Research

What we work on. Placeholder entries — replace with the group's real directions.

Hypervisor & Virtualization SecuritySample — replace

Making the layer under everything smaller, and harder to break.

SAMPLE — replace with a real description. We study how hypervisors fail and how to make them fail less: attack surface reduction, memory-safety hardening of device models, and formally verified micro-hypervisors.

KVMXenattack surfaceformal verification

Operating System Kernel HardeningSample — replace

Defense in depth for the code that everything else trusts.

SAMPLE — replace with a real description. Exploit mitigations, kernel isolation primitives, and automated vulnerability discovery for commodity and research operating systems.

memory safetysandboxingfuzzingeBPF

Confidential Computing & Trusted ExecutionSample — replace

Trust models, attestation, and side channels for enclaves and confidential VMs.

SAMPLE — replace with a real description. We examine what enclaves and confidential VMs actually guarantee: attestation protocols, microarchitectural side channels, and usable trust models.

SGXSEVattestationside channels