Course Schedule, Reading List, and Slides Fall 2026
L Lecture given by the instructor D Paper discussion led by student presenters
Jump to next date Finding upcoming card
Week 1: Bootstrap Aug 26Wed
L Topic Overview and Project Ideas Materials: Slides
Week 2: Microarchitectural Side Channels Aug 31Mon
L Cache-Based Side Channels (w/ Demo!) Pre-lecture: Please watch this conference presentation Link
Post-lecture: Choose one to review:
Last-Level Cache Side-Channel Attacks are Practical (SP '15) Link Theory and Practice of Finding Eviction Sets (SP '19) Link Materials: Slides , PoC
Sep 2Wed
L Side Channels in Public Clouds (w/ Demo!) Pre-lecture: Please read this short article on serverless computing Link
Optional:
Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds (CCS '09) Link Everywhere All at Once: Co-Location Attacks on Public Cloud FaaS (ASPLOS '24) Link Materials: Slides
Week 3: Transient Execution Attacks Sep 9Wed
L Spectre and Meltdown (w/ Demo!) Pre-lecture: Conference presentation of Spectre Attacks Link
Post-lecture: Choose one to review:
An Analysis of Speculative Type Confusion Vulnerabilities in the Wild (USENIX Sec '21) Link A Systematic Evaluation of Transient Execution Attacks and Defenses Link Materials: TBA
Week 4: Side-Channel Defenses Sep 14Mon
L Data-Oblivious Computation Pre-lecture: Guidelines for Mitigating Timing Side Channels Against Cryptographic Implementations by Intel Link
Optional:
Oblivious RAM by Elaine Shi Link Cryptocoding by Jean-Philippe Aumasson Link Materials: Slides , PoC
Sep 16Wed
L Partitioning and Randomization Pre-lecture: TBA
Note: No post-lecture reading; please focus on your term project proposal.
Optional: A Game of Cache Attacks and Defense by Moinuddin Qureshi at MAD tutorial (ISCA '22) Link
Materials: TBA
Sep 21Mon
D A Tale of Two Spectre Defenses Papers to discuss: Choose one to review:
Efficient Invisible Speculative Execution through Selective Delay and Value Prediction (ISCA '19) Link Speculative Taint Tracking (STT): A Comprehensive Protection for Speculatively Accessed Data (MICRO '19) Link Optional:
Speculative interference attacks: breaking invisible speculation schemes Link Speculative Data-Oblivious Execution: Mobilizing Safe Prediction For Safe and Efficient Speculative Execution Link Retpoline: a software construct for preventing branch-target-injection Link RETBLEED: Arbitrary Speculative Code Execution with Return Instructions Link The AMD Branch (Mis)predictor: Just Set it and Forget it! (Part 1 , Part 2 ) Sep 23Wed
Papers to discuss: Choose one to review:
Complete Information Flow Tracking from the Gates Up (ASPLOS '09) Link Speculative Privacy Tracking (SPT): Leaking Information From Speculative Execution Without Compromising Privacy (MICRO '21) Link Week 6: Trusted Execution Environments (TEEs) Sep 28Mon
L TEE Overview and Software Attestation Optional: Intel SGX Explained Link
Materials: Slides
Sep 30Wed
L Memory Encryption and Integrity Protection Optional:
Efficient Memory Integrity Verification and Encryption for Secure Processors Link Using Address Independent Seed Encryption and Bonsai Merkle Trees to Make Secure Processors OS- and Performance-Friendly Link Materials: Slides
Week 7: Trusted Execution Environments (TEEs) Oct 5Mon
L TEE Designs Pre-lecture: (Presentation) Keystone: An Open Framework for Architecting Trusted Execution Environments Link
Materials: Slides
Oct 7Wed
D Attacks on TEEs Papers to discuss: Choose one to review:
Controlled-Channel Attacks: Deterministic Side Channels for Untrusted Operating Systems (SP '15) Link MicroScope: Enabling Microarchitectural Replay Attacks (ISCA '19) Link Week 8: Isolation and Memory Safety Oct 12Mon
L OS and VM Isolation Optional:
