Responsive image





Reliable DRAM Bank Addressing Function Recovery in Asymmetric Channel Setups

Fiedler, Carina; Rauscher, Fabian; Pfeifenberger, Markus; Heckel, Martin...

34rd Network and Distributed System Security Symposium (NDSS).


Open Access Peer Reviewed
 

Rowhammer attacks and DRAM side channel attacks require addresses that map to the same DRAM bank. Such addresses can be found using undocumented, reverse-engineered DRAM addressing functions. A recent large-scale Rowhammer study showed that existing reverse-engineering tools fail in about 50 % of real-world setups. These tools assume conventional setups with a power-of-two number of identical power-of-twosized DIMMs (PTID) but fail on asymmetric non-PTID setups.

In this paper, we discover that many non-PTID setups follow previously unknown conditional DRAM mappings, where different parts of memory obey different locally valid linear function sets. We present DREAMS, the first approach to recover DRAM bank addressing functions on non-PTID setups with such conditionally valid function sets. The key novelty is to model asymmetric mappings together with the conditions that select each function set, instead of assuming one globally valid linear function set. DREAMS detects bit-inconsistent behavior, i.e., cases where the influence of an address bit is not consistent across the address space, and uses this signal to infer whether the system is PTID or non-PTID. For non-PTID setups, DREAMS recovers the region- and channel-specific function sets and their selection conditions, and verifies the resulting conditional mapping entirely in software. For overlapping functions, DREAMS uses SAT constraints to model interactions between multiple candidate bits simultaneously, allowing the analytical recovery pipeline to handle functions that share bits. We evaluate DREAMS on 19 non-PTID DIMM configurations across 6 Intel and AMD DDR4/DDR5 systems, recovering mappings with up to 3 conditional function sets selected by address cutoffs and channel functions. We show that these reverse-engineered functions provide security-critical DRAM-bank information, e.g., for Rowhammer attacks, DRAM isolation mechanisms, and side-channel attacks. 

mehr

Side Attack: Off-Path Website Fingerprinting via Cross-Circuit Interference in Tor

Gad, Mohamed Farrag; Pahl, Sebastian; Gast, Stefan; Gruss, Daniel; Adamsky, Florian (2026)

Workshop on Privacy in the Electronic Society (WPES).


Open Access Peer Reviewed
 

Tor is a privacy-enhancing technology that enables anonymous communication by leveraging onion routing. A client chooses a path of three Tor relays, known as a circuit, and encrypts the traffic for each relay in reverse order, sending it to the first relay. Each relay knows only its predecessor and successor, unaware of the entire circuit, thus enabling anonymous communication. Tor builds the circuit telescopically, i. e., the first relay establishes a TCP connection to the second, and the second establishes a TCP connection to the third. However, Tor allows cross-circuit interference (CCI), meaning that if two circuits share two consecutive relays, data transmitted over the same TCP connection interferes with each other.

In this paper, we demonstrate that CCI can be exploited as a side channel to conduct an off-path (non-MitM) website fingerprinting attack. An attacker builds a two-hop circuit between a shared link and measures the Round Trip Time (RTT), while the victim browses on the same link, visiting different websites. That creates a bottleneck, which reveals the website the victim was accessing. We conducted an open-world experiment and show that an attacker can distinguish between monitored and unmonitored websites, achieving an 𝐹1-score of 94.2 % in a single-class setup and 63.2 % in a multi-class setup, where we differentiate between all websites and unmonitored ones. Additionally, we conducted a closed-world experiment with different exit relays on the Tor network. We demonstrate that an attacker can achieve an 𝐹1-score of up to 66.7 % when distinguishing the top 95 websites using only 150 traces per website. We also show that the security settings in the Tor browser can be an effective countermeasure when set to safest, reducing the 𝐹1-score to 1.2 %, but making web surfing unusable. 

mehr

Unlocking UML Class Diagram Understanding in Vision Language Models

Naboichenko, Artem; Peinl, René (2026)

11th Future Technologies Conference (FTC 2026), 15-16 October 2026, Berlin, Germany 2026.


