Responsive image





Reliable DRAM Bank Addressing Function Recovery in Asymmetric Channel Setups

Fiedler, Carina; Rauscher, Fabian; Pfeifenberger, Markus; Heckel, Martin...

34rd Network and Distributed System Security Symposium (NDSS).


Open Access Peer Reviewed
 

Rowhammer attacks and DRAM side channel attacks require addresses that map to the same DRAM bank. Such addresses can be found using undocumented, reverse-engineered DRAM addressing functions. A recent large-scale Rowhammer study showed that existing reverse-engineering tools fail in about 50 % of real-world setups. These tools assume conventional setups with a power-of-two number of identical power-of-twosized DIMMs (PTID) but fail on asymmetric non-PTID setups.

In this paper, we discover that many non-PTID setups follow previously unknown conditional DRAM mappings, where different parts of memory obey different locally valid linear function sets. We present DREAMS, the first approach to recover DRAM bank addressing functions on non-PTID setups with such conditionally valid function sets. The key novelty is to model asymmetric mappings together with the conditions that select each function set, instead of assuming one globally valid linear function set. DREAMS detects bit-inconsistent behavior, i.e., cases where the influence of an address bit is not consistent across the address space, and uses this signal to infer whether the system is PTID or non-PTID. For non-PTID setups, DREAMS recovers the region- and channel-specific function sets and their selection conditions, and verifies the resulting conditional mapping entirely in software. For overlapping functions, DREAMS uses SAT constraints to model interactions between multiple candidate bits simultaneously, allowing the analytical recovery pipeline to handle functions that share bits. We evaluate DREAMS on 19 non-PTID DIMM configurations across 6 Intel and AMD DDR4/DDR5 systems, recovering mappings with up to 3 conditional function sets selected by address cutoffs and channel functions. We show that these reverse-engineered functions provide security-critical DRAM-bank information, e.g., for Rowhammer attacks, DRAM isolation mechanisms, and side-channel attacks. 

more

Side Attack: Off-Path Website Fingerprinting via Cross-Circuit Interference in Tor

Gad, Mohamed Farrag; Pahl, Sebastian; Gast, Stefan; Gruss, Daniel; Adamsky, Florian (2026)

Workshop on Privacy in the Electronic Society (WPES).


Open Access Peer Reviewed
 

Tor is a privacy-enhancing technology that enables anonymous communication by leveraging onion routing. A client chooses a path of three Tor relays, known as a circuit, and encrypts the traffic for each relay in reverse order, sending it to the first relay. Each relay knows only its predecessor and successor, unaware of the entire circuit, thus enabling anonymous communication. Tor builds the circuit telescopically, i. e., the first relay establishes a TCP connection to the second, and the second establishes a TCP connection to the third. However, Tor allows cross-circuit interference (CCI), meaning that if two circuits share two consecutive relays, data transmitted over the same TCP connection interferes with each other.

In this paper, we demonstrate that CCI can be exploited as a side channel to conduct an off-path (non-MitM) website fingerprinting attack. An attacker builds a two-hop circuit between a shared link and measures the Round Trip Time (RTT), while the victim browses on the same link, visiting different websites. That creates a bottleneck, which reveals the website the victim was accessing. We conducted an open-world experiment and show that an attacker can distinguish between monitored and unmonitored websites, achieving an 𝐹1-score of 94.2 % in a single-class setup and 63.2 % in a multi-class setup, where we differentiate between all websites and unmonitored ones. Additionally, we conducted a closed-world experiment with different exit relays on the Tor network. We demonstrate that an attacker can achieve an 𝐹1-score of up to 66.7 % when distinguishing the top 95 websites using only 150 traces per website. We also show that the security settings in the Tor browser can be an effective countermeasure when set to safest, reducing the 𝐹1-score to 1.2 %, but making web surfing unusable. 

more

Unlocking UML Class Diagram Understanding in Vision Language Models

Naboichenko, Artem; Peinl, René (2026)

11th Future Technologies Conference (FTC 2026), 15-16 October 2026, Berlin, Germany 2026.


Open Access Peer Reviewed
 

Although Vision Language Models (VLMs) have seen tremendous progress across all kinds of use cases, they still fall behind in answering questions regarding diagrams compared to photos. Although progress has been made in the area of bar charts, line charts and similar diagrams, there is still few research concerned with other types of diagrams, e.g. in the computer science domain. We identified a gap in research on visual question answering on UML class diagrams. Our objective is to fill the gap by analyzing the performance of popular open-weight VLMs on a self-constructed benchmark for visual question answering based on UML class diagrams which is both challenging and manageable. We further construct a large-scale training dataset with 16.000 image-question-an-swer triples based on real software repositories on GitHub. We focus on Java-based repositories and filter for project sizes that are small enough to fit on a single diagram with 4000x4000 pixels maximum in a readable manner. We ask questions based on 18 question templates. We show that a LoRA-based finetune of Qwen 2.5 VL 7B easily outperforms Qwen 3.5 27B, which is a recent and well-performing VLM in many other benchmarks.

more

PUF the Magic DRAmGON: Persistent Storage in Volatile Memory using Rowhammer PUF

Gelóczi, Emiliia; Heckel, Martin; Katzenbeisser, Stefan; Adamsky, Florian (2026)

31st European Symposium on Research in Computer Security.