Performance Evaluation of Intel EPT Hardware Assist Link A Comparison of Software and Hardware Techniques for x86 Virtualization Link My VM is Lighter (and Safer) than your Container Link Firecracker: Lightweight Virtualization for Serverless Applications Link Blending Containers and Virtual Machines: A Study of Firecracker and gVisor Link Materials: Slides
Oct 14Wed
L Memory Safety Pre-lecture: Running a Buffer Overflow Attack - Computerphile Link
Optional:
SoK: Eternal War in Memory Link An Introduction to CHERI Link No-FAT: Architectural Support for Low Overhead Memory Safety Checks Link SPECCFI: Mitigating Spectre Attacks using CFI Informed Speculation Link Materials: Slides
Week 9: Isolation and Memory Safety Oct 19Mon
D In-Process Isolation Papers to discuss: Choose one to review:
Donky: Domain Keys–Efficient In-Process Isolation for RISC-V and x86 (USENIX '20) Link Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFI (ASPLOS '23) Link Oct 21Wed
D Transient Execution + Memory Safety Papers to discuss: Choose one to review:
Speculative Probing: Hacking Blind in the Spectre Era (CCS '20) Link PACMAN: Attacking ARM Pointer Authentication with Speculative Execution (ISCA '22) Link Week 10: RowHammer and Inspiring Papers/Ideas Oct 26Mon
L RowHammer Optional:
The Story of Rowhammer Link Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors Link Graphene: Strong yet Lightweight RowHammer Protection Link ProTRR: Principled yet Optimal In-DRAM Target Row Refresh Link Materials: Slides
Oct 28Wed
D Attacking AI Systems Papers to discuss: Choose one to review:
MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs (CCS '25) Link I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM Serving (NDSS '25) Link Week 11: Inspiring Papers/Ideas Nov 2Mon
D Emerging TEE Designs Papers to discuss: Choose one to review:
Graviton: Trusted Execution Environments on GPUs (OSDI '18) Link Sequestered Encryption: A Hardware Technique for Comprehensive Data Privacy (SEED '22) Link Optional:
Creating the First Confidential GPUs Link Security Verification of Low-Trust Architectures (CCS '23) Link Privacy-enhanced computation via sequestered encryption (US Patent) Link Nov 4Wed
D uArch Weird Machines Papers to discuss: Choose one to review:
Computing with Time: Microarchitectural Weird Machines (ASPLOS '21) Link The Gates of Time: Improving Cache Attacks with Transient Execution (USENIX Sec '23) Link Week 12: Inspiring Papers/Ideas Nov 9Mon
L Physical Attacks Nov 11Wed
D Fun Side Channels Papers to discuss: Choose one to review:
Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86 (USENIX Sec '22) Link Pentimento: Data Remanence in Cloud FPGAs (ASPLOS '24) Link Optional:
DVFS Frequently Leaks Secrets: Hertzbleed Attacks Beyond SIKE, Cryptography, and CPU-Only Data Link Hot Pixels: Frequency, Power, and Temperature Attacks on GPUs and Arm SoCs Link Advice from DJB Link Week 13: Inspiring Papers/Ideas Nov 16Mon
D Attacks on GPU Paper to discuss:
BarraCUDA: Edge GPUs do Leak DNN Weights (USENIX Sec '25) Link GPU.zip: On the Side-Channel Implications of Hardware-Based Graphical Data Compression (SP '24) Link Optional:
On Subnormal Floating Point and Abnormal Timing Link Pixnapping Attack Link Nov 18Wed
D SW & HW Fuzzing Papers to discuss: Choose one to review:
SpecFuzz: Bringing Spectre-Type Vulnerabilities to the Surface (USENIX Sec '20) Link Cascade: CPU Fuzzing via Intricate Program Generation (USENIX Sec '24) Link Optional videos on hardware fuzzing:
The Discovery of Zenbleed ft. Tavis Ormandy by LiveOverflow Link Breaking the x86 Instruction Set by Christopher Domas at BlackHat '17 Link Week 14: Fall Break Nov 23-Nov 28Mon-Sat
Fall Break Optional reading: Why We Sleep by Matthew Walker
Week 15: Summary and Project Presentations Nov 30Mon
Reflect and Chat (with free food!) Dec 2Wed
Final Presentation (1) Week 16: Project Presentations Dec 7Mon
Final Presentation (2)