Gururaj Saileshwar · University of Toronto

Secure Computer Hardware & Systems

CSC2237 (Graduate, UTSG) & CSC498 (Undergraduate, UTM) · Fall 2026

Overview

In recent years, numerous hardware vulnerabilities have left software systems open to exploitation: processor speculation attacks like Spectre and Meltdown, cache side-channel attacks, and DRAM Rowhammer. These attacks let malicious software extract sensitive data, tamper with critical data, and even seize control of entire systems via privilege escalation.

This course covers both the offensive and defensive sides of micro-architectural security, spanning cache side-channel attacks, transient execution, Rowhammer, trusted execution environments, and memory safety, with material drawn from security (USENIX Security, IEEE S&P) and computer architecture (ISCA, MICRO, HPCA, ASPLOS) papers. Students will develop proof-of-concept exploits on real systems, complete two programming assignments, and undertake a mini-research project.

Course Information

Important Links

Prerequisites

A general understanding of computer organization and architecture, and operating systems is required. There is no textbook for this course, but material is drawn from security (USENIX Security, IEEE S&P) and computer architecture (ISCA, MICRO, HPCA, ASPLOS) papers.

Course Evaluation

The assignments are programming-based and involve coding up micro-architectural attacks on real systems. The paper reviews focus on security papers selected from the computer architecture (ISCA, MICRO, HPCA, ASPLOS) and security (IEEE S&P, USENIX Security) conferences. Please submit all the slides and reports required in the course in PDF format. Course projects can be done in teams of 1–2, and project topics must be approved by the instructor.

Policy on the Use of Artificial Intelligence

You are welcome to use AI assistants (ChatGPT) to help you understand course material and for brainstorming on your research project. You remain fully responsible for the correctness of the material you submit. Any use of AI tools on the research project should be disclosed in your submission. You may not use AI assistants for writing the paper reviews, or programming assignments or midterms. If you have any questions about this policy, please reach out.

Schedule

Lectures are on Mondays, 3:00 PM – 5:00 PM.

#DateTopicDeadlines
1Sep 14Introduction & Side-Channel Attacks
2Sep 21Defenses Against Side-Channel AttacksReview 1 due; Assignment 1 released
3Sep 28Transient Execution Attacks (Spectre, Meltdown)
4Oct 5Defenses Against Transient Execution AttacksAssignment 1 due; Assignment 2 released
5Oct 19Midterm 1Review 2 due; project proposal due
6Nov 2Rowhammer AttacksAssignment 2 due
7Nov 9Rowhammer DefensesReview 3 due
8Nov 16Trusted Execution Environments (TEEs)
9Nov 23Attacks and Defenses on TEEs
10Nov 30Midterm 2
11Dec 7Project Presentations
12Dec 8Project PresentationsProject report due Dec 8