Flavio ToffaliniView profile
Assistant Professor
Dr. Flavio Toffalini serves as Assistant Professor of Cybersecurity at Ruhr University Bochum (RUB) since September 2024, holding the Chair for Automated Security Analysis. His research group focuses on advancing system security through innovative approaches to software testing and trusted computing. Dr. Toffalini completed his Ph.D. at Singapore University of Technology and Design (SUTD) in 2021 under Professor Jianying Zhou, followed by postdoctoral research at EPFL's HexHive group with Professor Mathias Payer. His educational background includes a Master's degree from the University of Verona (2015) focused on web security. His research centers on system security with emphasis on automatic software testing (particularly fuzzing), threat mitigation, and trusted execution environments (SGX, TrustZone). Current projects explore browser/interpreter testing, memory safety mechanisms, and compiler-assisted security hardening. He actively develops novel fuzzing techniques to uncover deep vulnerabilities in complex systems. Analysis of his 2023-2025 publications reveals dominant themes in JavaScript engine security (DUMPLING), adaptive fuzzing (TuneFuzz), and trusted computing hardening (TLBlur). His work bridges theoretical security concepts with practical implementations, often yielding tools adopted by the security community. Notable scientific recognition includes: Distinguished Paper award at NDSS 2025 for JavaScript engine fuzzing research Distinguished Paper award at NDSS 2025 for type confusion mitigation Best Paper award at ACNS 2022 for IoT attestation systems Dr. Toffalini currently supervises three Ph.D. students (Tobias Wienand at RUB, Nicolas Badoux and Han Zheng at EPFL) and has guided multiple MSc theses. His research is supported through projects in software analysis, vulnerability detection, and system security, with active recruitment for students specializing in fuzzing and trusted computing. He leads the Automated Security Analysis research group at RUB, maintaining strong collaborations with EPFL's HexHive group. The team actively develops tools for interpreter testing, reverse engineering, and trusted execution environment security, with current projects focusing on extending fuzzing to new programming languages and mitigating microarchitectural vulnerabilities.





