• Skip to content (access key 1)
  • Skip to search (access key 7)
FWF — Austrian Science Fund
  • Go to overview page Discover

    • Research Radar
      • Research Radar Archives 1974–1994
      • Open API
    • Discoveries
      • Emmanuelle Charpentier
      • Adrian Constantin
      • Monika Henzinger
      • Ferenc Krausz
      • Wolfgang Lutz
      • Walter Pohl
      • Christa Schleper
      • Elly Tanaka
      • Anton Zeilinger
    • Impact Stories
      • Ruth Breu
      • Verena Gassner
      • Wolfgang Lechner
      • Birgit Mitter
      • Oliver Spadiut
      • Georg Winter
    • scilog Magazine
    • Austrian Science Awards
      • FWF Wittgenstein Awards
      • FWF ASTRA Awards
      • FWF START Awards
      • Award Ceremony
    • excellent=austria
      • Clusters of Excellence
      • Emerging Fields
    • In the Spotlight
      • 40 Years of Erwin Schrödinger Fellowships
      • Quantum Austria
    • Dialogs and Talks
      • think.beyond Summit
    • Knowledge Transfer Events
    • E-Book Library
  • Go to overview page Funding

    • Portfolio
      • excellent=austria
        • Clusters of Excellence
        • Emerging Fields
      • Projects
        • Principal Investigator Projects
        • Principal Investigator Projects International
        • Clinical Research
        • 1000 Ideas
        • Arts-Based Research
        • FWF Wittgenstein Award
      • Careers
        • ESPRIT
        • FWF ASTRA Awards
        • Erwin Schrödinger
        • doc.funds
        • doc.funds.connect
      • Collaborations
        • Specialized Research Groups
        • Special Research Areas
        • International – Multilateral Initiatives
        • #ConnectingMinds
      • Communication
        • Top Citizen Science
        • Science Communication
        • Book Publications
        • Digital Publications
        • Open-Access Block Grant
      • Subject-Specific Funding
        • Belmont Forum
        • ERA-NET HERA
        • ERA-NET NORFACE
        • ERA-NET QuantERA
        • Alternative Methods to Animal Testing
        • European Partnership BE READY
        • European Partnership Biodiversa+
        • European Partnership BrainHealth
        • European Partnership ERA4Health
        • European Partnership ERDERA
        • European Partnership EUPAHW
        • European Partnership FutureFoodS
        • European Partnership OHAMR
        • European Partnership PerMed
        • European Partnership Water4All
        • Gottfried and Vera Weiss Award
        • LUKE – Ukraine
        • netidee SCIENCE
        • Herzfelder Foundation Projects
        • Quantum Austria
        • Rückenwind Funding Bonus
        • TRANSCAN
        • WE&ME Award
        • Zero Emissions Award
      • International Collaborations
        • Belgium/Flanders
        • Germany
        • France
        • Israel
        • Italy/South Tyrol
        • Japan
        • Korea
        • Luxembourg
        • Poland
        • Switzerland
        • Slovakia
        • Slovenia
        • Taiwan
        • Tyrol-South Tyrol-Trentino
        • Czech Republic
        • Hungary
    • Step by Step
      • Find Funding
      • Submitting Your Application
      • International Peer Review
      • Funding Decisions
      • Carrying out Your Project
      • Closing Your Project
      • Further Information
        • Integrity and Ethics
        • Inclusion
        • Applying from Abroad
        • Personnel Costs
        • PROFI
        • Final Project Reports
        • Final Project Report Survey
    • FAQ
      • Project Phase PROFI
      • Project Phase Ad Personam
      • Expiring Programs
        • Elise Richter and Elise Richter PEEK
        • FWF START Awards
        • Research Groups
        • AI Mission Austria
  • Go to overview page About Us

    • Mission Statement
    • FWF Video
    • Values
    • Facts and Figures
    • Annual Report
    • What We Do
      • Research Funding
        • Matching Funds Initiative
      • International Collaborations
      • Studies and Publications
      • Equal Opportunities and Diversity
        • Objectives and Principles
        • Measures
        • Creating Awareness of Bias in the Review Process
        • Terms and Definitions
        • Your Career in Cutting-Edge Research
      • Open Science
        • Open-Access Policy
          • Open-Access Policy for Peer-Reviewed Publications
          • Open-Access Policy for Peer-Reviewed Book Publications
          • Open-Access Policy for Research Data
        • Research Data Management
        • Citizen Science
        • Open Science Infrastructures
        • Open Science Funding
      • Evaluations and Quality Assurance
      • Academic Integrity
      • Science Communication
      • Philanthropy
      • Sustainability
    • History
    • Legal Basis
    • Organization
      • Executive Bodies
        • Executive Board
        • Supervisory Board
        • Assembly of Delegates
        • Scientific Board
        • Juries
      • FWF Office
    • Jobs at FWF
  • Go to overview page News

