveh Razavi

2022

IEEE/ACM MICROTools & analysisFuzzing & validation

RemembERR: Leveraging Microprocessor Errata for Design Testing and Validation

Flavien Solt, Patrick Jattke, and Kaveh Razavi

2022

IEEE Symposium on Security & PrivacyCountermeasuresDRAM & Rowhammer

ProTRR: Principled Yet Optimal In-DRAM Target Row Refresh

Michele Marazzi, Patrick Jattke, Flavien Solt, and Kaveh Razavi

2022

USENIX SecurityTools & analysisInformation-flow tracking

CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTL

Flavien Solt, Ben Gras, and Kaveh Razavi