Discovery with impact
Research
Explore the center's interdisciplinary work in security, privacy and technology policy.
- Systems Security
- Software Security
- Network Security
- Mobile and IoT Security
- ML/AI Security
- Autonomous Vehicles Security
- Privacy
- Usable Security
- Cybersecurity Law
- Cybersecurity Risk Management
Characterizing Smart Home Security & Automation
Lead researcher: Dr. Adwait Nadkarni — Secure Platforms Lab
Field: Mobile and IoT Security
Explores security challenges in home automation platforms like SmartThings and Nest, focusing on user-driven routines, device constraints, and runtime limitations to build robust security frameworks for the evolving smart home ecosystem.
Project details
Evaluating the Soundness of Android Security Tools
Lead researcher: Dr. Adwait Nadkarni — Secure Platforms Lab
Field: Software Security
Introduces μSE (Mutation-based Soundness Evaluation), a novel method to systematically assess and improve the reliability of static analysis tools used in Android app security.
Project details
Computing with Time: Microarchitectural Weird Machines
Lead researcher: Dr. Dmitry Evtyushkin – William & Mary
Field: Systems Security
Introducing a new form of computation using side-channel effects inside CPUs. This project demonstrates how microarchitectural 'weird machines' (μWMs) can be used to perform computations through timing-based side effects, evade reverse engineering, and even execute obfuscated malware payloads through speculative execution and transactional memory.
Project details
Exploring Branch Predictors for Constructing Transient Execution Trojans
Lead researcher: Dr. Dmitry Evtyushkin, Kenneth Koltermann, Tao Zhang
Field: Systems Security
This research introduces 'transient trojans'—malicious code hidden within transient execution that evades traditional analysis and exploits modern CPU branch predictors. The team reveals new attack vectors by reverse-engineering predictors and building practical, stealthy trojans on current systems.
Project details
Technology Integration in Higher Education and Student Privacy
Lead researcher: Dr. Iria Giuffrida – William & Mary Law School
Field: Cybersecurity Law
Examines how technology integration in higher education raises overlooked student privacy concerns beyond learning environments, particularly at the institutional level. A comparative analysis of UK and US legal frameworks highlights gaps in privacy protections during mental health crises and calls for interdisciplinary awareness of regulatory risks.
Project details
STBPU: A Reasonably Secure Branch Prediction Unit
Lead researcher: Dr. Dmitry Evtyushkin, Tao Zhang, Timothy Lesch, Kenneth Koltermann
Field: Systems Security
STBPU is a secure BPU design that mitigates collision-based transient execution attacks and side channels with minimal performance overhead. It isolates software entities through custom BPU data representations and actively thwarts brute-force prediction collisions.
Project details
SoK: Transient Execution Attacks
Lead researcher: Dr. Dmitry Evtyushkin, Emanuele Vannacci, et al.
Field: Systems Security
A comprehensive systematization of transient execution attacks, including Spectre and Meltdown variants. This work analyzes their root causes, classifications, and the effectiveness of proposed mitigations across hardware and software layers.
Project details
Smart Cities and Sustainability: A New Challenge to Accountability?
Lead researcher: Dr. Iria Giuffrida – William & Mary Law School
Field: Cybersecurity Risk Management
Analyzes the governance and accountability risks associated with smart city technologies. This work highlights how data collection, privatized infrastructure, and citizen datafication raise complex questions about responsibility, transparency, and privacy in the pursuit of urban sustainability.
Project details
Keeping AI Under Observation: Anticipated Impacts on Physicians' Standard of Care
Lead researcher: Dr. Iria Giuffrida, Taylor Treece
Field: Cybersecurity Risk Management
Examines how the integration of AI tools in healthcare may shift the legal standards for physician malpractice. This essay explores the evolving landscape of liability and professional responsibility as hospitals adopt AI-assisted decision-making.
Project details
Bento: Safely Bringing Network Function Virtualization to Tor
Lead researcher: Dr. Stephen Herwig, Michael Reininger, Arushi Arora, etc.
Field: Network Security
Introduces Bento, a system that enables programmable network functions within the Tor network without modifying its core. Bento improves Tor’s anonymity, performance, and resilience by securely running custom functions on willing routers using Network Function Virtualization.
Project details
Achieving Keyless CDNs with Conclaves
Lead researcher: Dr. Stephen Herwig, Dr. Christina Garman, Dr. Dave Levin
Field: Network Security
Presents Phoenix, a keyless CDN architecture that uses secure enclaves (Intel SGX) to protect private keys and deliver CDN services without trusting edge servers. The system introduces 'conclaves'—containers of enclaves—for scalable, secure deployment of multi-process applications.
Project details
Measurement and Analysis of Hajime, a Peer-to-peer IoT Botnet
Lead researcher: Dr. Stephen Herwig, Katura Harvey, George Hughey, Richard Roberts, Dr. Dave Levin
Field: Mobile and IoT Security
Analyzes Hajime, a decentralized IoT botnet using peer-to-peer infrastructure for command and control. This study provides insights into device vulnerabilities, geographic infection trends, and evolving attack techniques through large-scale measurement and traffic analysis.
Project details
FABA: An Algorithm for Fast Aggregation against Byzantine Attacks in Distributed Neural Networks
Lead researcher: Dr. Qun Li, Qi Xia, Zeyi Tao, Zijiang Hao
Field: ML/AI Security
Proposes FABA, an efficient aggregation algorithm that defends against Byzantine attacks in distributed deep learning by filtering out poisoned gradients. The approach ensures stability and convergence while maintaining model performance under adversarial conditions.
Project details