    • News
    • Press
      • Logos
    • Calendar
      • Post an Event
      • FWF Informational Events
    • Job Openings
      • Enter Job Opening
    • Newsletter
  • Discovering
    what
    matters.

    FWF-Newsletter Press-Newsletter Calendar-Newsletter Job-Newsletter scilog-Newsletter

    SOCIAL MEDIA

    • LinkedIn, external URL, opens in a new window
    • , external URL, opens in a new window
    • Facebook, external URL, opens in a new window
    • Instagram, external URL, opens in a new window
    • YouTube, external URL, opens in a new window

    SCILOG

    • Scilog — The science magazine of the Austrian Science Fund (FWF)
  • elane login, external URL, opens in a new window
  • Scilog external URL, opens in a new window
  • de Wechsle zu Deutsch

  

NeRAM: Next-Generation Rowhammer Attacks and Mitigations

Daniel Gruss (ORCID: 0000-0002-7977-3246)
  • Grant DOI 10.55776/I6054
  • Funding program Principal Investigator Projects International
  • Status Ended
  • Start December 1, 2022
  • End December 31, 2025
  • Funding amount € 360,014

Weave

Disciplines

Computer Sciences (100%)

Keywords

  • System Security,
  • Rowhammer,
  • Software-based Attacks,
  • Software-based Defenses
Abstract Final report

Modern computers have several gigabytes of DRAM memory that is used to store basically all data processed by the computer while it is running. DRAM memory itself consists of cells that store the 1`s and 0`s in capacitors - for example, charged for a 1 and discharged for a 0. Manufacturers are constantly increasing the density of chips and thus decreasing the capacitance of these capacitors in order to optimize storage capacity, performance and efficiency . The result is that parasitic effects can occur, such as the Rowhammer effect. With the Rowhammer effect, high-frequency accesses to two DRAM capacitors ensure that an adjacent capacitor loses so much charge that a stored 1 is read as a 0 the next time it is accessed. This seemingly small problem fundamentally undermines system security, since a single bit can decide whether a program has administrator rights or not. The aim of our research project "NeRAM" is to better understand the Rowhammer effect, to investigate countermeasures and to develop new effective countermeasures. To this end, we investigate the extent of the Rowhammer effect using automated frameworks. An important part is to describe yet unknown properties of the Rowhammer effect, especially those arising in different environments, such as the effects of temperature, EM radiation and aging. In addition, we also examine the Rowhammer effect on devices that have not yet been examined in the context of Rowhammer, namely graphics cards. Graphics cards have special GDDR DRAM memory, which we expect to be vulnerable to Rowhammer-based attacks. On this basis, we will finally propose countermeasures against Rowhammer that specifically protect data from the operating system. We will then use prototypes to demonstrate the effectiveness of the countermeasures. NeRAM is a research collaboration between Florian Adamsky (University of Applied Sciences Hof) and Daniel Gruss (Graz University of Technology).

Modern computers can fail in unexpected ways: simply accessing memory many times in a row can disturb nearby data and silently change it. This effect, known as Rowhammer, can be abused by attackers to bypass security mechanisms. Our project shows that this is not just a theoretical risk - it already affects real-world systems. Our most important result is FlippyRAM, a large-scale user study on Rowhammer in the wild. We developed an easy-to-use testing tool and invited volunteers from the public and the research community to run it on their own computers. In total, we collected more than 1000 datasets from over 800 different systems, making this one of the most comprehensive studies of its kind. The result is clear: about one in ten systems tested showed this dangerous behavior. This demonstrates that Rowhammer remains a real and relevant security risk in everyday devices. At the same time, our study explains why such attacks are not yet widespread in practice. Successfully triggering Rowhammer is difficult and depends strongly on the exact hardware and system configuration. In many cases, attacks fail because the internal structure of memory is hard to reconstruct automatically. Our follow-up research significantly improved these analysis techniques, making it much easier to detect vulnerable systems - even for modern memory technologies. Another key insight from our work is that scientific results in this field must be interpreted carefully. By systematically reviewing previous studies, we found that many experiments rely on small test sets or unrealistic assumptions. This can lead to misleading conclusions about real-world risks. Our work helps make future research more reliable and comparable. Finally, we explored practical defenses. We developed new protection mechanisms that can detect and stop harmful memory access patterns early. Our results show that effective protection is possible with only minor performance impact - if supported by future hardware designs. Overall, our project provides a realistic picture of how widespread this hidden hardware weakness is, explains why it is difficult to exploit, and shows how it can be mitigated. These insights contribute to improving the security of everyday devices, cloud services, and critical digital infrastructure.

