Novel Hardware Attacks with MIT CSAIL Associate Professor Mengjia Yan

Audrey Woods, MIT CSAIL Alliances | October 5, 2026 

Modern hardware security relies on implicit assumptions—that certain design choices are safe, that certain attack windows are too small to matter, that certain behaviors can be trusted. But hidden inside those assumptions are blindspots waiting to be exploited. 

MIT CSAIL Associate Professor Mengjia Yan's group is dedicated to exposing security vulnerabilities before bad actors discover them, and building a more rigorous foundation for secure hardware—from probing the limits of real-world processors to applying formal verification at the design stage of next-generation hardware. 

 

SPECULATIVE EXECUTION ATTACKS: HOW TONTOU CHANGED THE GAME 

Speculative execution attacks are not new—the first attacks, Spectre and Meltdown, were discovered in 2018. This class of cybersecurity attacks exploit the microarchitecture of computer hardware to find openings during CPU processing that would allow a hacker to trick a computer into executing instructions or performing actions without proper authorization. Most computers predict the next instruction in an operation, saving time and offering the user a faster, smoother experience. When a prediction is wrong, the computer can just go to the correct action and continue as if nothing had happened. But a hacker can inject a malicious prediction into the system and siphon off information, like passwords, keychains, and other private data. “Speculative execution is such a ubiquitous feature. It's been in nearly every processor for decades, and nobody had thought to question it. It wasn't until Spectre and Meltdown that people realized this performance optimization we had built into everything can actually be used to leak secrets.” Yan says. “There has been an arms race between attackers and defenders ever since.” 

As offensive researchers, Yan and her colleagues are always on the lookout for new methods of attack, helping companies find the ways that someone might sneak into a system and break the isolation or security mechanisms that keep data and operations private. Their most recent work is a class of attack they call TONTOU, or “Time Of Neutralization to Time Of Use.” The name comes from a very tiny window between two hardware operations: neutralization and use. After Spectre was identified, chip vendors added workarounds to neutralize the states influenced by malicious instructions injected as predictions. However, there’s a time gap between neutralizing the incorrect prediction and moving on to the next prediction. This gap was a known risk for years, but considered too small to be used by real-world hackers. 

Daniel Trujillo, one of Yan’s PhD students, came to her with “an approach to use interrupts to inject malicious prediction within this window. Even if the window is just a few milliseconds, he can still hit it.” By setting a timer for the exact moment of the TONTOU window and wiping the instructions from the cache to slow down the processor, Trujillo was able to succeed 2% of the time. That sounds small, but “once you break that assumption, you can do all kinds of things to leak secrets. You can revive attacks that were supposed to be suppressed by the mitigation.” Critically, the implications of this attack are not constrained to an individual computer. Because cloud servers often host various users and data—including bank information, medical records, and passwords—even at just a 2% success rate, one successful TONTOU attack could have far-reaching consequences. 

 

FRACTAL & FORMAL VERIFICATION 

Doing this research is difficult because it requires a deep understanding of computer hardware, which is not as simple as opening up a hard drive and looking inside. To conceptualize attacks like TONTOU, Yan and her group need to know the microarchitecture designs of commercial hardware, details that are not publicly available. Traditionally, researchers modify operating systems ad-hoc to understand chip microarchitecture. But another one of Yan’s students, Joseph Ravichandran, came up with the idea of an operating system built to reverse-engineer hardware called Fractal. 

“Fractal is very different from traditional operating systems like Linux, macOS, or Windows, which are designed primarily for usability. In those systems, you have a user space for running applications and a kernel space that performs all the security countermeasures to keep them isolated. But we've found that the kernel actually prevents us from reverse engineering hardware, because user-space applications have to go through the kernel before they can interact with the hardware. To do reverse engineering, we often need to hack and modify Linux in various ways. Even our TONTOU attack required some of that.” Ravichandran wanted a more direct approach, so he designed an operating system to enable free reverse engineering of hardware. Fractal is one of the few tools that allow for reverse engineering Apple Silicon and is open-source on GitHub. 

Another significant direction in Yan’s group is using formal verification to guarantee the security of a system. Insight—pioneered by Vincent Ulitzsch, a postdoc in Yan’s lab—aimed to accelerate the infamously thorny process of hardware verification. “When you’re doing hardware verification and you find a counterexample, it’s very difficult to debug. In software, you have debuggers and simulation tools to step through a program. In hardware, a counterexample is a trace of all the signals in your system, potentially thousands of signals. It's very tedious and labor-intensive.” To put the scale in context, the common ratio of chip designers to chip verifiers is roughly 1 to 5. “Hardware is just very difficult to get right, and a huge amount of money and human effort goes into verification in this industry.” 

Insight offers an elegant approach where, given a counterexample, the system slightly tweaks the input to generate another case. This might also be a counterexample triggering the same bug, or it might be benign, but by collecting each of these, Ulitzsch can innovatively reformulate the problem to be solved by standard math tools to find the signature that separates the groups. “Once you identify that signature, you know exactly where the problem is. This significantly reduces the labor-intensive work down to a simple algorithm that gets results efficiently. There's also a future direction to incorporate large language models into this workflow.” 

Modern processors utilize out-of-order instructions so that operations can be executed in parallel. This dramatically improves performance, but makes the design—and verification—enormously complicated. Yan and her group created a technique called HUF (Uninterpreted Functions with History) which “managed to prove challenging security properties on one of the most complex open-source RISC-V processors.” This was a big step forward in the area of security verification because “most formal verification work tends to focus on simple, in-order cores. We managed to prove properties on a complex one, without a lot of manual effort.” 

 

ADVICE FOR INDUSTRY & FUTURE DIRECTIONS 

Because side channel attacks require co-location—meaning the attacker and victim processes are running on the same computer—it might be tempting to worry about them less than other threats. But Yan emphasizes that co-location “is actually much more common than you think. Even on a personal computer, any website you open is running JavaScript or other code written by someone else. Think about how many tabs you just leave open. And phones could potentially be targeted as well, with so many apps running at any given time.” Another vulnerability “is the cloud, because a lot of heavy and security-sensitive computation is outsourced there. Cloud vendors have many-core server machines and pack compute from different clients onto the same hardware for efficient use of resources. There's a lot of co-location happening there.”

In the slow-moving world of hardware, where chips take years to design and weaknesses can’t be quickly patched with code like software, how can companies protect themselves? Yan says, “industry players should really keep in contact with chip vendors. When vendors issue security guidelines, read them and follow them.” She also advises caution about cloud services. “Understand the security implications of different service configurations… where you have exclusive access to a machine versus those where you share the machine with others. Shared environments expose you to a different category of side-channel risk.” 

Can AI help in her research, either identifying vulnerabilities or verifying systems? Not yet, although Yan is hopeful it can someday. “Existing AI tools aren't good enough yet at dealing with closed-source, black-box hardware. They're doing well in software, though I have no doubt they'll get there.” Even though she spends all day thinking of hardware security risks, Yan finds it joyful and inspiring to engage with MIT students and researchers, both in her group and beyond. “At MIT, you really have some of the most creative, brilliant, and passionate students. I always gain a lot of energy from conversations with them. If I can have just one exciting discussion with a student in a day, I feel like the whole day paid off.” 

Learn more about Professor Yan on her website or CSAIL page.