Open Access Peer Reviewed
 

Although Vision Language Models (VLMs) have seen tremendous progress across all kinds of use cases, they still fall behind in answering questions regarding diagrams compared to photos. Although progress has been made in the area of bar charts, line charts and similar diagrams, there is still few research concerned with other types of diagrams, e.g. in the computer science domain. We identified a gap in research on visual question answering on UML class diagrams. Our objective is to fill the gap by analyzing the performance of popular open-weight VLMs on a self-constructed benchmark for visual question answering based on UML class diagrams which is both challenging and manageable. We further construct a large-scale training dataset with 16.000 image-question-an-swer triples based on real software repositories on GitHub. We focus on Java-based repositories and filter for project sizes that are small enough to fit on a single diagram with 4000x4000 pixels maximum in a readable manner. We ask questions based on 18 question templates. We show that a LoRA-based finetune of Qwen 2.5 VL 7B easily outperforms Qwen 3.5 27B, which is a recent and well-performing VLM in many other benchmarks.

mehr

PUF the Magic DRAmGON: Persistent Storage in Volatile Memory using Rowhammer PUF

Gelóczi, Emiliia; Heckel, Martin; Katzenbeisser, Stefan; Adamsky, Florian (2026)

31st European Symposium on Research in Computer Security.


Peer Reviewed
 

Physical Unclonable Functions (PUFs) exploit inherent manufacturing variations in electronic devices to create unique hardware fingerprints, which are typically used as a source of randomness for generating device-specific cryptographic keys. In this work, however, we explore the possibility of repurposing PUFs as a secure storage mechanism for pre-existing keys. First, we evaluate existing RH-PUFs, introduce five novel RH-PUF constructions, and compare all of them with respect to their suitability for cryptographic key generation. Second, we propose DRAmGON, a novel, unconventional PUF-based approach that enables the direct encoding of cryptographic keys into Rowhammer-susceptible DRAM, thereby allowing persistent data storage in volatile memory. Our experiments using FlippyRAM show that 81 % of the tested systems exhibit Rowhammer susceptibility, establishing RH-PUFs as a viable hardware-based security primitive. 

mehr

Modeling Legal Governance for Digital Service Platforms in Construction for existing Buildings

Weber, Beatrix; Zielke, Philipp; Kreißig, Johannes (2026)

ECPPM 2026 – European Conference on Product and Process Modelling.


 

The decision for construction works in existing buildings depends on technical feasibility, economic efficiency, and compliance with law. Decision-making can be supported by efficient digital services offering objective assessment criteria and recommending scalable and sustainable measures for new construction or renovation. This requires the digitalization of existing information such as floor and site plans as well as image files of the buildings making them available for digital services. The paper will demonstrate how intelligent tools for sustainable renovation may be offered legally market-ready by developing a Legal Governance Concept for sharing data and tools via con- struction service platforms. In this, Legal Governance depends on defining rights and roles as well as modeling compliant processes. The Legal Governance Concept was designed and implemented within the research project NaiS (Sustainable intelligent renovation measures).

mehr

PGP and S/MIME in the Age of Multi-Device Email Usage: “Admittedly, an outrageously confusing system.”

Schiller, Katharina; Herrmannsdörfer, Andreas; Benenson, Zinaida; Adamsky, Florian (2026)

Conference on Sociotechnical Cybersecurity and Privacy (SCP2026).


Peer Reviewed

Weekend headache in migraine – fact or fiction? An observational study from DMKG-app data

Ruscheweyh, Ruth; Dresler, Thomas; Goßrau, Gudrun; Kraya, Torsten; Neeb, Lars...

Cephalalgia 46 (6).
DOI: 10.1177/03331024261444664


Open Access
 

Background

It has long been proposed that some individuals with migraine are especially prone to experience headache on weekends, however, results have been contradictory. Electronic headache diaries offer the possibility to analyze this question more thoroughly in larger populations.

Methods

Two non-overlapping samples of individuals with migraine from the DMKG-App electronic headache diary were investigated. Cluster analysis and logistic regression were performed to study existence, prevalence and predictive factors of weekend headache.

Results

We included 1793 and 5840 patients with ≥35 headache day entries in the two samples (“registry sample” and “app-only sample”), respectively. In both samples, cluster analysis identified a cluster of patients with headache occurring preferably on weekends, accounting for 14–15% of all patients, and 18% of individuals with episodic migraine. Compared to the three other clusters identified (an early week cluster, a midweek cluster and a flat cluster without preference for a specific day), the weekend cluster was more frequent in working patients (p < 0.001, OR = 3.57 to 3.97) and in patients with lower headache frequencies (p < 0.001, OR = 0.86). A small association with older age (p < 0.001, OR = 1.01) was limited to the app-only sample. Longitudinal analysis showed that headache patterns of single patients were variable over time.