Peer Reviewed
 

Physical Unclonable Functions (PUFs) exploit inherent manufacturing variations in electronic devices to create unique hardware fingerprints, which are typically used as a source of randomness for generating device-specific cryptographic keys. In this work, however, we explore the possibility of repurposing PUFs as a secure storage mechanism for pre-existing keys. First, we evaluate existing RH-PUFs, introduce five novel RH-PUF constructions, and compare all of them with respect to their suitability for cryptographic key generation. Second, we propose DRAmGON, a novel, unconventional PUF-based approach that enables the direct encoding of cryptographic keys into Rowhammer-susceptible DRAM, thereby allowing persistent data storage in volatile memory. Our experiments using FlippyRAM show that 81 % of the tested systems exhibit Rowhammer susceptibility, establishing RH-PUFs as a viable hardware-based security primitive. 

more

Spatially Arranging is Knowing: Spatial Hypertext as Method for Digital Folkloristics

Roßner, Lisa; Atzenbeck, Claus; Nürnberg, Peter (2026)

, 163-169.
DOI: 3800935.3830886


Open Access Peer Reviewed
more

PGP and S/MIME in the Age of Multi-Device Email Usage: “Admittedly, an outrageously confusing system.”

Schiller, Katharina; Herrmannsdörfer, Andreas; Benenson, Zinaida; Adamsky, Florian (2026)

Conference on Sociotechnical Cybersecurity and Privacy (SCP2026).


Peer Reviewed

Reimagining Healthcare Organizations: Integrating Digital Competencies into Structural Change

Stock, Nele; Wolff, Dietmar; Neeb, Désirée; Schmoll, Barbara (2026)

International Journal of Information Systems and Project Management (IJISPM), Special Issue „Innovative Information Systems and Project Management for Healthcare Operations and Supply Chain Management 2026.



Perspectives and Applications of Technical Textiles: Composites Based on High-Performance Textile Structures

Hahn, Lars (2026)

Vortrag auf der 5th INTERNATIONAL TEXTILE ONLINE WEEK, online.


more

Efficiency enhancement of complex thermal energy storages under multiple transient loads

Fick, Robin; Honke, Robert; Brüggemann, Dieter (2026)

Journal of Energy Storage 175, 123110.
DOI: 10.1016/j.est.2026.123110


Open Access Peer Reviewed
 

This paper presents a numerical investigation and performance optimization of a large-scale, stratified thermal energy storage system integrated into a public research building. The system combines multiple renewable heat sources — including solar thermal collectors and a photovoltaic-powered power-to-heat unit — with various thermal heating loads. The methodology integrates both simultaneous and sequential building energy demand and generation modeling with transient CFD simulations in OpenFOAM® to analyze internal mixing and thermocline dynamics. A generally applicable performance evaluation is based on the internal temperature distribution, the temporal evolution of temperature gradients, Reynolds and Richardson number under various operating scenarios. Results confirm that carefully matched inlet temperatures and injection heights significantly enhance stratification stability. The best performance was observed during summer operation with reduced charging temperatures to better fit stratification levels while maintaining thermal power, and during winter with increased temperatures at reduced volumetric flow rates. These adjustments result in thermoclines up to 22% thinner during summer and up to 42% thinner during winter compared to sequential operation.

more

Weekend headache in migraine – fact or fiction? An observational study from DMKG-app data

Ruscheweyh, Ruth; Dresler, Thomas; Goßrau, Gudrun; Kraya, Torsten; Neeb, Lars...

Cephalalgia 46 (6).
DOI: 10.1177/03331024261444664


Open Access
 

Background

It has long been proposed that some individuals with migraine are especially prone to experience headache on weekends, however, results have been contradictory. Electronic headache diaries offer the possibility to analyze this question more thoroughly in larger populations.

Methods

Two non-overlapping samples of individuals with migraine from the DMKG-App electronic headache diary were investigated. Cluster analysis and logistic regression were performed to study existence, prevalence and predictive factors of weekend headache.

