Search arXivSearch

arXiv subjects

Christian Gehrmann

Publications and source records attributed to Christian Gehrmann.

17 recordsLinked to original sources

Dissecting the Black Box: Circuit-Level Analysis of LLM Vulnerability Detection

Large language models (LLMs) can detect software vulnerabilities, but how do they actually identify vulnerable code? We address this question using mechanistic interpretability; analyzing the internal computations of a neural network to understand its reasoning process.Using Circuit Tracer on Gemma-2-2b, we trace the computational pathways activated when the model classifies 472 C/C++ code samples as vulnerable or safe. Our analysis reveals a surprising finding: the model primarily relies on safety detectors, attention heads that recognize safe coding patterns, rather than directly detecting vulnerability signatures. When these safety detectors fail to activate, the model classifies code as vulnerable. We identify the critical neural components: specific attention heads in early layers (L5, L7) that focus on safety patterns, and Multilayer Perceptron (MLP) neurons in Layer 7 that encode vulnerability-related features. Ablation experiments confirm their causal role; removing Layer 11 drops vulnerability detection accuracy from 100% to 6%, while ablating just 20 neurons in Layer 7 reduces it by 50%.Our findings show that LLM vulnerability detection uses sparse, interpretable circuits (only 16% of model capacity), enabling circuit-level explanations for security predictions and targeted improvements to detection systems.

cs.CR

SAMSEM -- A Generic and Scalable Approach for IC Metal Line Segmentation

In light of globalized hardware supply chains, the assurance of hardware components has gained significant interest, particularly in cryptographic applications and high-stakes scenarios. Identifying metal lines on scanning electron microscope (SEM) images of integrated circuits (ICs) is one essential step in verifying the absence of malicious circuitry in chips manufactured in untrusted environments. Due to varying manufacturing processes and technologies, such verification usually requires tuning parameters and algorithms for each target IC. Often, a machine learning model trained on images of one IC fails to accurately detect metal lines on other ICs. To address this challenge, we create SAMSEM by adapting Meta's Segment Anything Model 2 (SAM2) to the domain of IC metal line segmentation. Specifically, we develop a multi-scale segmentation approach that can handle SEM images of varying sizes, resolutions, and magnifications. Furthermore, we deploy a topology-based loss alongside pixel-based losses to focus our segmentation on electrical connectivity rather than pixel-level accuracy. Based on a hyperparameter optimization, we then fine-tune the SAM2 model to obtain a model that generalizes across different technology nodes, manufacturing materials, sample preparation methods, and SEM imaging technologies. To this end, we leverage an unprecedented dataset of SEM images obtained from 48 metal layers across 14 different ICs. When fine-tuned on seven ICs, SAMSEM achieves an error rate as low as 0.72% when evaluated on other images from the same ICs. For the remaining seven unseen ICs, it still achieves error rates as low as 5.53%. Finally, when fine-tuned on all 14 ICs, we observe an error rate of 0.62%. Hence, SAMSEM proves to be a reliable tool that significantly advances the frontier in metal line segmentation, a key challenge in post-manufacturing IC verification.

cs.CR

Lost in the Pages: WebAssembly Code Recovery through SEV-SNP's Exposed Address Space

WebAssembly (Wasm) has risen as a widely used technology to distribute computing workloads on different platforms. The platform independence offered through Wasm makes it an attractive solution for many different applications that can run on disparate infrastructures. In addition, Trusted Execution Environments (TEEs) are offered in many computing infrastructures, which allows also running security sensitive Wasm workloads independent of the specific platforms offered. However, recent work has shown that Wasm binaries are more sensitive to code confidentiality attacks than native binaries. The previous result was obtained for Intel SGX only. In this paper, we take this one step further, introducing a new Wasm code-confidentiality attack that exploits exposed address-space information in TEEs. Our attack enables the extraction of crucial execution features which, when combined with additional side channels, allows us to with high reliability obtain more than 70% of the code in most cases. This is a considerably larger amount than was previously obtained by single stepping Intel SGX where only upwards to 50% of the code could be obtained.