Conclusions

Results from two large samples corroborate that there is a subgroup of individuals with migraine prone to weekend headache. Association with working status supports the notion that release from stress could be a trigger factor in these patients, although change in sleep, caffeine and alcohol intake and other factors might also contribute.


mehr

Von der digitalen zur gesellschaftsideologischen Transformation: Carl Schmitt und die Technolibertarians.

Wagener, Andreas (2026)

Zeitschrift für Politik (ZfP), Zeitschrift für Politik (ZfP) 73,, Jg. 2/2026, S. 121 – 132, ISSN 0044-3360, DOI: 10.5771/0044-3360-2026-2-121 2026 (2), S. 121 - 132.
DOI: DOI: 10.5771/0044-3360-2026-2-121


 

Der Beitrag untersucht die gegenwärtige Renaissance des politischen Denkens Carl Schmitts im Umfeld US-amerikanischer Technolibertarians und analysiert deren Bedeutung für das Staats- und Politikverständnis während der zweiten Amtszeit Donald Trumps. Ausgangspunkt ist die Beobachtung, dass zentrale schmittsche Konzepte insbesondere das Freund-Feind-Kriterium, der Dezisionismus sowie der Begriff des Ausnahmezustands im Silicon Valley nicht lediglich rezipiert, sondern aktiv in eine technologiegetriebene Gesellschafts- und Herrschaftstheorie übersetzt werden. Anhand zentraler Akteure und Diskursstränge (u. a. Neoreactionary Movement, Dark Enlightenment, Network-State-Konzepte) zeigt der Beitrag, wie Schmitts Kritik am Liberalismus mit technolibertären Vorstellungen von Effizienz, Exit-Strategien und privater Souveränität verschränkt wird. Der Souverän erscheint dabei nicht mehr als staatliche Institution, sondern als Gründer, CEO oder Code-basierte Exekutivinstanz, während demokratische Verfahren durch marktbasierte Leistungs- und Outputlegitimation ersetzt werden. Der Artikel argumentiert, dass diese Transformation nicht nur eine ideologische Verschiebung innerhalb der Tech-Eliten darstellt, sondern auf eine tiefgreifende Reartikulation des Politischen zielt, in der Demokratie als Hindernis und Technologie als Medium autoritärer Ordnung fungiert. Abschließend wird gezeigt, dass die technolibertäre Fortschreibung Schmittscher Motive zu einem postdemokratischen, plutokratischen Politikmodell führt, das mit klassischen demokratischen Legitimitätsvorstellungen fundamental bricht.

mehr

KV-Cache-Quantisierung mit TurboQuant

Peinl, René (2026)

iX - Magazin für professionelle IT 2026 (06), S. 108.


 

Während die Quantisierung von Modellgewichten zum Sparen von Speicherplatz Normalität ist, war das starke Verkleinern des KV-Cache bisher eher exotisch. Ein Beitrag von Google hat das Thema nun in den Mainstream gerückt.

  • Der KV-Cache, der Berechnungen in LLMs beschleunigt, wird bei langen Kontexten zu einem Speicherfresser.
  • Während Quantisierung der Modellgewichte auf 4 Bit längst Standard ist, beschränken Inferenz-Engines wie vLLM den KV-Cache bislang meist auf 8 Bit, da Ausreißer in den Keys zu Genauigkeitsverlusten führen.
  • Die Forschung kennt mit KVQuant und KIVI bereits seit 2024 Verfahren, die den KV-Cache stark quantisieren. Google versucht nun dem eigenen Verfahren TurboQuant Bekanntheit zu verschaffen.
  • Parallel gewinnen hardwaregestützte 4-Bit-Gleitkommaformate wie NVFP4 und MXFP4 auf Blackwell- und AMD-Instinct-GPUs an Bedeutung.

  • mehr

    Hypertext as Method—Continued

    Bernstein, Mark; Blustein, James; Marshall, Cathy; Pisarski, Mariusz; Nürnberg, Peter...