Results

We included 1793 and 5840 patients with ≥35 headache day entries in the two samples (“registry sample” and “app-only sample”), respectively. In both samples, cluster analysis identified a cluster of patients with headache occurring preferably on weekends, accounting for 14–15% of all patients, and 18% of individuals with episodic migraine. Compared to the three other clusters identified (an early week cluster, a midweek cluster and a flat cluster without preference for a specific day), the weekend cluster was more frequent in working patients (p < 0.001, OR = 3.57 to 3.97) and in patients with lower headache frequencies (p < 0.001, OR = 0.86). A small association with older age (p < 0.001, OR = 1.01) was limited to the app-only sample. Longitudinal analysis showed that headache patterns of single patients were variable over time.

Conclusions

Results from two large samples corroborate that there is a subgroup of individuals with migraine prone to weekend headache. Association with working status supports the notion that release from stress could be a trigger factor in these patients, although change in sleep, caffeine and alcohol intake and other factors might also contribute.


more

MANTA: A Low-Cost open-source 3D-Printed Vascular Phantom for Simulation-Based Embolization Training

Misbahuddin-Leis, Mohammed; Ankolvi, Muzaffer; Göhring, René ; Rausch, Thomas...

European Conference on Embolotherapy, Valencia, Spain, June 17-20 2026.



Von der digitalen zur gesellschaftsideologischen Transformation: Carl Schmitt und die Technolibertarians.

Wagener, Andreas (2026)

Zeitschrift für Politik (ZfP), Zeitschrift für Politik (ZfP) 73,, Jg. 2/2026, S. 121 – 132, ISSN 0044-3360, DOI: 10.5771/0044-3360-2026-2-121 2026 (2), S. 121 - 132.
DOI: DOI: 10.5771/0044-3360-2026-2-121


 

Der Beitrag untersucht die gegenwärtige Renaissance des politischen Denkens Carl Schmitts im Umfeld US-amerikanischer Technolibertarians und analysiert deren Bedeutung für das Staats- und Politikverständnis während der zweiten Amtszeit Donald Trumps. Ausgangspunkt ist die Beobachtung, dass zentrale schmittsche Konzepte insbesondere das Freund-Feind-Kriterium, der Dezisionismus sowie der Begriff des Ausnahmezustands im Silicon Valley nicht lediglich rezipiert, sondern aktiv in eine technologiegetriebene Gesellschafts- und Herrschaftstheorie übersetzt werden. Anhand zentraler Akteure und Diskursstränge (u. a. Neoreactionary Movement, Dark Enlightenment, Network-State-Konzepte) zeigt der Beitrag, wie Schmitts Kritik am Liberalismus mit technolibertären Vorstellungen von Effizienz, Exit-Strategien und privater Souveränität verschränkt wird. Der Souverän erscheint dabei nicht mehr als staatliche Institution, sondern als Gründer, CEO oder Code-basierte Exekutivinstanz, während demokratische Verfahren durch marktbasierte Leistungs- und Outputlegitimation ersetzt werden. Der Artikel argumentiert, dass diese Transformation nicht nur eine ideologische Verschiebung innerhalb der Tech-Eliten darstellt, sondern auf eine tiefgreifende Reartikulation des Politischen zielt, in der Demokratie als Hindernis und Technologie als Medium autoritärer Ordnung fungiert. Abschließend wird gezeigt, dass die technolibertäre Fortschreibung Schmittscher Motive zu einem postdemokratischen, plutokratischen Politikmodell führt, das mit klassischen demokratischen Legitimitätsvorstellungen fundamental bricht.

more

Client-Side Mitigation of Remote Latency Side-Channel Attacks

Gast, Stefan; Franza, Simone; Heckel, Martin; Juffinger, Jonas; Gruss, Daniel...

23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA '26).


Peer Reviewed
 

Remote latency side channels reveal sensitive information by only observing latency variations in the attacker’s traffic with the victim. While these attacks are easy to mount and scale, there is no practical defense. Considering the more powerful attacker-in-the-middle scenarios, available mitigations require the cooperation of all communication partners for protection, and cause prohibitive overheads.

In this paper, we propose AckwardDelay, a new unilateral, purely client-side, and lightweight defense against remote latency side channels. In detail, we piece-wise apply constant-time principles on the latency side channel and computationally show that a fully remote attacker requires more than 250 samples to reduce the initial search space to below 1% with our recommended parameters, even in a scenario favoring the attacker. Based on our proof-of-concept AckwardDelay implementation with less than 1000 lines of code on Linux, we demonstrate that the accuracy of website- and video-fingerprinting attacks is reduced to random guessing in practice. With an increase of only 5.55% on website-loading times and a reduction of only 0.51% in transfer rates, we conclude that AckwardDelay is a practical, lightweight, and effective mitigation applicable to the vast number of client systems such as smart phones, tablets, and laptops.

more

KV-Cache-Quantisierung mit TurboQuant

Peinl, René (2026)

iX - Magazin für professionelle IT 2026 (06), S. 108.


