Hey! I am a PhD student at Saarland University working for the CISPA Helmholtz Center for Information Security under the supervision of Dr. Michael Schwarz and Prof. Christian Rossow. I like to explore the microarchitectural security of modern computer systems. A particular interest of mine lies in the security implications of up-and-coming web features such as WebAssembly.
CV
PhD Student
CISPA / Saarland University
2023 – today
PhD Preparation
Saarbrücken Graduate School of CS
2021 – 2022
Cybersecurity B.Sc.
Saarland University
2018 – 2021
Publications
2025
Styled to Steal: The Overlooked Attack Surface in Email Clients
CCS
Taipei, Taiwan, October 13-17, 2025
Confusing Value with Enumeration: Studying the Use of CVEs in Academia
Moritz Schloegel,
Daniel Klischies,
Simon Koch,
David Klein, Lukas Gerlach,
Malte Wessels, Leon Trampert,
Martin Johns,
Mathy Vanhoef, Michael Schwarz,
Thorsten Holz,
Jo Van Bulck
USENIX Security
Seattle, Washington, USA, August 13-15, 2025
SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution
USENIX Security
Seattle, Washington, USA, August 13-15, 2025
Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage
Mikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz, Leon Trampert, Lukas Gerlach, Michael Schwarz
S&P
San Francisco, California, USA, May 12-15, 2025
Peripheral Instinct: How External Devices Breach Browser Sandboxes
WWW
Sydney, Australia, April 8 - May 2, 2025
Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting
NDSS
San Diego, California, USA, February 23-28, 2025
Hidden in Plain Sight: Scriptless Microarchitectural Attacks via TrueType Font Hinting
uASC
Bochum, Germany, February 19, 2025
2023
FetchBench: Systematic Identification and Characterization of Proprietary Prefetchers
Till Schlüter,
Amit Choudhari, Lorenz Hetterich, Leon Trampert,
Hamed Nemati,
Ahmad Ibrahim, Michael Schwarz,
Christian Rossow,
Nils Ole Tippenhauer
CCS
Copenhagen, Denmark, November 26-30, 2023
Honey, I Cached our Security Tokens - Re-usage of Security Tokens in the Wild
Leon Trampert,
Ben Stock,
Sebastian Roth
RAID
Hong Kong, October 16-18, 2023
2022
Browser-based CPU Fingerprinting
Leon Trampert,
Christian Rossow, Michael Schwarz
ESORICS
Copenhagen, Denmark, September 26-30, 2022
BibTeX Citation
@misc{trampert2025styled,
title={Styled to Steal: The Overlooked Attack Surface in Email Clients},
howpublished={CCS},
author={Leon Trampert and Daniel Weber and Christian Rossow and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{schloegel2025cve,
title={Confusing Value with Enumeration: Studying the Use of CVEs in Academia},
howpublished={USENIX Security},
author={Moritz Schloegel and Daniel Klischies and Simon Koch and David Klein and Lukas Gerlach and Malte Wessels and Leon Trampert and Martin Johns and Mathy Vanhoef and Michael Schwarz and Thorsten Holz and Jo Van Bulck},
year={2025}
}BibTeX Citation
@misc{weber2025scase,
title={SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution},
howpublished={USENIX Security},
author={Daniel Weber and Lukas Gerlach and Leon Trampert and Youheng Lue and Jo Van Bulck and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{rainer2025rapid,
title={Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage},
howpublished={S\&P},
author={Mikka Rainer and Lorenz Hetterich and Fabian Thomas and Tristan Hornetz and Leon Trampert and Lukas Gerlach and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{trampert2025peripheralinstinct,
title={Peripheral Instinct: How External Devices Breach Browser Sandboxes},
howpublished={WWW},
author={Leon Trampert and Lorenz Hetterich and Lukas Gerlach and Mona Schappert and Christian Rossow and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{trampert2025cascadingspysheets,
title={Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting},
howpublished={NDSS},
author={Leon Trampert and Daniel Weber and Lukas Gerlach and Christian Rossow and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{trampert2025hiddenplainsight,
title={Hidden in Plain Sight: Scriptless Microarchitectural Attacks via TrueType Font Hinting},
howpublished={uASC},
author={Leon Trampert and Michael Schwarz},
year={2025}
}BibTeX Citation
@misc{schlueter2023fetchbench,
title={FetchBench: Systematic Identification and Characterization of Proprietary Prefetchers},
howpublished={CCS},
author={Till Schlüter and Amit Choudhari and Lorenz Hetterich and Leon Trampert and Hamed Nemati and Ahmad Ibrahim and Michael Schwarz and Christian Rossow and Nils Ole Tippenhauer},
year={2023}
}BibTeX Citation
@misc{trampert2023honey,
title={Honey, I Cached our Security Tokens - Re-usage of Security Tokens in the Wild},
howpublished={RAID},
author={Leon Trampert and Ben Stock and Sebastian Roth},
year={2023}
}BibTeX Citation
@misc{trampert2022uarchfp,
title={Browser-based CPU Fingerprinting},
howpublished={ESORICS},
author={Leon Trampert and Christian Rossow and Michael Schwarz},
year={2022}
}Talks
2026
Cascading Spy Sheets: The Privacy & Security Implications of CSS in Emails
FOSDEM
Brussels, Belgium, January 31, 2026
2025
Invisible Ink: Privacy Risks of CSS in Browsers and Emails
Black Hat Asia
Singapore, April 3, 2025
Beauty at a Cost: Privacy Implications of CSS on the Web and in Emails
RuhrSec
Bochum, Germany, February 21, 2025
2022
Browser-based CPU Fingerprinting
Black Hat MEA
Riyadh, Saudi Arabia, November 15, 2022
BibTeX Citation
@misc{trampert2025spysheets,
title={Cascading Spy Sheets: The Privacy & Security Implications of CSS in Emails},
howpublished={FOSDEM},
author={Leon Trampert and Daniel Weber and Michael Schwarz},
year={2026}
}BibTeX Citation
@misc{trampert2025invisible,
title={Invisible Ink: Privacy Risks of CSS in Browsers and Emails},
howpublished={Black Hat Asia},
author={Leon Trampert and Daniel Weber},
year={2025}
}BibTeX Citation
@misc{trampert2025beauty,
title={Beauty at a Cost: Privacy Implications of CSS on the Web and in Emails},
howpublished={RuhrSec},
author={Leon Trampert and Daniel Weber},
year={2025}
}BibTeX Citation
@misc{trampert2022browser,
title={Browser-based CPU Fingerprinting},
howpublished={Black Hat MEA},
author={Leon Trampert},
year={2022}
}Awards
2025
Distinguished Artifact Award
Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting
NDSS
February 23, 2025
