About me

I am a Silicon Security Engineer at Google. Before that, I was a Senior Product Security Analyst at PQShield. Before that, I obtained my PhD degree, entitled “Cache Side-Channel Attacks on Existing and Emerging Computing Platforms”, at the COSIC group at KU Leuven in June 2023. During the summer of 2022, I interned at Intel Labs.

My professional interests are centered around {microarchitectural,software,hardware} security, as well as engineering efficient and secure cryptographic implementations.

In 2024, I found an exploitable (compiler-introduced) timing side-channel vulnerability in several implementations of ML-KEM (blog, code).

Selected Publications

Cache Side-Channel Attacks on Existing and Emerging Computing Platforms
Antoon Purnal
PhD Dissertation
Summa Cum Laude (top 5% of Engineering Faculty)

SpectrEM: Exploiting Electromagnetic Emanations During Transient Execution
Jesse De Meulemeester, Antoon Purnal, Lennert Wouters, Arthur Beckers, Ingrid Verbauwhede
USENIX Security '23

ShowTime: Amplifying Arbitrary CPU Timing Side Channels
Antoon Purnal, Marton Bognar, Frank Piessens, Ingrid Verbauwhede
AsiaCCS '23

Scatter and Split Securely: Defeating Cache Contention and Occupancy Attacks
Lukas Giner, Stefan Steinegger, Antoon Purnal, Maria Eichlseder, Thomas Unterluggauer, Stefan Mangard, and Daniel Gruss
S&P '23

Double Trouble: Combined Heterogeneous Attacks on Non-inclusive Cache Hierarchies
Antoon Purnal, Furkan Turan, Ingrid Verbauwhede
USENIX Security '22

Prime+Scope: Overcoming the Observer Effect for High-Precision Cache Contention Attacks
Antoon Purnal, Furkan Turan, Ingrid Verbauwhede
CCS '21

Systematic Analysis of Randomization-based Protected Cache Architectures
Antoon Purnal, Lukas Giner, Daniel Gruss, Ingrid Verbauwhede
S&P '21

Forkcipher: a new primitive for authenticated encryption of very short messages
Elena Andreeva, Virginie Lallemand, Antoon Purnal, Reza Reyhanitabar, Arnab Roy, Damian Vizár
ASIACRYPT '19

Trade-offs in protecting Keccak against combined side-channel and fault attacks
Antoon Purnal, Victor Arribas, Lauren De Meyer
COSADE '19
OneSpan MSc Thesis Award


Reviewing

  • TCHES 2024
  • External: USENIX Security 2023, 2022, 2021, 2020, 2019
  • External: COSADE 2022
  • External: IEEE EuroS&P 2021
  • External: HOST 2020
  • External: ESSCIRC 2019