§ Profile / 00

Claudio Migliorelli

EPFL · IBM Research Zürich

Avatar of Claudio Migliorelli
Predoctoral Researcher
Kernel security · Zürich, Switzerland

Welcome to my website. My name is Claudio. I am a Predoctoral Researcher at IBM Research Zürich and a PhD Student at EPFL (HexHive group), in Switzerland — supervised by Mathias Payer and co-supervised by Anil Kurmus. I am funded by an SNSF Grant (LinSpecteur). I have a Master's Degree in Computer Engineering from Politecnico di Milano and a Bachelor's Degree in Computer Science and Engineering from University of Rome "Tor Vergata".

My work is focused on the broad area of kernel security and hardening. More broadly, my work connects three areas: kernel-level heap feng shui, which studies how predictable allocator states can make exploitation more reliable; automated exploit generation, which helps distinguish truly dangerous kernel bugs from the large volume of issues found by fuzzers; and operating system hardening, which aims to reduce the impact and practicality of exploitation through stronger isolation and defensive design.

Publications

  • Discovering, characterizing and exploiting controllable-copy objects for kernel data-only attacks with CopyKat [PDF]
    • Jacob Koschel, Andrea Mambretti, Alessandro Sorniotti, Pietro Moretto, Claudio Migliorelli, Andrea Di Dio, Cristiano Giuffrida, Anil Kurmus.
    • 35th USENIX Security Symposium (USENIX Security), Baltimore, USA, August 2026.
  • Cross-Cache Attacks for the Linux Kernel via PCP Massaging [PDF, BIB, YT]
    • Claudio Migliorelli, Andrea Mambretti, Alessandro Sorniotti, Vittorio Zaccaria, Anil Kurmus.
    • Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, USA, February 2026.

Teaching and Supervision

The following is an overview of the courses for which I have served as a teaching assistant. My duties include conducting interactive exercise and laboratory sessions, as well as preparing course materials, exercises, and exams (including grading):

I supervise (and have supervised) students working on both Master's theses and practical projects, at different institutions. The following is a summary of what I did. If you're interested in pursuing a Semester Project under my supervision at EPFL, explore the available topics on the HexHive's projects page, or drop me an e-mail (see Contact).

EPFL

Semester Projects

  • Miloš Medic, Kernel objects and where to find them (2026) - MSc Semester Project @ HexHive Laboratory.

Politecnico di Milano

Master's Thesis Supervision

  • Federico Zanca, Exploring Data-Only Privilege Escalation through Use-After-Free Corruption of Linux Kernel Stacks (2026).

Course Projects

Since 2023, I have served as a project assistant for the Advanced Operating Systems Master's course at Politecnico di Milano, a role I continue to hold. Over the years, I have proposed numerous kernel security related projects and guided students through their development. Below is a quick overview of some of such projects:

  • Hijacking system calls via direct table modification [link];
  • UAF-OOB pivoting attack in the SLUB allocator [link];
  • Page-level UAF using struct pipe_buffer (and struct page pointer corruption) [link];
  • Cross-cache attacks via page reclamation [link].

Service

I have served as a reviewer for the following conferences and journals:

  • USENIX '26 (External Reviewer)

Invited talks and presentations

Contact

If you'd like to get in touch, email is the best way to reach me. You can also find me on a few other platforms.

You can find my GPG key below.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEagGh5hYJKwYBBAHaRw8BAQdA0IM6AsBcorLSdUlJajq6l8a1P9O1kMcx7l1m
O7I9Wu+0YENsYXVkaW8gTWlnbGlvcmVsbGkgKEtleSBmb3IgZS1tYWlsIGV4Y2hh
bmdlIG9uIHRoZSBFUEZMIGFkZHJlc3MuKSA8Y2xhdWRpby5taWdsaW9yZWxsaUBl
cGZsLmNoPoiWBBMWCgA+FiEEWmHOfHysn/A4v0Xa1dAxibTdmbAFAmoBoeYCGwMF
CQeEzgAFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ1dAxibTdmbDKPgEA09aG
LkkKtCxmyWetxNzPwo7FSkfQ/NtYpZbYH7FBhuEBAKKRJs5ntHsEO+SXtGKf/5Hz
YOWzyzU+M1Ir5XnJ/agGuDgEagGh5hIKKwYBBAGXVQEFAQEHQDQitJqzEtICp/wc
UGouz0ZNHu1UujoSzNt7bzyZRsdfAwEIB4h+BBgWCgAmFiEEWmHOfHysn/A4v0Xa
1dAxibTdmbAFAmoBoeYCGwwFCQeEzgAACgkQ1dAxibTdmbCwvAD/Xh/fv1HvUxSu
vqGwM5wsPADJ0H81GBKTpl4JvaHCxzsBAOHIbqCgSQOr04ttFIOu4ibRTyPd7RxB
qY08nG0Od20L
=Y95h
-----END PGP PUBLIC KEY BLOCK-----