Tracking Down Security Vulnerabilities at the Software-Hardware Interface: A Look at the SUSHI Team

On May 13, the Rennes campus hosted the Cash Investigation team for a TV report on cyberattacks and information system security. Among the experts interviewed was Guillaume Hiet, a professor at CentraleSupélec who leads the SUSHI (SecUrity at the Software/Hardware Interface) research team and the “Cybersecurity” specialized engineering program, was invited to share his expertise on the components of a cyberattack presented by the journalists. This news story provides an opportunity to learn about the research being conducted on the Rennes campus and the programs that help prepare engineers for the challenges of cybersecurity. 

Le 24 September 2026 #Recherche
Image
cybersecurité
  • Partager
  • At the interface between software and hardware 

    Image
    Equipe SUSHI

    Part of IRISA’s Architecture Department, the SUSHI team brings together researchers from CentraleSupélec, Inria, and ENS Rennes to focus on a specific area of cybersecurity: the interface between software and hardware. 

    On one hand, software security focuses primarily on applications and the systems that run them. On the other, hardware security deals with the physical components of computer systems. Between the two lies a critical interface: the one that allows software to utilize the hardware resources on which it runs. 

     

    “This interface is both a potential source of vulnerabilities and a lever for strengthening system security,” explains Guillaume Hiet. 

    These interactions between software and hardware pose a major challenge for the security of computing platforms. Certain attacks can exploit the interactions between hardware and software, while these interactions can also be leveraged to enhance security. SUSHI is therefore studying how to combine the properties of hardware and software to better protect systems, as well as how to assess and demonstrate their level of security.

    Image
    Computing system

    This interface is becoming increasingly important as computing systems evolve. To meet ever-increasing demands for performance and new services, while limiting energy consumption, architectures now combine numerous computing units with different functions: processors, graphics processing units (GPUs), accelerators dedicated to artificial intelligence, FPGAs, and so on. These components, combined with software layers such as operating systems, hypervisors, and firmware, give rise to increasingly complex interactions.

    This complexity can give rise to new vulnerabilities, but it also makes it possible to integrate new security features directly into the hardware. This is one of the key focuses of the team’s collaborations with industry partners, such as HP Labs: designing hardware mechanisms capable of providing additional security features, independent of the software running on the machine. 

     

    3 Research Areas to Better Understand and Strengthen System Security 

    SUSHI’s work is organized around three main areas.

    Image
    Side channel analysis tool
    Outils d’analyse des canaux auxiliaires (Side channels) 

    Identifying and mitigating vulnerabilities: The team is working in particular on analyzing software in binary form, without access to its source code. As part of a collaboration with Thales, a CIFRE doctoral thesis is exploring methods to assist and automate certain stages of security assessment, particularly through the use of artificial intelligence. SUSHI also studies vulnerabilities related to microarchitecture—that is, the way hardware is designed and implemented. Certain properties of this microarchitecture can indeed be exploited by an attacker, particularly through side-channel attacks. 

     

    Detecting intrusions and enabling systems to respond: SUSHI investigates how hardware and virtualization mechanisms can help detect intrusions and strengthen system resilience. The goal: to enable a compromised machine to respond automatically and return to a state secure enough to continue operating, possibly in degraded mode. 

    Ensuring security through formal methods: Finally, the team is developing approaches based on formal methods, which use mathematical models and proofs to verify that a security mechanism functions as intended. This work focuses in particular on mechanisms that combine hardware and software. Research in this area has been conducted in collaboration with ANSSI and is currently continuing with the CEA. 

     

    Training Engineers in Cybersecurity: A Challenge for Everyone

    While SUSHI contributes to research on highly technical cybersecurity issues, Guillaume Hiet also emphasizes another challenge: making cybersecurity a skill shared by all engineers.

    In Rennes, CentraleSupélec has been offering specialized courses in this field for several years, including a cybersecurity major within the general engineering curriculum. The program also includes the Specialized Master’s® in Cybersecurity, offered through Exed CentraleSupélec and led in Rennes by Valérie Viet Triem Tong, head of the PIRAT research team. Since 2025, a specialized engineering program in cybersecurity, led by Guillaume Hiet, has rounded out this offering.

    For Hiet, however, raising awareness of cybersecurity cannot be limited to future specialists alone. Many engineers are called upon, throughout their careers, to design, develop, or deploy digital systems and must therefore be able to integrate security considerations into their projects from the very beginning. 

    “Cybersecurity, however, cannot be the sole responsibility of specialists. We can no longer deploy systems while telling ourselves that we’ll address cybersecurity issues only when we encounter a problem,” explains Guillaume Hiet.

    This approach also takes on particular significance in a context where mastery of digital technologies is a matter of sovereignty for France and Europe. From hardware to operating systems, developing the knowledge, skills, and technologies necessary for system security helps strengthen this capacity for mastery.

    “Beyond training specialists, the goal is therefore to equip every engineer with the knowledge needed to identify security challenges related to their future projects and responsibilities,” emphasizes Guillaume Hiet. 

    Cybersecurity training thus addresses a twofold challenge: equipping all engineers with the tools to incorporate security into their projects, while simultaneously developing in-depth expertise among future specialists in the field. 

    A Team at the Heart of the Cybersecurity Research Community

    SUSHI also helps foster the international cybersecurity community.  

    From September 14 to 18, the SUSHI team attended the ESORICS 2026 international conference in Rome, where Thomas Rokicki recently received a Best Paper Award for his work on assessing the threat of microarchitectural attacks on the cloud (Guillaume Didier, Augustin Lucas, Jasper Quirk, Thomas Rokicki. clflush-based Attacks on Modern Cloud Servers. ESORICS 2026—31st European Symposium on Research in Computer Security, Sep 2026, Rome, Italy. ⟨hal-05668056⟩). Rokicki also organized the HS3 workshop, held in conjunction with the conference.

    From October 28 to 30, the team will also be in Rennes for ISC 2026, an international conference that it is organizing this year. The event will bring together researchers and cybersecurity professionals to address issues related to the security of computer systems.

     

    From basic research to training, including industrial collaborations and international scientific exchanges, SUSHI contributes to developing the knowledge, skills, and technologies necessary for the security of digital systems.

    In a geopolitical context where mastery of digital technologies is an increasingly critical issue of sovereignty, this work takes on special significance. It aligns with one of the key priorities of CentraleSupélec’s 2023–2032 strategic plan: strengthening industrial, digital, technological, and European sovereignty, particularly through research and education.

     

    To learn more: watch Guillaume Hiet’s remarks at 1:08 in the Cash Investigation replay, “Cyber Scams: Do the Government and Companies Really Protect Us?”