Andrew Kwong
I am an Assistant Professor at UNC Chapel Hill in the Department of Computer Science. My research is in computer security and applied cryptography, with a focus on side-channel attacks and defenses.
Contact: andrew@cs.unc.edu
Google Scholar
Teaching
COMP 590-184
Hardware Security Spring 2026, 2025, 2024
COMP 790-184
Research Topics in Computer Security Fall 2026, 2025, 2024, 2023
Publications
-
GDDRHammer: Greatly Disturbing DRAM Rows — Cross-Component Rowhammer Attacks from Modern GPUs
Yichang Hu, Noah Brown, Yuhang Chen, Joshua Bakita, Tianlong Chen, Daniel Genkin, Andrew Kwong
In IEEE Symposium on Security and Privacy (IEEE S&P), 2026
(Acceptance Rate: 12.7%)
Website: [https://gddr.fail]
arsTECHNICA Article: [New Rowhammer attacks give complete control of machines running Nvidia GPUs]
-
KeyTAR: Practical Keystroke Timing Attacks and Input Reconstruction
Mufan Qiu, Lihsuan Chuang, Dohhyun Kim, Huaizhi Qu, Tianlong Chen, and Andrew Kwong
In IEEE Symposium on Security and Privacy (IEEE S&P), 2026
(Acceptance Rate: 12.7%)
★ Pwnie Award Finalist: "Most Underhyped Research"
-
Bit-Flip Error Resilience in LLMs: A Comprehensive Analysis and Defense Framework
Yuhang Chen, Zhen Tan, Ajay Kumar Jaiswal, Huaizhi Qu, Xinyu Zhao, Qi Lin, Yu Cheng, Andrew Kwong, Zhichao Cao, and Tianlong Chen
In Conference on Empirical Methods in Natural Language Processing (EMNLP), 2025
(Acceptance Rate: 22.16%)
-
PQ-Hammer: End-to-end Key Recovery Attacks on Post-Quantum Cryptography Using Rowhammer
Samy Amer, Yingchen Wang, Hunter Kippen, Thinh Dang, Daniel Genkin, Andrew Kwong, Alexander Nelson, and Arkady Yerukhimovich
In IEEE Symposium on Security and Privacy (IEEE S&P), 2025
(Acceptance Rate: 14.8%)
-
Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch Predictor
Hosein Yavarzadeh, Archit Agarwal, Max Christman, Christina Garman, Daniel Genkin, Andrew Kwong, Daniel Moghimi, Deian Stefan, Kazem Taram, and Dean Tullsen
In ACM International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS), 2024
(Acceptance Rate: 18.4%)
-
SledgeHammer: Amplifying Rowhammer via Bank-level Parallelism
Ingab Kang, Walter Wang, Jason Kim, Stephan van Schaik, Youssef Tobah, Daniel Genkin, Andrew Kwong, and Yuval Yarom
In USENIX Security Symposium (USENIX Security), 2024
(Acceptance Rate: 18.32%)
-
Go Go Gadget Hammer: Flipping Nested Pointers for Arbitrary Data Leakage
Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, and Kang Shin
In USENIX Security Symposium (USENIX Security), 2024
(Acceptance Rate: 18.32%)
-
Checking Passwords on Leaky Computers: A Side-Channel Analysis of Chrome's Password Leak Detection Protocol
Andrew Kwong, Walter Wang, Jason Kim, Jonathan Berger, Daniel Genkin, Eyal Ronen, Hovav Shacham, Riad Wahby, and Yuval Yarom
In USENIX Security Symposium (USENIX Security), 2023
(Acceptance Rate: 29.2%)
★ Google VRP Reward
-
When Frodo Flips: End-to-End Key Recovery on FrodoKEM via Rowhammer
Michael Fahr Jr.*, Hunter Kippen*, Andrew Kwong*, Thinh Dang, Jacob Lichtinger, Dana Dachman-Soled, Daniel Genkin, Alexander Nelson, Ray Perlner, Arkady Yerukhimovich, and Daniel Apon
In ACM Conference on Computer and Communications Security (CCS), 2022
(Acceptance Rate: 22.4%)
Cryptology ePrint: [https://eprint.iacr.org/2022/952]
★ Best Paper Award Honorable Mention
(* Students listed in alphabetical order)
-
SpecHammer: Combining Spectre and Rowhammer for New Speculative Attacks
Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, and Kang Shin
In IEEE Symposium on Security and Privacy (IEEE S&P), 2022
(Acceptance Rate: 14.6%)
-
CacheOut: Leaking Data on Intel CPUs via Cache Evictions
Stephan Van Schaik, Marina Minkin, Andrew Kwong, Daniel Genkin, and Yuval Yarom
In IEEE Symposium on Security and Privacy (IEEE S&P), 2021
(Acceptance Rate: 12.0%)
Website: [https://cacheoutattack.com]
Wired Article: [Intel Is Patching the Patch for the Patch for Its ‘Zombieload’ Flaw]
-
RAMBleed: Reading Bits in Memory Without Accessing Them
Andrew Kwong, Daniel Genkin, Daniel Gruss, and Yuval Yarom
In IEEE Symposium on Security and Privacy (IEEE S&P), 2020
(Acceptance Rate: 12.3%) [Preview Video] [Talk]
Website: [https://rambleed.com]
arsTECHNICA Article: [Researchers use Rowhammer bit flips to steal 2048-bit crypto key]
-
Pseudorandom Black Swans: Cache Attacks on CTR_DRBG
Shaanan Cohney, Andrew Kwong, Shahar Paz, Daniel Genkin, Nadia Heninger, Eyal Ronen, and Yuval Yarom
In IEEE Symposium on Security and Privacy (IEEE S&P), 2020
(Acceptance Rate: 12.3%) [Preview Video]
Cryptology ePrint: [https://eprint.iacr.org/2019/996]
Blog Post: [https://security.cohney.info/blackswans/]
★ Intel Bug Bounty Award
-
SGAxe: How SGX Fails in Practice
Stephan Van Schaik, Andrew Kwong, Daniel Genkin, and Yuval Yarom (2020)
Website: [https://sgaxe.com/]
Hard Drive of Hearing: Disks that Eavesdrop with a Synthesized Microphone
Andrew Kwong, Wenyuan Xu, and Kevin Fu
In IEEE Symposium on Security and Privacy (IEEE S&P), 2019
(Acceptance Rate: 12.4%) [Preview Video] [Talk Slides]
Blue Note: How Intentional Acoustic Interference Damages Availability and Integrity in Hard Disk Drives and Operating Systems
Connor Bolton, Sara Rampazzi, Chaohao Li, Andrew Kwong, Wenyuan Xu, and Kevin Fu
In IEEE Symposium on Security and Privacy (IEEE S&P), 2018
(Acceptance Rate: 11.5%)
Select Talks