    Proceedings of the 8th Workshop on Human Factors in Hypertext (HUMAN'25) 2026, 4.
    DOI: 10.1145/3759439.3773695


    Open Access
     

    At the HUMAN’25 workshop, four members of the hypertext research community reflected on the “hypertext as method” argument; specifically, the idea that hypertext should be understood as a method of inquiry rather than as merely a type of system. These community members presented position statements to address challenges stemming from this proposed method, including designing interfaces for LLMs, supporting annotation and note-taking as cognitive tools, evaluating AI as a collaborator in intellectual work, and applying hypertext analysis to historical information networks. These positions and the subsequent discussion contained several common themes, including a preference for augmentation over automation and concerns that generative AI may encourage users to disengage from critical thinking.

    mehr

    Proceedings of the 8th Workshop on Human Factors in Hypertext (HUMAN'25)

    Rubart, Jessica; Atzenbeck, Claus (2026)

    2025.
    DOI: 10.1145/3759439


    Open Access
    mehr

    Unknown Letters

    Zöllner, Michael (2026)

    Slanted Magazine #47—Digital Tools 2026 (47), 26.



    Build Drawbots and Learn to Code

    Zöllner, Michael; Baumgärtner, Felix (2026)

    Slanted Magazine #47—Digital Tools 2026 (47), 172.



    Unified-Memory-Workstations für lokale KI

    Peinl, René; Weber, Thomas (2026)

    iX - Magazin für professionelle IT 2026 (05), S. 72.


     

    Wer nicht in Server-GPUs investieren, aber trotzdem große Sprachmodelle selbst betreiben will, findet in Unified-Memory-Workstations eine bezahlbare Alternative. iX zeigt, wie sich Geräte aus dem AMD-, Nvidia- und Apple-Ökosystem schlagen.

  • Unified-Memory-Workstations bieten bezahlbare KI-Rechenleistung im kompakten Formfaktor.
  • Die Geräte eignen sich für LLMs der Größenklasse um 100 Milliarden Parameter mit Mixture-of-Experts-Architektur.
  • Wir vergleichen die Leistung von DGX Spark, Ryzen AI Max+ 395 und Apple M4 Max für dichte und dünn besetzte Modelle bei Prefill und Decode.

  • mehr

    A data-based certification platform for additively manufactured metal aircraft components: considering compliance with European law and potential business cases

    Schwarz, Hannes; Neumann, Gregor; Winkler, Kai; Rauschert, André; Weber, Beatrix...

    2026 (Volume 20), 49.
    DOI: 10.1007/s13272-026-00970-2


     

    Additive Manufacturing (AM) is increasingly adopted in the aerospace industry, as benefits like resource efficiency are complemented by distributed manufacturing possibilities that enhance supply chain resilience. However, replacing con ventional, established manufacturing methods with Laser Powder Bed Fusion in a highly regulated domain such as civil aviation comes at the price of increased requirements and thus costs for certification and quality assurance, which limit the attractiveness of AM. This paper presents a new data-based certification platform using Machine Learning (ML), a subdomain of artificial intelligence (AI), to enable faster and more cost-efficient design and manufacturing approval for additively manufactured aircraft components. The platform connects all relevant stakeholders and guides them through the certification process. As data sharing across different stakeholders and ML applications are central to the platform, a data governance concept aligned with European legislation, based on project-specific closed groups comprising direct supplier-customer relationships was developed. In addition, a compatible platform business model is described, presenting the roles of stakeholders and their respective value contributions. To this end, a deep dive into the landscape of current certification approaches and requirements was conducted and the impact of AM and the general use of AI on aircraft component certification was evaluated from technical, regulatory, legal, and economic perspectives

    mehr

    AI that drives impact. KI in Medien und Verlagswesen.

    Wagener, Andreas (2026)

    AI that drives impact. KI in Medien und Verlagswesen. ACM: Wiesbaden/Online, 28.04.2026 .


    mehr

    Implementing Lean Six Sigma Methodologies in an Industry 4.0 Manufacturing Setup: A Case Study

    Cisneros Saldana, Shantall Marucia; Markus, Heike (2026)

    Proceedings of the Conference on Production Systems and Logistics: CPSL 2026.


