Oussama Draissi
Olympiapark, Munich

Oussama Draissi

Security Researcher · Fuzzing & Binary Analysis

Open to industry roles · EU / remote

  • Systems Security Group, University of Duisburg-Essen
  • Dr.-Ing. expected 2027
  • Essen, Germany

About

I am a doctoral researcher in the Systems Security group at the University of Duisburg‑Essen, advised by Prof. Lucas Davi.

I work on memory corruption in sandboxed bytecode such as WebAssembly: finding it automatically with fuzzing and program analysis, and containing it with practical, low-overhead defenses. The same problems carry over to blockchains, trusted execution environments, and RISC-V.

Published at ACM CCS · ACM ISSTA · RAID · The Web Conference · IEEE CNS · ACNS

News

Research

Wemby — hunting memory corruption in WebAssembly
Wemby — Fuzzing WebAssembly for Memory Corruption on the Live Web

Wemby’s Web: Hunting for Memory Corruption in WebAssembly

ACM ISSTA 2025

The first holistic fuzzer for WebAssembly on the live web: 232× faster and +46% coverage over prior Wasm fuzzers, with real bugs found, including one on the Zoom platform. Across 37,797 domains, 77.81% pass unchecked Wasm memory into XSS-prone sinks.

Websites trust the data coming out of Wasm memory and pass it into sinks such as eval or innerHTML, so corrupting that memory becomes cross-site scripting. Wemby’s binary-only instrumentation adds memory-corruption oracles and taint tracking on top of SAP’s Foxhound browser. Joint work with TU Braunschweig and AWS.

Rust · Python · JavaScript · Foxhound (Firefox) · Taint tracking

Bento — fine-grained memory isolation for WebAssembly
Bento — Isolating a Wasm Module's Memory Into Separate Instances

Bento: Fine-Grained Memory Isolation for COTS WebAssembly Binaries

The Web Conference (WWW) 2026

The first static binary rewriter that hardens off-the-shelf WebAssembly modules: a software MMU built on Wasm multi-memory, with no new instructions and no runtime checks, stopping real exploits at 3% runtime / 1% startup overhead.

A whole-program pointer analysis splits a module’s single linear memory into stack, heap, and globals, each placed in its own isolated memory. Bento stops real exploits in libpng and pdfalto, and differential testing confirms the rewritten binaries behave the same. A compiler-pass version is in progress and will be open-sourced.

Rust · Binary rewriting · Whole-program pointer analysis · Wasm multi-memory

Waslr — fine-grained memory randomization for WebAssembly
Waslr — A Fresh Memory Layout on Every Module Instantiation

Waslr: Fine-Grained Memory Randomization for WebAssembly

RAID 2026

ASLR for WebAssembly: every module load gets a fresh, unpredictable memory layout, cutting the odds of a correct address guess to as low as 1 in 6.4M at 3–8% overhead, an order of magnitude below WBSan (34%) and ASan (123%).

Wasm has no virtual memory, page permissions, or kernel entropy, so exploits work the same on every machine. Waslr adds randomization inside the sandbox: a compiler pass randomizes every stack frame and a linker pass relocates static data at load time. The binary uses only standard Wasm features, so it runs unchanged in browsers and in runtimes such as Wasmtime. Against CVEs in libpng, pdfalto, and OpenSSL (Heartbleed), all 10,000 randomized exploit attempts failed.

LLVM compiler & linker passes · C++ · Wasmtime

FuzzDelSol — fuzzing Solana smart contracts
FuzzDelSol — Coverage-Guided Fuzzing of Solana Contract Binaries

FuzzDelSol: Fuzzing Solana Smart Contracts

ACM CCS 2023

The first binary-only, coverage-guided fuzzer for Solana smart contracts, and the largest security study of the Solana mainnet to date (6,049 contracts), finding impactful vulnerabilities with high precision and recall.

Most Solana contracts ship without source code, and their stateless execution model creates bugs that Ethereum tools miss. FuzzDelSol models the runtime faithfully and has bug oracles for every major Solana bug class.