cs.CR

Vulnerability Detection in Popular Programming Languages with Language Models

Vulnerability detection is crucial for maintaining software security, and recent research has explored the use of Language Models (LMs) for this task. While LMs have shown promising results, their performance has been inconsistent across datasets, particularly when generalizing to unseen code. Moreover, most studies have focused on the C/C++ programming language, with limited attention given to other popular languages. This paper addresses this gap by investigating the effectiveness of LMs for vulnerability detection in JavaScript, Java, Python, PHP, and Go, in addition to C/C++ for comparison. We utilize the CVEFixes dataset to create a diverse collection of language-specific vulnerabilities and preprocess the data to ensure quality and integrity. We fine-tune and evaluate state-of-the-art LMs across the selected languages and find that the performance of vulnerability detection varies significantly. JavaScript exhibits the best performance, with considerably better and more practical detection capabilities compared to C/C++. We also examine the relationship between code complexity and detection performance across the six languages and find only a weak correlation between code complexity metrics and the models' F1 scores.

cs.CR

From Generalist to Specialist: Exploring CWE-Specific Vulnerability Detection

Vulnerability Detection (VD) using machine learning faces a significant challenge: the vast diversity of vulnerability types. Each Common Weakness Enumeration (CWE) represents a unique category of vulnerabilities with distinct characteristics, code semantics, and patterns. Treating all vulnerabilities as a single label with a binary classification approach may oversimplify the problem, as it fails to capture the nuances and context-specific to each CWE. As a result, a single binary classifier might merely rely on superficial text patterns rather than understanding the intricacies of each vulnerability type. Recent reports showed that even the state-of-the-art Large Language Model (LLM) with hundreds of billions of parameters struggles to generalize well to detect vulnerabilities. Our work investigates a different approach that leverages CWE-specific classifiers to address the heterogeneity of vulnerability types. We hypothesize that training separate classifiers for each CWE will enable the models to capture the unique characteristics and code semantics associated with each vulnerability category. To confirm this, we conduct an ablation study by training individual classifiers for each CWE and evaluating their performance independently. Our results demonstrate that CWE-specific classifiers outperform a single binary classifier trained on all vulnerabilities. Building upon this, we explore strategies to combine them into a unified vulnerability detection system using a multiclass approach. Even if the lack of large and high-quality datasets for vulnerability detection is still a major obstacle, our results show that multiclass detection can be a better path toward practical vulnerability detection in the future. All our models and code to produce our results are open-sourced.

cs.CR

Attacks Against Mobility Prediction in 5G Networks

The $5^{th}$ generation of mobile networks introduces a new Network Function (NF) that was not present in previous generations, namely the Network Data Analytics Function (NWDAF). Its primary objective is to provide advanced analytics services to various entities within the network and also towards external application services in the 5G ecosystem. One of the key use cases of NWDAF is mobility trajectory prediction, which aims to accurately support efficient mobility management of User Equipment (UE) in the network by allocating ``just in time'' necessary network resources. In this paper, we show that there are potential mobility attacks that can compromise the accuracy of these predictions. In a semi-realistic scenario with 10,000 subscribers, we demonstrate that an adversary equipped with the ability to hijack cellular mobile devices and clone them can significantly reduce the prediction accuracy from 75\% to 40\% using just 100 adversarial UEs. While a defense mechanism largely depends on the attack and the mobility types in a particular area, we prove that a basic KMeans clustering is effective in distinguishing legitimate and adversarial UEs.

cs.CR

Anharmonic Fluctuations Govern the Band Gap of Halide Perovskites

We determine the impact of anharmonic thermal vibrations on the fundamental band gap of CsPbBr$_3$, a prototypical model system for the broader class of halide perovskite semiconductors. Through first-principles molecular dynamics and stochastic calculations, we find that anharmonic fluctuations are a key effect in the electronic structure of these materials. We present experimental and theoretical evidence that important characteristics, such as a mildly changing band-gap value across a temperature range that includes phase-transitions, cannot be explained by harmonic phonons thermally perturbing an average crystal structure and symmetry. Instead, the thermal characteristics of the electronic structure are microscopically connected to anharmonic vibrational contributions to the band gap that reach a fairly large magnitude of 450 meV at 425 K.

cond-mat.mtrl-sci

Static and Dynamic Disorder in Formamidinium Lead Bromide Single Crystals

We show that formamidinium lead bromide is unique among the halide perovskite crystals because its inorganic sub-lattice exhibits intrinsic local static disorder that co-exists with a well-defined average crystal structure. Our study combines THz-range Raman-scattering with single-crystal X-ray diffraction and first-principles calculations to probe the inorganic sub-lattice dynamics evolution with temperature in the range of 10-300 K. The temperature evolution of the Raman spectra shows that low-temperature, local static disorder strongly affects the crystal's structural dynamics and phase transitions at higher temperatures.

