Discovery with impact

Research

Explore the center's interdisciplinary work in security, privacy and technology policy.

Faculty members affiliated with the Center are interested in a wide range of security and privacy research areas, including, but not limited to:
  • Systems Security
  • Software Security
  • Network Security
  • Mobile and IoT Security
  • ML/AI Security
  • Autonomous Vehicles Security
  • Privacy
  • Usable Security
  • Cybersecurity Law
  • Cybersecurity Risk Management

Characterizing Smart Home Security & Automation

Lead researcher: Dr. Adwait Nadkarni — Secure Platforms Lab

Field: Mobile and IoT Security

Explores security challenges in home automation platforms like SmartThings and Nest, focusing on user-driven routines, device constraints, and runtime limitations to build robust security frameworks for the evolving smart home ecosystem.

Project details

Evaluating the Soundness of Android Security Tools

Lead researcher: Dr. Adwait Nadkarni — Secure Platforms Lab

Field: Software Security

Introduces μSE (Mutation-based Soundness Evaluation), a novel method to systematically assess and improve the reliability of static analysis tools used in Android app security.

Project details

Computing with Time: Microarchitectural Weird Machines

Lead researcher: Dr. Dmitry Evtyushkin – William & Mary

Field: Systems Security

Introducing a new form of computation using side-channel effects inside CPUs. This project demonstrates how microarchitectural 'weird machines' (μWMs) can be used to perform computations through timing-based side effects, evade reverse engineering, and even execute obfuscated malware payloads through speculative execution and transactional memory.

Project details

Exploring Branch Predictors for Constructing Transient Execution Trojans

Lead researcher: Dr. Dmitry Evtyushkin, Kenneth Koltermann, Tao Zhang

Field: Systems Security

This research introduces 'transient trojans'—malicious code hidden within transient execution that evades traditional analysis and exploits modern CPU branch predictors. The team reveals new attack vectors by reverse-engineering predictors and building practical, stealthy trojans on current systems.

Project details

Technology Integration in Higher Education and Student Privacy

Lead researcher: Dr. Iria Giuffrida – William & Mary Law School

Field: Cybersecurity Law

Examines how technology integration in higher education raises overlooked student privacy concerns beyond learning environments, particularly at the institutional level. A comparative analysis of UK and US legal frameworks highlights gaps in privacy protections during mental health crises and calls for interdisciplinary awareness of regulatory risks.

Project details

STBPU: A Reasonably Secure Branch Prediction Unit

Lead researcher: Dr. Dmitry Evtyushkin, Tao Zhang, Timothy Lesch, Kenneth Koltermann

Field: Systems Security

STBPU is a secure BPU design that mitigates collision-based transient execution attacks and side channels with minimal performance overhead. It isolates software entities through custom BPU data representations and actively thwarts brute-force prediction collisions.

Project details

SoK: Transient Execution Attacks

Lead researcher: Dr. Dmitry Evtyushkin, Emanuele Vannacci, et al.

Field: Systems Security

A comprehensive systematization of transient execution attacks, including Spectre and Meltdown variants. This work analyzes their root causes, classifications, and the effectiveness of proposed mitigations across hardware and software layers.

Project details

Smart Cities and Sustainability: A New Challenge to Accountability?

Lead researcher: Dr. Iria Giuffrida – William & Mary Law School

Field: Cybersecurity Risk Management

Analyzes the governance and accountability risks associated with smart city technologies. This work highlights how data collection, privatized infrastructure, and citizen datafication raise complex questions about responsibility, transparency, and privacy in the pursuit of urban sustainability.

Project details

Keeping AI Under Observation: Anticipated Impacts on Physicians' Standard of Care

Lead researcher: Dr. Iria Giuffrida, Taylor Treece

Field: Cybersecurity Risk Management

Examines how the integration of AI tools in healthcare may shift the legal standards for physician malpractice. This essay explores the evolving landscape of liability and professional responsibility as hospitals adopt AI-assisted decision-making.

Project details

Bento: Safely Bringing Network Function Virtualization to Tor

Lead researcher: Dr. Stephen Herwig, Michael Reininger, Arushi Arora, etc.

Field: Network Security

Introduces Bento, a system that enables programmable network functions within the Tor network without modifying its core. Bento improves Tor’s anonymity, performance, and resilience by securely running custom functions on willing routers using Network Function Virtualization.

Project details

Achieving Keyless CDNs with Conclaves

Lead researcher: Dr. Stephen Herwig, Dr. Christina Garman, Dr. Dave Levin

Field: Network Security

Presents Phoenix, a keyless CDN architecture that uses secure enclaves (Intel SGX) to protect private keys and deliver CDN services without trusting edge servers. The system introduces 'conclaves'—containers of enclaves—for scalable, secure deployment of multi-process applications.

Project details

Measurement and Analysis of Hajime, a Peer-to-peer IoT Botnet

Lead researcher: Dr. Stephen Herwig, Katura Harvey, George Hughey, Richard Roberts, Dr. Dave Levin

Field: Mobile and IoT Security

Analyzes Hajime, a decentralized IoT botnet using peer-to-peer infrastructure for command and control. This study provides insights into device vulnerabilities, geographic infection trends, and evolving attack techniques through large-scale measurement and traffic analysis.

Project details

FABA: An Algorithm for Fast Aggregation against Byzantine Attacks in Distributed Neural Networks

Lead researcher: Dr. Qun Li, Qi Xia, Zeyi Tao, Zijiang Hao

Field: ML/AI Security

Proposes FABA, an efficient aggregation algorithm that defends against Byzantine attacks in distributed deep learning by filtering out poisoned gradients. The approach ensures stability and convergence while maintaining model performance under adversarial conditions.

Project details