Research agenda
Building trust below the application boundary.
We study security mechanisms across hardware, privileged software, trusted runtimes and applications—with particular attention to what remains trustworthy when infrastructure is compromised.
Primary areas
A systems view of computational trust.
Each area is distinct, but the research questions are deliberately connected.
Trusted Execution Environments
Isolated execution environments that protect code and data from privileged software.
Confidential Computing
Protecting data in use through hardware-backed isolation and verifiable workloads.
Hardware Security
Security properties rooted in processors, memory systems and hardware architectures.
Secure Systems
System software designed for strong isolation, minimal trust and measurable assurance.
Confidential AI
Protecting models, prompts, training data and inference on trusted accelerators.
Side-Channel Security
Understanding information leakage across shared hardware and software resources.
RESEARCH PHILOSOPHY
Precise threat models.
Explicit assumptions.
Evidence over appearance.
We aim to make security claims understandable, testable and bounded by the systems that actually implement them.
