https://zhangruiyi.me/publication/snpeek/
SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMs | Ruiyi Zhang / 张睿一
May 9, 2026 - Confidential virtual machines (CVMs) based on trusted execution environments (TEEs) enable new privacy-preserving solutions. Yet, they leave side-channel...
side channelruiyi zhang
https://zhangruiyi.me/publication/cachewarp/
CacheWarp: Software-based Fault Injection using Selective State Reset | Ruiyi Zhang / 张睿一
Nov 13, 2024 - AMD SEV is a trusted-execution environment (TEE), providing confidentiality and integrity for virtual machines (VMs). With AMD SEV, it is possible to securely...
fault injectionruiyi zhangcachewarpsoftwarebased
https://zhangruiyi.me/publication/mapa/
Taming the Linux Memory Allocator for Rapid Prototyping | Ruiyi Zhang / 张睿一
May 9, 2026 - Microarchitectural attacks pose an increasing threat to system security. They enable attackers to extract sensitive information such as cryptographic keys,...
rapid prototypingruiyi zhangtaminglinuxmemory
https://zhangruiyi.me/publication/riscv/
A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs | Ruiyi Zhang / 张睿一
May 9, 2026 - Microarchitectural attacks threaten the security of computer systems even in the absence of software vulnerabilities. Such attacks are well explored on x86 and...
microarchitectural attacksruiyi zhangsecurityrischardware
https://zhangruiyi.me/publication/shadowload/
ShadowLoad: Injecting State into Hardware Prefetchers | Ruiyi Zhang / 张睿一
May 9, 2026 - Hardware prefetchers are an optimization in modern CPUs for predicting memory accesses and preemptively loading the corresponding value into the cache....
ruiyi zhanginjectingstatehardware
https://roots.ec/people/ruiyi-zhang/
Ruiyi Zhang | Rootsec
Hi there! I am a PhD student at the RootSec lab. My research explores the security of microarchitecture and TEEs. I am a big fan of Coke Zero.
ruiyi zhangrootsec
https://zhangruiyi.me/
Ruiyi Zhang / 张睿一
Ruiyi Zhang is a PhD researcher specializing in CPU and system security. Discoverer of CacheWarp and StackWarp CPU vulnerabilities.
ruiyi zhang
https://zhangruiyi.me/talk/arbitrary-data-manipulation-and-leakage-with-cpu-zero-day-bugs-on-risc-v/
Arbitrary Data Manipulation and Leakage with CPU Zero-Day Bugs on RISC-V | Ruiyi Zhang / 张睿一