Projects
Long-running research vehicles in the lab. Each project corresponds to a thesis chapter or sequence of papers, plus a public artifact we maintain on GitHub.
ArmGuard
activeAn always-on detector for Prime+Probe and Flush+Reload contention on Arm Cortex-A. Ships as a kernel module + lightweight userspace daemon; <1% overhead on SPEC.
Tessera
activeHardware partitioning for confidential GPU workloads on Mali. Splits the command stream and memory hierarchy so untrusted tenants cannot observe each other's tiles.
BootShade
activeSelective authentication of firmware code regions to keep boot latency tractable on real-time SoCs. Integrates with TF-A; upstream patches in review.
Realm-OS
activeAn operating-system substrate for Arm Confidential Compute Architecture. Treats realms as first-class composable units with explicit memory and IPC contracts.
FirmFuzz-A
maintainedCoverage-guided fuzzer for Arm Trusted Firmware-A, with custom harnesses for PSCI and SCMI. Has found 17 CVEs to date.
PrimeWatch
archivedDetector that motivated ArmGuard. Retained as a reproducibility artifact for the 2025 ISCA paper.