 

Während die Quantisierung von Modellgewichten zum Sparen von Speicherplatz Normalität ist, war das starke Verkleinern des KV-Cache bisher eher exotisch. Ein Beitrag von Google hat das Thema nun in den Mainstream gerückt.

  • Der KV-Cache, der Berechnungen in LLMs beschleunigt, wird bei langen Kontexten zu einem Speicherfresser.
  • Während Quantisierung der Modellgewichte auf 4 Bit längst Standard ist, beschränken Inferenz-Engines wie vLLM den KV-Cache bislang meist auf 8 Bit, da Ausreißer in den Keys zu Genauigkeitsverlusten führen.
  • Die Forschung kennt mit KVQuant und KIVI bereits seit 2024 Verfahren, die den KV-Cache stark quantisieren. Google versucht nun dem eigenen Verfahren TurboQuant Bekanntheit zu verschaffen.
  • Parallel gewinnen hardwaregestützte 4-Bit-Gleitkommaformate wie NVFP4 und MXFP4 auf Blackwell- und AMD-Instinct-GPUs an Bedeutung.

  • more

    Hypertext as Method—Continued

    Bernstein, Mark; Blustein, James; Marshall, Cathy; Pisarski, Mariusz; Nürnberg, Peter...

    Proceedings of the 8th Workshop on Human Factors in Hypertext (HUMAN'25) 2026, 4.
    DOI: 10.1145/3759439.3773695


    Open Access
     

    At the HUMAN’25 workshop, four members of the hypertext research community reflected on the “hypertext as method” argument; specifically, the idea that hypertext should be understood as a method of inquiry rather than as merely a type of system. These community members presented position statements to address challenges stemming from this proposed method, including designing interfaces for LLMs, supporting annotation and note-taking as cognitive tools, evaluating AI as a collaborator in intellectual work, and applying hypertext analysis to historical information networks. These positions and the subsequent discussion contained several common themes, including a preference for augmentation over automation and concerns that generative AI may encourage users to disengage from critical thinking.

    more

    Proceedings of the 8th Workshop on Human Factors in Hypertext (HUMAN'25)

    Rubart, Jessica; Atzenbeck, Claus (2026)

    2025.
    DOI: 10.1145/3759439


    Open Access
    more

    Revisiting 1998 torque data: a machine learning analysis of time series data for tapping experiments

    Al Najjar, Alaa; Havaldar, Nakul; Plenk, Valentin; Linß, Marco (2026)

    2026 IEEE International Conference on Advanced Systems and Emergent Technologies (ic_aset) 2026.
    DOI: 10.1109/IC_ASET69920.2026.11502539


    Peer Reviewed
     

    This paper addresses the challenge of real-time tool condition monitoring in tapping processes using machine learning techniques, with a focus on cross-material generalization and robust fault detection. The study leverages a historical dataset from 1998, comprising 2,195 tapping experiments on two steel alloys - 16 MnCr 5 and 42 CrMo 4 - monitoring torque (Mz) signals to predict binary quality outcomes (good/bad) based on defined quality criteria. To overcome limitations in prior work, the authors introduce a feature extraction method that captures both amplitude and duration characteristics across distinct phases of the torque signal,. The evaluation framework includes increasingly challenging train/test splits: random, run-wise holdout, and cross-material (training on 16 MnCr 5, testing on 42 CrMo 4), enabling assessment of real-world generalizability.

    Multiple machine learning models are tested using both raw time-series data (after cleaning and normalization) and engineered features. Results show Matthews Correlation Coefficients (MCC) of 0.40 - 0.41 under cross-material testing-indicating moderate but meaningful generalization across materials with different mechanical properties. This performance level suggests that fundamental physical regularities in successful tapping produce consistent torque signatures, enabling transferable detection of anomalies without retraining. Findings support the feasibility of plug-and-play monitoring systems in agile manufacturing environments, where minimal setup and broad applicability are essential.

    Download-Link: Revisiting 1998 Torque Data: A Machine Learning Analysis of Time Series Data for Tapping Experiments

    more

    Veränderung als Chance: Changemanagement für die Pflegepraxis

    Neeb, Désirée; Großmann, Yvonne (2026)

    because we care, Augsburg.



    Pflege neu denken - Digitale Tools und KI als Motor für Innovationen

    Neeb, Désirée; Großmann, Yvonne (2026)

    Pflegekonferenz Fürth, Fürth.



    Unknown Letters

    Zöllner, Michael (2026)

    Slanted Magazine #47—Digital Tools 2026 (47), 26.



    Forschung und Entwicklung

    Hochschule für Angewandte Wissenschaften Hof

    Alfons-Goppel-Platz 1
    95028 Hof

    T +49 9281 409 - 4091
    gerald.schmola[at]hof-university.de

    Support of publications

    Daniela Stock

    T 09281 409 – 3042
    daniela.stock.2[at]hof-university.de