Hi, I’m a PhD student at Saarland University working at CISPA. My research topics are Rowhammer, side channels and transient execution. I spent my free time either playing Volleyball or hacking on my GNU/Linux setup. For the latter checkout the blog on my page.
Publications
2026
StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU’s Stack Engine
USENIX Security
Baltimore, MD, USA, August 12-14, 2026
InstrSem: Automatically and Generically Inferring Semantics of (Undocumented) CPU Instructions
USENIX Security
Baltimore, Maryland, USA, August 12-14, 2026
2025
ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUs
Fabian Thomas,
Michael Torres,
Daniel Moghimi, Michael Schwarz
CCS
Taipei, Taiwan, October 13-17, 2025
RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs
Fabian Thomas,
Eric García Arribas, Lorenz Hetterich, Daniel Weber, Lukas Gerlach, Ruiyi Zhang, Michael Schwarz
CCS
Taipei, Taiwan, October 13-17, 2025
Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage
Mikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz, Leon Trampert, Lukas Gerlach, Michael Schwarz
S&P
San Francisco, California, USA, May 12-15, 2025
ShadowLoad: Injecting State into Hardware Prefetchers
Lorenz Hetterich, Fabian Thomas, Lukas Gerlach, Ruiyi Zhang,
Nils Bernsdorf, Eduard Ebert, Michael Schwarz
ASPLOS
Rotterdam, Netherlands, March 30 - April 13, 2025
2023
A Rowhammer Reproduction Study Using the Blacksmith Fuzzer
ESORICS
The Hague, The Netherlands, September 25-29, 2023
Indirect Meltdown: Building Novel Side-Channel Attacks from Transient Execution Attacks
ESORICS
The Hague, The Netherlands, September 25-29, 2023
Reviving Meltdown 3a
ESORICS
The Hague, The Netherlands, September 25-29, 2023
Hammulator: Simulate Now - Exploit Later
DRAMSec
Virtual, June 17, 2023
BibTeX Citation
@misc{zhang2024cachewarp,
title={StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU’s Stack Engine},
howpublished={USENIX Security},
author={Ruiyi Zhang and Tristan Hornetz and Daniel Weber and Fabian Thomas and Michael Schwarz},
year={2026}
}BibTeX Citation
@misc{hetterich2026instrsem,
title={InstrSem: Automatically and Generically Inferring Semantics of (Undocumented) CPU Instructions},
howpublished={USENIX Security},
author={Lorenz Hetterich and Fabian Thomas and Tristan Hornetz and Michael Schwarz},
year={2026}
}BibTeX Citation
@misc{thomas2025exfilstate,
title={ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUs},
howpublished={CCS},
author={Fabian Thomas and Michael Torres and Daniel Moghimi and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{thomas2025riscover,
title={RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs},
howpublished={CCS},
author={Fabian Thomas and Eric García Arribas and Lorenz Hetterich and Daniel Weber and Lukas Gerlach and Ruiyi Zhang and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{rainer2025rapid,
title={Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage},
howpublished={S\&P},
author={Mikka Rainer and Lorenz Hetterich and Fabian Thomas and Tristan Hornetz and Leon Trampert and Lukas Gerlach and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{hetterich2025shadowload,
title={ShadowLoad: Injecting State into Hardware Prefetchers},
howpublished={ASPLOS},
author={Lorenz Hetterich and Fabian Thomas and Lukas Gerlach and Ruiyi Zhang and Nils Bernsdorf and Eduard Ebert and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{gerlach2023blacksmithrepro,
title={A Rowhammer Reproduction Study Using the Blacksmith Fuzzer},
howpublished={ESORICS},
author={Lukas Gerlach and Fabian Thomas and Robert Pietsch and Michael Schwarz},
year={2023}
}BibTeX Citation
@misc{weber2023masc,
title={Indirect Meltdown: Building Novel Side-Channel Attacks from Transient Execution Attacks},
howpublished={ESORICS},
author={Daniel Weber and Fabian Thomas and Lukas Gerlach and Ruiyi Zhang and Michael Schwarz},
year={2023}
}BibTeX Citation
@misc{weber2023meltdown3a,
title={Reviving Meltdown 3a},
howpublished={ESORICS},
author={Daniel Weber and Fabian Thomas and Lukas Gerlach and Ruiyi Zhang and Michael Schwarz},
year={2023}
}BibTeX Citation
@misc{thomas2023hammulator,
title={Hammulator: Simulate Now - Exploit Later},
howpublished={DRAMSec},
author={Fabian Thomas and Lukas Gerlach and Michael Schwarz},
year={2023}
}Talks
2026
No Time To Leak: Exposing Timer-Free Cache-State Leaks on ARM CPUs
uASC
Leuven, Belgium, February 3, 2026
How Secure Are Commercial RISC-V CPUs?
FOSDEM
Brussels, Belgium, January 31, 2026
2025
No Clock, No Problem: Discovering Timer-Free Cache-State Side Channels
MIC-SEC
Paris, France, December 4, 2025
When Timers Fail: Discovering Hidden Cache State Leaks on ARM CPUs
hardwear.io NL
Amsterdam, Netherlands, November 20, 2025
2024
From Rowhammer to GhostWrite: Advanced Exploitation and Discovery of Hardware Bugs
hardwear.io NL
Amsterdam, Netherlands, October 25, 2024
Arbitrary Data Manipulation and Leakage with CPU Zero-Day Bugs on RISC-V
Black Hat USA
Las Vegas, USA, August 7, 2024
BibTeX Citation
@misc{thomas2026notime,
title={No Time To Leak: Exposing Timer-Free Cache-State Leaks on ARM CPUs},
howpublished={uASC},
author={Fabian Thomas},
year={2026}
}BibTeX Citation
@misc{thomas2026secure,
title={How Secure Are Commercial RISC-V CPUs?},
howpublished={FOSDEM},
author={Lukas Gerlach and Fabian Thomas},
year={2026}
}BibTeX Citation
@misc{thomas2025noclock,
title={No Clock, No Problem: Discovering Timer-Free Cache-State Side Channels},
howpublished={MIC-SEC},
author={Fabian Thomas},
year={2025}
}BibTeX Citation
@misc{thomas2025timers,
title={When Timers Fail: Discovering Hidden Cache State Leaks on ARM CPUs},
howpublished={hardwear.io NL},
author={Fabian Thomas},
year={2025}
}BibTeX Citation
@misc{thomas2024advanced,
title={From Rowhammer to GhostWrite: Advanced Exploitation and Discovery of Hardware Bugs},
howpublished={hardwear.io NL},
author={Fabian Thomas},
year={2024}
}BibTeX Citation
@misc{thomas2024arbitrary,
title={Arbitrary Data Manipulation and Leakage with CPU Zero-Day Bugs on RISC-V},
howpublished={Black Hat USA},
author={Fabian Thomas and Lorenz Hetterich},
year={2024}
}Awards
2025
Distinguished Artifact Award
ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUs
CCS
October 13, 2025
