I am a senior principal researcher in the Office of the CTO, Azure for Operators at Microsoft. My research focuses on building trusted and secure systems, but I am interested in all aspects of systems research.

I am very proud when my research has impact in practice. Over the years, together with my colleagues, I have been fortunate to:

  • influence the DRAM industry to start addressing the threat of Rowhammer attacks.
  • ship a cloud service used by 20+ million users.
  • build the reference implementation of the firmware TPM.
  • build one of the first face recognition-based payment systems, six years before Amazon Go was launched.

Prior to coming to Microsoft, I was a faculty member of the Computer Science Department at the University of Toronto. I received my Ph.D. from the Computer Science & Engineering department at the University of Washington. I am an ACM Distinguished Member.

The good folks at Microsoft Research recorded a podcast with me on Rowhammer and wrote a blog post on my work and background. I also maintain a page with brief articles on various topics on Rowhammer.


Nov '22
Our Row-sampling paper has an incorrect claim in Section V. Configuring the Rowhammer threshold and the sampling rate values does not depend on the blast radius (unlike the paper's earlier claim). We added an Errata with more explanations to the end of our paper on Page 7.
Nov '22
DDR5 now has a new DRAM command to defend against Rowhammer: Directed Refresh Management (DRFM). I wrote up a short article describing this new command, its semantics, and its shortcomings.
For more short articles on Rowhammer, see this page.
June '22
Row-sampling (e.g., PARA) is a simple, practical, and strong form of Rowhammer defense. But only if properly configured. We published a short paper at DRAMSec 2022 describing how to configure such a defense.
Watch the 15-minute presentation.

Recent Publications

How to Configure Row-Sampling-Based Rowhammer Defenses
Stefan Saroiu and Alec Wolman
DRAMSec 2022
MOESI-prime: Preventing Coherence-Induced Hammering in Commodity Workloads
Kevin Loughlin, Stefan Saroiu, Alec Wolman, Yatin A. Manerkar, and Baris Kasikci
ISCA 2022
The Price of Secrecy: How Hiding Internal DRAM Topologies Hurts Rowhammer Defenses
Stefan Saroiu, Alec Wolman, and Lucian Cojocar
IRPS 2022

Recent Service