Hey and welcome to my site. I am a security researcher from Austria. I defended my PhD titled Kernel Security in the Wild at the Institute of Information Security (former IAIK), Graz University of Technology. My research focuses on system security, with a particular focus on kernel attacks and defenses, side-channel attacks targeting the kernel, and Android kernel security.
mm_struct-backed page locations without relying on a memory-safety bug, with its POC having a near-100% success rate.msg_msg/pipe_buffer heap KASLR leaks: above 98% on desktop kernels and KernelCTF instances, and practical on the Android kernel.mm_struct addresses.
@inproceedings{Draschbacher2026Clone2Pwn,
author = {Florian Draschbacher and Lukas Maar and Lorenz Schumm and Rene Denifl and Lukas Treffner and Stefan Mangard},
booktitle = {{ESORICS}},
title = {{Clone2Pwn: A Systematic Security Analysis of Data Migration Tools in the Android Ecosystem}},
year = {2026}
}
@inproceedings{Neela2026EvictionNotive,
author = {Sudheendra Raghav Neela and Jonas Juffinger and Lukas Maar and Daniel Gruss},
booktitle = {{NDSS}},
title = {{Eviction Notice: Reviving and Advancing Page Cache Attacks}},
year = {2026}
}
@phdthesis{Maar2025KernelSecurityInTheWild,
author = {Lukas Maar},
title = {{Kernel Security in the Wild}},
year = {2025},
school = {Graz University of Technology},
type = {PhD thesis}
}
@inproceedings{Maar2025DeviceDrivers,
author = {Lukas Maar and Florian Draschbacher and Lorenz Schumm and Ernesto Martinez Garcia and Stefan Mangard},
booktitle = {{USENIX Security}},
title = {{The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel Vulnerabilities}},
year = {2025}
}
@inproceedings{Maar2025LocationDisclosures,
author = {Lukas Maar and Lukas Giner and Daniel Gruss and Stefan Mangard},
booktitle = {{USENIX Security}},
title = {{When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks}},
year = {2025}
}
@inproceedings{Draschbacher2025ChoiceJacking,
author = {Florian Draschbacher and Lukas Maar and Mathias Oberhuber and Stefan Mangard},
booktitle = {{USENIX Security}},
title = {{ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago}},
year = {2025}
}
@inproceedings{Unterguggenberger2025CLPE,
author = {Martin Unterguggenberger and David Schrammel and Lukas Maar and Lukas Lamster and Vedad Hadzic and Stefan Mangard},
booktitle = {{HOST}},
title = {{Cryptographic Least Privilege Enforcement for Scalable Memory Isolation}},
year = {2025}
}
@inproceedings{Maar2025KernelSnitch,
author = {Lukas Maar and Jonas Juffinger and Thomas Steinbauer and Daniel Gruss and Stefan Mangard},
booktitle = {{NDSS}},
title = {{KernelSnitch: Side-Channel Attacks on Kernel Data Structures}},
year = {2025}
}
@inproceedings{Oberhuber2025PowerAndroidSensor,
author = {Mathias Oberhuber and Martin Unterguggenberger and Lukas Maar and Andreas Kogler and Stefan Mangard},
booktitle = {{NDSS}},
title = {{Power-Related Side-Channel Attacks using the Android Sensor Framework}},
year = {2025}
}
@inproceedings{Draschbacher2024ManifestProblems,
author = {Florian Draschbacher and Lukas Maar},
booktitle = {{ACSAC}},
title = {{Manifest Problems: Analyzing Code Transparency for Android Application Bundles}},
year = {2024}
}
@inproceedings{Maar2024DefectsInDepth,
author = {Lukas Maar and Florian Draschbacher and Lukas Lamster and Stefan Mangard},
booktitle = {{USENIX Security}},
title = {{Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android Kernels}},
year = {2024}
}
@inproceedings{Maar2024SLUBStick,
author = {Lukas Maar and Stefan Gast and Martin Unterguggenberger and Mathias Oberhuber and Stefan Mangard},
booktitle = {{USENIX Security}},
title = {{SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel}},
year = {2024}
}
@inproceedings{Maar2024HEKCFI,
author = {Lukas Maar and Pascal Nasahl and Stefan Mangard},
booktitle = {{AsiaCCS}},
title = {{Beyond the Edges of Kernel Control-Flow Hijacking Protection with HEK-CFI}},
year = {2024}
}
@inproceedings{Gast2024Remote,
author = {Stefan Gast and Jonas Juffinger and Lukas Maar and Christoph Royer and Andreas Kogler and Daniel Gruss},
booktitle = {{FC}},
title = {{Remote Scheduler Contention Attacks}},
year = {2024}
}
@inproceedings{Maar2023DOPE,
author = {Lukas Maar and Martin Schwarzl and Fabian Rauscher and Daniel Gruss and Stefan Mangard},
booktitle = {{ACSAC}},
title = {{DOPE: DOmain Protection Enforcement with PKS}},
year = {2023}
}