    Open Access Peer Reviewed
     

    The integration of Lean Six Sigma (LSS) principles with Industry 4.0 technologies offers an effective way to improve operational performance in modern manufacturing environments. This case study presents the systematic application of LSS within an Industry 4.0 manufacturing laboratory, employing the DMAIC (Define, Measure, Analyze, Improve, Control) framework to identify and eliminate inefficiencies. In a context dominated by automation, cyber-physical systems, and data-driven decision making, the study addresses persistent challenges including inaccurate sensor readings, limited user knowledge of advanced systems, and suboptimal material storage configurations. Through a combination of statistical analysis, root-cause identification, and iterative process redesign, the intervention resulted in measurable improvements in process reliability, user experience, and overall workflow efficiency. The findings highlight how LSS can serve as an effective bridge between traditional continuous-improvement methodologies and digitalized manufacturing operations. Moreover, the outcomes position the integration of LSS as a foundational enabler for Industry 5.0, where human-centricity, resilience, and sustainability will increasingly shape manufacturing system design.

    mehr

    Lending a Hand: The Effectiveness of Support Systems in Assisting Users to Detect Phishing Attacks

    Schiller, Katharina; Scheidt, Jörg; Adamsky, Florian; Benenson, Zinaida (2026)

    ACM CHI (Conference on Human Factors in Computing Systems).


    Peer Reviewed
     

    We investigate the effectiveness of anti-phishing support systems through a quantitative study involving 453 participants. To this end, we developed a tool that allows participants to immerse themselves in a realistic setting, tasked with classifying emails as either phishing or legitimate, while being assisted by support systems. Despite the prevalence of support systems in webmailers and email clients, our results indicate no significant difference in correctly assessing emails of varying difficulty between these systems and the control group. We found a minor negative effect of the support system that uses tooltips compared to other support systems. In the subsequent survey, we found that the support systems are appreciated and considered helpful by users, as supported by the results of the UEQ-S, even if they have no observable effect. Email context, such as the contact list, as well as hovering over the links, had stronger effects on the classification than the tested support systems. 

    mehr

    Was bedeutet das Social-Media-Verbot in Australien finanziell für Meta & Co?

    Wagener, Andreas (2026)

    Nerdwärts https://nerdwaerts.de/2026/03/social-media-verbot-weil-die-eltern-unfaehig-sind-und-ueberhaupt-warum-eigentlich-nur-fuer-minderjaehrige/.


    Open Access
     

    Täglich hört man von der angeblich unausweichlichen Notwendigkeit eines Social-Media-Verbotes für Minderjährige. Das scheint weitgehender gesellschaftlicher Konsens zu sein. Einige wichtige Fragen werden dazu aber nicht gestellt: Was ist mit den Eltern?  Und warum eigentlich nur für Minderjährige?

    mehr

    A Lightweight Open-Source Framework for Packaging Visualization and Data Automation

    Markus, Heike; Acharya, Sampat; Cisneros Saldana, Shantall Marucia (2026)

    Procedia Computer Science 277, 2026, 1889-1898.


    Open Access Peer Reviewed
     

    This paper presents a low-complexity, open-source platform designed to empower small and medium-sized enterprises (SMEs) in the premium business to business (B2B) packaging industry with advanced digital capabilities for product personalization and rapid design visualization. Addressing the sector’s persistent barriers such as limited IT resources, manual workflows, and lack of structured supplier data access, the proposed system integrates dynamic web scraping for automated supplier data acquisition with real-time image processing for printable area detection on packaging components, particularly bottles. Leveraging open-source tools like Beautiful Soup, OpenCV, and Shapely, the platform eliminates reliance on time-intensive manual integration and supports agile, data-driven design workflows. The development process is guided by human-centered design principles to ensure usability and alignment with SME operational realities. Results demonstrate that this approach significantly streamlines catalog management and design preparation, offering a scalable pathway for SMEs to achieve digital transformation and maintain competitive differentiation in an increasingly digitalized packaging market.

    mehr

    Forschung und Entwicklung

    Hochschule für Angewandte Wissenschaften Hof

    Alfons-Goppel-Platz 1
    95028 Hof

    T +49 9281 409 - 4091
    gerald.schmola[at]hof-university.de

    Betreuung der Publikationsseiten

    Daniela Stock

    T 09281 409 – 3042
    daniela.stock.2[at]hof-university.de