Research institution(s)
  • Technische Universität Graz - 100%
International project participants
  • Florian Adamsky - Germany, project partner

Research Output

  • 63 Citations
  • 21 Publications
  • 2 Methods & Materials
  • 5 Datasets & models
  • 1 Software
  • 2 Disseminations
  • 2 Fundings
Publications
  • 2026
    Title Advancing CPU Security through Attack Discovery and Systematization
    Type PhD Thesis
    Author Rauscher, Fabian
  • 2026
    Title Eviction Notice: Reviving and Advancing Page Cache Attacks
    Type Conference Proceeding Abstract
    Author Neela Sr
    Conference Network and Distributed System Security (NDSS) Symposium 2026
    Link Publication
  • 2026
    Title Memory Band-Aid: A Principled Rowhammer Defense-in-Depth
    Type Conference Proceeding Abstract
    Author Fiedler C
    Conference Network and Distributed System Security (NDSS) Symposium 2026
    Link Publication
  • 2026
    Title Continuous User Behavior Monitoring using DNS Cache Timing Attacks
    Type Conference Proceeding Abstract
    Author Weissteiner H
    Conference Network and Distributed System Security (NDSS) Symposium 2026
    Link Publication
  • 2026
    Title FLIPPYRAM: A Large-Scale Study of Rowhammer Prevalence
    Type Conference Proceeding Abstract
    Author Heckel M
    Conference Network and Distributed System Security (NDSS) Symposium 2026
    Link Publication
  • 2025
    Title A Systematic Evaluation of Novel and Existing Cache Side Channels
    DOI 10.14722/ndss.2025.230253
    Type Conference Proceeding Abstract
    Author Rauscher F
  • 2025
    Title KernelSnitch: Side Channel-Attacks on Kernel Data Structures
    DOI 10.14722/ndss.2025.240223
    Type Conference Proceeding Abstract
    Author Maar L
    Link Publication
  • 2025
    Title Secret Spilling Drive: Leaking User Behavior through SSD Contention
    DOI 10.14722/ndss.2025.230208
    Type Conference Proceeding Abstract
    Author Juffinger J
    Link Publication
  • 2024
    Title Cross-Core Interrupt Detection: Exploiting User and Virtualized IPIs
    DOI 10.1145/3658644.3690242
    Type Conference Proceeding Abstract
    Author Rauscher F
    Pages 94-108
    Link Publication
  • 2024
    Title IdleLeak: Exploiting Idle State Side Effects for Information Leakage
    DOI 10.14722/ndss.2024.24078
    Type Conference Proceeding Abstract
    Author Rauscher F
    Link Publication
  • 2024
    Title Presshammer: Rowhammer and Rowpress Without Physical Address Information
    DOI 10.1007/978-3-031-64171-8_24
    Type Book Chapter
    Author Juffinger J
    Publisher Springer Nature
    Pages 460-479
  • 2024
    Title Generic and Automated Drive-by GPU Cache Attacks from the Browser
    DOI 10.1145/3634737.3656283
    Type Conference Proceeding Abstract
    Author Giner L
    Pages 128-140
    Link Publication
  • 2025
    Title Fast and Efficient Secure L1 Caches for SMT
    DOI 10.1007/978-3-032-00627-1_6
    Type Book Chapter
    Author Giner L
    Publisher Springer Nature
    Pages 106-126
  • 2025
    Title Systematic Analysis of Kernel Security Performance and Energy Costs
    DOI 10.1145/3708821.3736197
    Type Conference Proceeding Abstract
    Author Rauscher F
    Pages 1676-1689
    Link Publication
  • 2025
    Title Epistemology of Rowhammer Attacks: Threats to Rowhammer Research Validity
    DOI 10.1007/978-3-032-07894-0_11
    Type Book Chapter
    Author Heckel M
    Publisher Springer Nature
    Pages 204-223
  • 2025
    Title Verifying DRAM Addressing in Software
    DOI 10.1007/978-3-032-07894-0_10
    Type Book Chapter
    Author Heckel M
    Publisher Springer Nature