cond-mat.mtrl-sci

Probing the Disorder inside the Cubic Unit Cell of Halide Perovskites from First-Principles

Strong deviations in the finite temperature atomic structure of halide perovskites from their average geometry can have profound impacts on optoelectronic and other device-relevant properties. Detailed mechanistic understandings of these structural fluctuations and their consequences remain, however, limited by the experimental and theoretical challenges involved in characterizing strongly anharmonic vibrational characteristics and their impact on other properties. We overcome some of these challenges by a theoretical characterization of the vibrational interactions that occur among the atoms in the prototypical cubic CsPbBr$_3$. Our investigation based on first-principles molecular dynamics calculations finds that the motions of neighboring Cs-Br atoms interlock, which appears as the most likely Cs-Br distance being significantly shorter than what is inferred from an ideal cubic structure. This form of dynamic Cs-Br coupling coincides with very shallow dynamic potential wells for Br motions that occur across a locally and dynamically disordered energy landscape. We reveal an interesting dynamic coupling mechanism among the atoms within the nominal unit cell of cubic CsPbBr$_3$ and quantify the important local structural fluctuations on an atomic scale.

cond-mat.mtrl-sci

Transversal Halide Motion Intensifies Band-To-Band Transitions in Halide Perovskites

Despite their puzzling vibrational characteristics that include strong signatures of anharmonicity and thermal disorder already around room temperature, halide perovskites exhibit favorable optoelectronic properties for applications in photovoltaics and beyond. Whether these vibrational properties are advantageous or detrimental to their optoelectronic properties remains, however, an important open question. Here, this issue is addressed by investigation of the {finite-temperature optoelectronic properties} in the prototypical cubic CsPbBr$_3$, using first-principles molecular dynamics based on density-functional theory. It is shown that the dynamic flexibility associated with halide perovskites enables the so-called transversality, which manifests as a preference for large halide displacements perpendicular to the Pb-Br-Pb bonding axis. We find that transversality is concurrent with vibrational anharmonicity and leads to a rapid rise in the joint density of states, which is favorable for photovoltaics since this implies sharp optical absorption profiles. These findings are contrasted to the case of PbTe, a material that shares several key properties with CsPbBr$_3$ but cannot exhibit any transversality and, hence, is found to exhibit much wider band-edge distributions. We conclude that the dynamic structural flexibility in halide perovskites and their unusual vibrational characteristics might not just be a mere coincidence, but play active roles in establishing their favorable optoelectronic properties.

cond-mat.mtrl-sci

A Decentralized Dynamic PKI based on Blockchain

The central role of the certificate authority (CA) in traditional public key infrastructure (PKI) makes it fragile and prone to compromises and operational failures. Maintaining CAs and revocation lists is demanding especially in loosely-connected and large systems. Log-based PKIs have been proposed as a remedy but they do not solve the problem effectively. We provide a general model and a solution for decentralized and dynamic PKI based on a blockchain and web of trust model where the traditional CA and digital certificates are removed and instead, everything is registered on the blockchain. Registration, revocation, and update of public keys are based on a consensus mechanism between a certain number of entities that are already part of the system. Any node which is part of the system can be an auditor and initiate the revocation procedure once it finds out malicious activities. Revocation lists are no longer required as any node can efficiently verify the public keys through witnesses.

cs.CR

Lic-Sec: an enhanced AppArmor Docker security profile generator

Along with the rapid development of cloud computing technology, containerization technology has drawn much attention from both industry and academia. In this paper, we perform a comparative measurement analysis of Docker-sec, which is a Linux Security Module proposed in 2018, and a new AppArmor profile generator called Lic-Sec, which combines Docker-sec with a modified version of LiCShield, which is also a Linux Security Module proposed in 2015. Docker-sec and LiCShield can be used to enhance Docker container security based on mandatory access control and allows protection of the container without manually configurations. Lic-Sec brings together their strengths and provides stronger protection. We evaluate the effectiveness and performance of Docker-sec and Lic-Sec by testing them with real-world attacks. We generate an exploit database with 42 exploits effective on Docker containers selected from the latest 400 exploits on Exploit-db. We launch these exploits on containers spawned with Docker-sec and Lic-Sec separately. Our evaluations show that for demanding images, Lic-Sec gives protection for all privilege escalation attacks for which Docker-sec failed to give protection.

