Research
What we work on. Placeholder entries — replace with the group's real directions.
Hypervisor & Virtualization SecuritySample — replace
Making the layer under everything smaller, and harder to break.SAMPLE — replace with a real description. We study how hypervisors fail and how to make them fail less: attack surface reduction, memory-safety hardening of device models, and formally verified micro-hypervisors.
KVMXenattack surfaceformal verification
Operating System Kernel HardeningSample — replace
Defense in depth for the code that everything else trusts.SAMPLE — replace with a real description. Exploit mitigations, kernel isolation primitives, and automated vulnerability discovery for commodity and research operating systems.
memory safetysandboxingfuzzingeBPF
Confidential Computing & Trusted ExecutionSample — replace
Trust models, attestation, and side channels for enclaves and confidential VMs.SAMPLE — replace with a real description. We examine what enclaves and confidential VMs actually guarantee: attestation protocols, microarchitectural side channels, and usable trust models.
SGXSEVattestationside channels