    Pages 184-203
  • 2025
    Title Zero-Click SnailLoad: From Minimal to No User Interaction
    DOI 10.1007/978-3-032-07901-5_6
    Type Book Chapter
    Author Gast S
    Publisher Springer Nature
    Pages 106-125
  • 2025
    Title The HMB Timing Side Channel: Exploiting the SSD’s Host Memory Buffer
    DOI 10.1007/978-3-031-97620-9_10
    Type Book Chapter
    Author Juffinger J
    Publisher Springer Nature
    Pages 169-190
  • 2025
    Title Cohere+Reload: Re-enabling High-Resolution Cache Attacks on AMD SEV-SNP
    DOI 10.1007/978-3-031-97620-9_11
    Type Book Chapter
    Author Giner L
    Publisher Springer Nature
    Pages 191-212
  • 2025
    Title Microarchitectural Attacks and Defenses for Isolated Domains
    Type PhD Thesis
    Author Giner, Lukas
  • 2024
    Title SnailLoad: Exploiting Remote Network Latency Measurements without JavaScript
    Type Other
    Author Gast S.
    Pages 2315-2332
Methods & Materials
  • 2024 Link
    Title FlippyRAM: Automated Rowhammer Testing Framework and Large-Scale User Study
    Type Improvements to research infrastructure
    Public Access
    Link Link
  • 2023 Link
    Title SplitCache Extension for CacheSim
    Type Improvements to research infrastructure
    Public Access
    Link Link
Datasets & models
  • 2026 Link
    Title Eviction Notice: Systematic page cache side-channel analysis technique
    Type Data analysis technique
    Public Access
    Link Link
  • 2026 Link
    Title Memory Band-Aid: Bandwidth-based control model for Rowhammer mitigation
    Type Computer model/algorithm
    Public Access
    Link Link
  • 2024 Link
    Title DramaVerify: Software-based DRAM addressing verification technique
    Type Data analysis technique
    Public Access
    Link Link
  • 2024 Link
    Title FLIPPYRAM: Automated large-scale Rowhammer analysis framework
    Type Data analysis technique
    Public Access
    Link Link
  • 2024 Link
    Title KernelSnitch: Software-based side-channel analysis of kernel data structures
    Type Data analysis technique
    Public Access
    Link Link
Software
  • 2024 Link
    Title FlippyRAM framework
    Link Link
Disseminations
  • 2025 Link
    Title Chaos Communication Congress - User Study Results
    Type A talk or presentation
    Link Link
  • 2024 Link
    Title Chaos Communication Congress - User Study
    Type Participation in an activity, workshop or similar
    Link Link
Fundings
  • 2022
    Title Next-Generation Rowhammer Attacks and Mitigations
    Type Research grant (including intramural programme)
    Start of Funding 2022
    Funder German Research Foundation
  • 2022
    Title NeRAM: Next-Generation Rowhammer Attacks and Mitigations
    Start of Funding 2022
    Funder Austrian Science Fund (FWF)

Discovering
what
matters.

Newsletter

FWF-Newsletter Press-Newsletter Calendar-Newsletter Job-Newsletter scilog-Newsletter

Contact

Austrian Science Fund (FWF)
Georg-Coch-Platz 2
(Entrance Wiesingerstraße 4)
1010 Vienna

office(at)fwf.ac.at
+43 1 505 67 40

General information

  • Job Openings
  • Jobs at FWF
  • Press
  • Philanthropy
  • scilog
  • FWF Office
  • Social Media Directory
  • LinkedIn, external URL, opens in a new window
  • , external URL, opens in a new window
  • Facebook, external URL, opens in a new window
  • Instagram, external URL, opens in a new window
  • YouTube, external URL, opens in a new window
  • Cookies
  • Whistleblowing/Complaints Management
  • Accessibility Statement
  • Data Protection
  • IFG-Form
  • Acknowledgements
  • © Österreichischer Wissenschaftsfonds FWF
© Österreichischer Wissenschaftsfonds FWF