cs.CR

Anharmonic Host Lattice Dynamics Enable Fast Ion Conduction in Superionic AgI

Basic understanding of the driving forces of ion conduction in solids is critical to the development of new solid-state ion conductors. Physical understanding of ion conduction is limited due to strong deviations from harmonic vibrational dynamics in these systems that are difficult to characterize experimentally and theoretically. We overcome this challenge in superionic AgI by combining THz-frequency Raman polarization-orientation measurements and ab-initio molecular dynamics computations. Our findings demonstrate clear signatures of strong coupling between the mobile ions and host lattice that are of importance to the diffusion process. We first derive a dynamic structural model from the Raman measurements that captures the simultaneous crystal-like and fluid-like properties of this fast-ion conductor. Then we show and discuss the importance of anharmonic relaxational motion that arises from the iodine host lattice by demonstrating its strong impact on ion conduction in superionic AgI.

cond-mat.mtrl-sci

Dynamic Shortening of Disorder Potentials in Anharmonic Halide Perovskites

Halide perovskites are semiconductors that exhibit sharp optical absorption edges and small Urbach energies allowing for efficient collection of sunlight in thin-film photovoltaic devices. However, halide perovskites also exhibit large nuclear anharmonic effects and disorder, which is unusual for efficient optoelectronic materials and difficult to rationalize in view of the small Urbach energies that indicate a low amount of disorder. To address this important issue, the disorder potential induced for electronic states by the nuclear dynamics in various paradigmatic halide perovskites is studied with molecular dynamics and density functional theory. We find that the disorder potential is dynamically shortened due to the nuclear motions in the perovskite, such that it is short-range correlated, which is shown to lead to favorable distributions of band edge energies. This dynamic mechanism allows for sharp optical absorption edges and small Urbach energies, which are highly desired properties of any solar absorber material.

cond-mat.mtrl-sci

Structure and Binding in Halide Perovskites: Analysis of Static and Dynamic Effects from Dispersion-Corrected Density Functional Theory

We investigate the impact of various levels of approximation in density functional theory calculations for the structural and binding properties of the prototypical halide perovskite MAPbI$_3$. Specifically, we test how the inclusion of different correction schemes for including dispersive interactions, and how in addition using hybrid density functional theory, affects the results for pertinent structural observables by means of comparison to experimental data. In particular, the impact of finite temperature on the lattice constants and bulk modulus, and the role of dispersive interactions in calculating them, is examined by using molecular dynamics based on density functional theory. Our findings confirm previous theoretical work showing that including dispersive corrections is crucial for accurate calculation of structural and binding properties of MAPbI$_3$. They furthermore highlight that using a computationally much more expensive hybrid density functional has only minor consequences for these observables. This allows for suggesting the use of semilocal density functional theory, augmented by pairwise dispersive corrections, as a reasonable choice for structurally more complicated calculations of halide perovskites. Using this method, we perform molecular dynamics calculations and discuss the dynamic effect of molecular rotation on the structure of and binding in MAPbI$_3$, which allowed for rationalizing microscopically the simultaneous occurrence of cubic octahedral symmetry and MA disorder.

cond-mat.mtrl-sci

SDN Access Control for the Masses

The evolution of Software-Defined Networking (SDN) has so far been predominantly geared towards defining and refining the abstractions on the forwarding and control planes. However, despite a maturing south-bound interface and a range of proposed network operating systems, the network management application layer is yet to be specified and standardized. It has currently poorly defined access control mechanisms that could be exposed to network applications. Available mechanisms allow only rudimentary control and lack procedures to partition resource access across multiple dimensions. We address this by extending the SDN north-bound interface to provide control over shared resources to key stakeholders of network infrastructure: network providers, operators and application developers. We introduce a taxonomy of SDN access models, describe a comprehensive design for SDN access control and implement the proposed solution as an extension of the ONOS network controller intent framework.

cs.NI

TruSDN: Bootstrapping Trust in Cloud Network Infrastructure

Software-Defined Networking (SDN) is a novel architectural model for cloud network infrastructure, improving resource utilization, scalability and administration. SDN deployments increasingly rely on virtual switches executing on commodity operating systems with large code bases, which are prime targets for adversaries attacking the net- work infrastructure. We describe and implement TruSDN, a framework for bootstrapping trust in SDN infrastructure using Intel Software Guard Extensions (SGX), allowing to securely deploy SDN components and protect communication between network endpoints. We introduce ephemeral flow-specific pre-shared keys and propose a novel defense against cuckoo attacks on SGX enclaves. TruSDN is secure under a powerful adversary model, with a minor performance overhead.

cs.NI