a self portrait

I am a PhD student at the Institute of Applied Information Processing and Communications at Graz University of Technology, focusing on Rowhammer, side channels and microarchitectural attacks. In my free time I like to take pictures and time lapses.
I had a blog which I have not updated for quite some time.

Publications

  • 2024
  • Presshammer: Rowhammer and Rowpress without Physical Address Information

    We compare Rowhammer and Rowpress on various DRAM modules and show the first end-to-end Rowpress exploit.

    Jonas Juffinger, Sudheendra Raghav Neela, Martin Heckel, Lukas Schwarz, Florian Adamsky, Daniel Gruss

    DIMVA'24, EPFL in Lausanne, Switzerland, July 17 - 19, 2024
  • SUIT: Secure Undervolting with Instruction Traps

    We developed a system that allows securely undervolting CPUs by trapping faulting instructions.

    Jonas Juffinger, Stepan Kalinin, Daniel Gruss, Frank Mueller

    ASPLOS'24, San Diego, CA, USA, April 27 - May 1, 2024 Artifacts
  • JavaSQUIP: Remote Scheduler Contention Attacks

    We show the SQUIP side channel from JavaScript without a timer using a microarchitectural bingo race.

    Stefan Gast, Jonas Juffinger, Lukas Maar, Christoph Royer, Andreas Kogler Daniel Gruss

    FC'24, Willemstad, Curaçao, March 4-8, 2024
  • IdleLeak: Exploiting Idle State Side Effects for Information Leakage

    Using the tpause instruction to detect interrupts, we build a covert-channel and spy on user behavior.

    Fabian Rauscher, Andreas Kogler, Jonas Juffinger, Daniel Gruss

    NDSS'24, San Diego, CA, USA, February 26 - March 1, 2024
  • 2023
  • CSI:Rowhammer - Cryptographic Security and Integrity against Rowhammer

    With a MAC instead of ECC bits we are able to detect all data corruptions in DRAM and correct most.

    Jonas Juffinger, Lukas Lamster, Andreas Kogler, Maria Eichlseder, Moritz Lipp, Daniel Gruss

    S&P'23, San Francisco, California, USA, May 22–26, 2023 GitHub Trailer Recording Slides
  • Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels

    By colliding victim with attacker controlled data in the CPU cache we can leak arbitrary data.

    Andreas Kogler, Jonas Juffinger, Lukas Giner, Lukas Gerlach, Martin Schwarzl, Michael Schwarz, Daniel Gruss, Stefan Mangard

    32st USENIX Security Symposium, Anaheim, CA, USA, August 9–11, 2023 Website GitHub
  • PT-Guard: - Protected Page Tables to Defend Against Breakthrough Rowhammer Attacks

    We store a MAC in unused page table bits to detect and correct corruptions caused by Rowhammer.

    Anish Saxena, Gururaj Saileshwar, Jonas Juffinger, Andreas Kogler, Daniel Gruss, Moinuddin Qureshi

    IEEE IFIP DSN 2023, Porto, Portugal, June 27–30, 2023
  • SQUIP: Exploiting the Scheduler Queue Contention Side Channel

    By measuring contention in AMD execution unit scheduler queues we can leak RSA keys.

    Stefan Gast, Jonas Juffinger, Martin Schwarzl, Gururaj Saileshwar, Andreas Kogler, Simone Franza, Markus Köstl, Daniel Gruss

    S&P'23, San Francisco, California, USA, May 22–26, 2023
  • 2022
  • Half-Double: Hammering From the Next Row Over

    We show a new Rohammer method that exploits a mitigation and build a novel exploit for Chromebooks.

    Andreas Kogler, Jonas Juffinger, Salman Qazi, Yoongu Kim, Moritz Lipp, Nicolas Boichat, Eric Shiu, Mattias Nissler, Daniel Gruss

    31st USENIX Security Symposium, Boston, MA, USA, August 10–12, 2022 GitHub Recording Slides
  • 2021
  • Master’s Thesis: Rowhammer Exploits are still possible

    Using half-double Rowhammer we develop a novel privilege escalation exploit targeting a Chromebook.

    Jonas Juffinger, Advisor: Daniel Gruss

    Graz University of Technology IAIK, September 21, 2021
  • 2018
  • Another Flip in the Wall of Rowhammer Defenses

    With a new Rowhammer method and from Intel SGX we show a completely undetectable exploit.

    Daniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin, Jonas Juffinger, Sioli O'Connell, Wolfgang Schoechl, Yuval Yarom

    S&P'18, San Francisco, California, USA, May 21–23, 2018

Talks