Course Schedule, Reading List, and Slides

Fall 2026


L Lecture given by the instructor D Paper discussion led by student presenters

Week 1: Bootstrap

Aug 24Mon

L Course Logistics

Readings: Please fill this anonymous course-preparation survey after the first class and before Aug 27 (Thu).

Materials: Slides

Aug 26Wed

L Topic Overview and Project Ideas

Materials: Slides

Week 2: uArch Side Channels

Aug 31Mon

L Cache-Based Side Channels (w/ Demo!)

Pre-lecture: Flush+Reload: A High Resolution, Low Noise, L3 Cache Side-Channel Attack (USENIX Sec '14, Sections 1-3) Link

Post-lecture: Choose one to review:

  • Last-Level Cache Side-Channel Attacks are Practical (SP '15) Link
  • Theory and Practice of Finding Eviction Sets (SP '19) Link

Materials: Slides, PoC

Sep 2Wed

L Side Channels in Public Clouds (w/ Demo!)

Pre-lecture: Hey, You, Get Off of My Cloud: Exploring Information Leakage in Third-Party Compute Clouds (CCS '09, Sections 1-3, 6) Link

Post-lecture: Everywhere All at Once: Co-Location Attacks on Public Cloud FaaS (ASPLOS '24) Link

Materials: Slides

Week 3: uArch Side Channels

Sep 7Mon

Labor Day

Sep 9Wed

L Partitioning, Randomization, and Detection

Pre-lecture: CATalyst: Defeating Last-Level Cache Side Channel Attacks in Cloud Computing (HPCA '16, Sections 1-3) Link

Note: No post-lecture reading; please focus on your term project proposal.

Optional: A Game of Cache Attacks and Defense by Moinuddin Qureshi at MAD tutorial (ISCA '22) Link

Materials: Slides

Week 4: Data-Oblivious Computation and Speculation

Sep 14Mon

L Data-Oblivious Computation

Pre-lecture: Guidelines for Mitigating Timing Side Channels Against Cryptographic Implementations by Intel Link

Optional:

  • Oblivious RAM by Elaine Shi Link
  • Cryptocoding by Jean-Philippe Aumasson Link

Materials: Slides, PoC

Sep 16Wed

L Transient-Execution Attacks (w/ Demo!)

Pre-lecture: Conference presentation of Spectre Attacks Link

Optional:

  • Spectre Attacks: Exploiting Speculative Execution Link
  • Meltdown: Reading Kernel Memory from User Space Link
  • A Systematic Evaluation of Transient Execution Attacks and Defenses Link

Materials: Slides, PoC

Week 5: Speculation

Sep 21Mon

D Advanced Spectre Attacks

Papers to discuss: Choose one to review:

  • An Analysis of Speculative Type Confusion Vulnerabilities in the Wild (USENIX Sec '21) Link
  • Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 Attacks (USENIX Sec '22) Link

Optional:

  • Retpoline: a software construct for preventing branch-target-injection Link
  • RETBLEED: Arbitrary Speculative Code Execution with Return Instructions Link
  • The AMD Branch (Mis)predictor: Just Set it and Forget it! (Part 1, Part 2)
Sep 23Wed

D Hardware Defenses

Papers to discuss: Choose one to review:

  • Efficient Invisible Speculative Execution through Selective Delay and Value Prediction (ISCA '19) Link
  • Speculative Taint Tracking (STT): A Comprehensive Protection for Speculatively Accessed Data (MICRO '19) Link

Optional:

  • Speculative interference attacks: breaking invisible speculation schemes Link
  • Speculative Data-Oblivious Execution: Mobilizing Safe Prediction For Safe and Efficient Speculative Execution Link

Week 6: Trusted Execution Environments (TEEs)

Sep 28Mon

L TEE Overview and Attestation

Optional: Intel SGX Explained Link

Materials: Slides

Sep 30Wed

L Memory Encryption and Integrity Protection

Optional:

  • Efficient Memory Integrity Verification and Encryption for Secure Processors Link
  • Using Address Independent Seed Encryption and Bonsai Merkle Trees to Make Secure Processors OS- and Performance-Friendly Link

Materials: Slides

Week 7: Trusted Execution Environments (TEEs)

Oct 5Mon

L TEE Designs

Pre-lecture: (Presentation) Keystone: An Open Framework for Architecting Trusted Execution Environments Link

Materials: Slides

Oct 7Wed

D Attacks on TEEs

Papers to discuss: Choose one to review:

  • Controlled-Channel Attacks: Deterministic Side Channels for Untrusted Operating Systems (SP '15) Link
  • MicroScope: Enabling Microarchitectural Replay Attacks (ISCA '19) Link

Week 8: Isolation and Memory Safety

Oct 12Mon

L OS and VM Isolation

Optional:

  • Performance Evaluation of Intel EPT Hardware Assist Link
  • A Comparison of Software and Hardware Techniques for x86 Virtualization Link
  • My VM is Lighter (and Safer) than your Container Link
  • Firecracker: Lightweight Virtualization for Serverless Applications Link
  • Blending Containers and Virtual Machines: A Study of Firecracker and gVisor Link

Materials: Slides

Oct 14Wed

L Memory Safety

Pre-lecture: Running a Buffer Overflow Attack - Computerphile Link

Optional:

  • SoK: Eternal War in Memory Link
  • An Introduction to CHERI Link
  • No-FAT: Architectural Support for Low Overhead Memory Safety Checks Link
  • SPECCFI: Mitigating Spectre Attacks using CFI Informed Speculation Link

Materials: Slides

Week 9: Isolation and Memory Safety

Oct 19Mon

D In-Process Isolation

Papers to discuss: Choose one to review:

  • Donky: Domain Keys–Efficient In-Process Isolation for RISC-V and x86 (USENIX '20) Link
  • Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFI (ASPLOS '23) Link
Oct 21Wed

D Transient Execution + Memory Safety

Papers to discuss: Choose one to review:

  • Speculative Probing: Hacking Blind in the Spectre Era (CCS '20) Link
  • PACMAN: Attacking ARM Pointer Authentication with Speculative Execution (ISCA '22) Link

Week 10: RowHammer and Inspiring Papers/Ideas

Oct 26Mon

L RowHammer

Optional:

  • The Story of Rowhammer Link
  • Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors Link
  • Graphene: Strong yet Lightweight RowHammer Protection Link
  • ProTRR: Principled yet Optimal In-DRAM Target Row Refresh Link

Materials: Slides

Oct 28Wed

D Attacking AI Systems

Papers to discuss: Choose one to review:

  • MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs (CCS '25) Link
  • I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM Serving (NDSS '25) Link

Week 11: Inspiring Papers/Ideas

Nov 2Mon

D Emerging TEE Designs

Papers to discuss: Choose one to review:

  • Graviton: Trusted Execution Environments on GPUs (OSDI '18) Link
  • Sequestered Encryption: A Hardware Technique for Comprehensive Data Privacy (SEED '22) Link

Optional:

  • Creating the First Confidential GPUs Link
  • Security Verification of Low-Trust Architectures (CCS '23) Link
  • Privacy-enhanced computation via sequestered encryption (US Patent) Link
Nov 4Wed

D uArch Weird Machines

Papers to discuss: Choose one to review:

  • Computing with Time: Microarchitectural Weird Machines (ASPLOS '21) Link
  • The Gates of Time: Improving Cache Attacks with Transient Execution (USENIX Sec '23) Link

Week 12: Inspiring Papers/Ideas

Nov 9Mon

L Information-Flow Tracking in Hardware

Paper to discuss: Choose one to review:

  • Complete Information Flow Tracking from the Gates Up (ASPLOS '09) Link
  • Speculative Privacy Tracking (SPT): Leaking Information From Speculative Execution Without Compromising Privacy (MICRO '21) Link

Materials: Slides

Nov 11Wed

D Fun Side Channels

Papers to discuss: Choose one to review:

  • Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86 (USENIX Sec '22) Link
  • Pentimento: Data Remanence in Cloud FPGAs (ASPLOS '24) Link

Optional:

  • DVFS Frequently Leaks Secrets: Hertzbleed Attacks Beyond SIKE, Cryptography, and CPU-Only Data Link
  • Hot Pixels: Frequency, Power, and Temperature Attacks on GPUs and Arm SoCs Link
  • Advice from DJB Link

Week 13: Inspiring Papers/Ideas

Nov 16Mon

D Attacks on GPU

Paper to discuss:

  • BarraCUDA: Edge GPUs do Leak DNN Weights (USENIX Sec '25) Link
  • GPU.zip: On the Side-Channel Implications of Hardware-Based Graphical Data Compression (SP '24) Link

Optional:

  • On Subnormal Floating Point and Abnormal Timing Link
  • Pixnapping Attack Link
Nov 18Wed

D SW & HW Fuzzing

Papers to discuss: Choose one to review:

  • SpecFuzz: Bringing Spectre-Type Vulnerabilities to the Surface (USENIX Sec '20) Link
  • Cascade: CPU Fuzzing via Intricate Program Generation (USENIX Sec '24) Link

Optional videos on hardware fuzzing:

  • The Discovery of Zenbleed ft. Tavis Ormandy by LiveOverflow Link
  • Breaking the x86 Instruction Set by Christopher Domas at BlackHat '17 Link

Week 14: Fall Break

Nov 23-Nov 28Mon-Sat

Fall Break

Optional reading: Why We Sleep by Matthew Walker

Week 15: Summary and Project Presentations

Nov 30Mon

Reflect and Chat (with free food!)

Dec 2Wed

Final Presentation (1)

Week 16: Project Presentations

Dec 7Mon

Final Presentation (2)