Rust · Coverage-guided fuzzing · Solana eBPF binaries · Bug oracles

Attestation of microarchitectural attacks and complex software
Attestation of Microarchitectural Attacks and Complex Software

Attestation of Attacks and Complex Software

DFG CROSSING · Area S2

Taking remote attestation beyond embedded devices to microarchitectural attacks such as Rowhammer and to complex software such as WebAssembly applications and cross-chain bridges.

Includes HammerWatch (IEEE CNS 2026), which reports Rowhammer to a remote verifier; Walma, which learns to recognize memory corruption in WebAssembly; and Brigade (ACNS 2026), a Tamarin-verified defense against token losses in cross-chain bridges, evaluated on twelve real-world attacks.

Remote attestation · Rowhammer · TEEs · CNN classifiers · Tamarin proofs

Publications

My name is in bold. Full list on Google Scholar.

Talks

CV

Experience

Research Scientist & Doctoral Candidate · Systems Security, UDE 2022–now

Memory-safety analysis and defenses for WebAssembly, trusted execution, and emerging instruction sets (see Research). Mentoring student project groups and theses.

Research Assistant · Systems Security, UDE 2019–2022

RISC-V and TEE security; wrote exploits by hand and then automatically in RiscyROP, with Ahmad-Reza Sadeghi’s group at TU Darmstadt. Co-designed the mini-CTF exploitation lab for Secure Software Systems (M.Sc.).

Student Research Assistant · Systems Security, UDE 2017–2019

One of the group’s first hires. Wrote data-only exploits with pwntools for teaching and reproduced artifacts of academic security papers.

Education

Dr.-Ing. Computer Science · University of Duisburg‑Essen 2022–2027 (expected)

M.Sc. Software and Network Engineering · University of Duisburg‑Essen 2019–2022

WaWebFuzz — WebAssembly fuzzer for the web
WaWebFuzz — Web-Scale WebAssembly Fuzzing via wasm2c

Master’s thesis: WaWebFuzz, a WebAssembly Fuzzer for the Web

Fuzzed WebAssembly at web scale by compiling modules to native code with wasm2c. Of 2,844,980 websites crawled, 9,526 used WebAssembly, and 34% of the analyzed modules had memory errors. The bugs were hard to exploit without the surrounding page, which led to Wemby.

WAT — WebAssembly Analysis Toolkit
WAT — A Binary-Only WebAssembly Analysis Toolkit

WAT: WebAssembly Analysis Toolkit

To our knowledge the first binary-only Wasm fuzzer. It builds on Wasabi to generate fuzzing harnesses and crash oracles automatically, and drives them with AFL++.

DataMed — anomaly detection in insurance data
DataMed — Graph-Based Anomaly Detection in Insurance Claims

DataMed: Anomaly Detection in Medical Insurance Data

A graph-analysis prototype, built with the Barmenia insurance group, that flags patterns of organized insurance fraud, a problem estimated at €4–5 billion a year in Germany.

CompatAI — comparative training of AI agents
CompatAI — Emergent Cooperation Among Learning Agents

CompatAI: Comparative Training of AI Agents

Multi-agent reinforcement learning in Pommerman and Food Collector: a hierarchical communication scheme improved performance, and cooperation correlated with winning.

B.Sc. Applied Computer Science (Systems Engineering) · University of Duisburg‑Essen 2015–2019

FAILT — advanced information-leak exploitation
FAILT — Chasing Pointers to Defeat Memory Randomization

Bachelor’s thesis: FAILT, Automated Information-Leak Exploitation

Combined JIT-ROP and Pathfinder ideas to leak memory at runtime, recovering most of a binary’s segments under modern randomization and telling code pointers from data pointers with >90% accuracy. Key finding: extra defenses often add pointers that make leaks easier. Supervised by Michael Rodler.

Contact

Email me at oussama.draissi@protonmail.com. I’m based in Essen, Germany, and happy to talk about memory safety, fuzzing, and research or industry roles.