{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T08:27:09Z","timestamp":1786782429267,"version":"build-2736575974"},"reference-count":49,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T00:00:00Z","timestamp":1783900800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100031478","name":"NextGenerationEU","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100031478","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100012352","name":"University of Milan","doi-asserted-by":"publisher","award":["PE00000014"],"award-info":[{"award-number":["PE00000014"]}],"id":[{"id":"10.13039\/100012352","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100021856","name":"Ministero dell'Universit\u00e0 e della Ricerca","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100021856","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.cose.2026.105029","type":"journal-article","created":{"date-parts":[[2026,7,6]],"date-time":"2026-07-06T15:10:44Z","timestamp":1783350644000},"page":"105029","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["RemOTA: Remote attestation for detecting use-after-free in low-power microcontrollers"],"prefix":"10.1016","volume":"170","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2722-7178","authenticated-orcid":false,"given":"Matteo","family":"Zoia","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0570-0328","authenticated-orcid":false,"given":"Mirco","family":"Picca","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-3648-7416","authenticated-orcid":false,"given":"Davide","family":"Rusconi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-3301-5253","authenticated-orcid":false,"given":"Andrea","family":"Monzani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7114-5640","authenticated-orcid":false,"given":"Flavio","family":"Toffalini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5905-5976","authenticated-orcid":false,"given":"Danilo","family":"Bruschi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1544-3758","authenticated-orcid":false,"given":"Andrea","family":"Lanzi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.cose.2026.105029_b1","doi-asserted-by":"crossref","unstructured":"Abera, T., Asokan, N., Davi, L., Ekberg, J.-E., Nyman, T., Paverd, A., Sadeghi, A.-R., Tsudik, G., 2016. C-FLAT: control-flow attestation for embedded systems software. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. pp. 743\u2013754.","DOI":"10.1145\/2976749.2978358"},{"key":"10.1016\/j.cose.2026.105029_b2","doi-asserted-by":"crossref","unstructured":"Almakhdhub, N.S., Clements, A.A., Bagchi, S., Payer, M., 2020. muRAI: Securing Embedded Systems with Return Address Integrity. In: Network and Distributed Systems Security (NDSS) Symposium.","DOI":"10.14722\/ndss.2020.24016"},{"key":"10.1016\/j.cose.2026.105029_b3","series-title":"Program Analysis and Specialization for the C Programming Language","author":"Andersen","year":"1994"},{"key":"10.1016\/j.cose.2026.105029_b4","unstructured":"Arm Ltd, 2016. System design with ARMv8-M. https:\/\/developer.arm.com\/docs\/100767\/0100\/system-design-for-armv8m."},{"key":"10.1016\/j.cose.2026.105029_b5","series-title":"Proceedings of the ACM SIGPLAN 1994 Conference on Programming Language Design and Implementation","first-page":"290","article-title":"Efficient detection of all pointer and array access errors","author":"Austin","year":"1994"},{"key":"10.1016\/j.cose.2026.105029_b6","series-title":"Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering","article-title":"Efficient greybox fuzzing to detect memory errors","author":"Ba","year":"2023"},{"issue":"6","key":"10.1016\/j.cose.2026.105029_b7","doi-asserted-by":"crossref","first-page":"158","DOI":"10.1145\/1133255.1134000","article-title":"DieHard: probabilistic memory safety for unsafe languages","volume":"41","author":"Berger","year":"2006","journal-title":"SIGPLAN Not."},{"key":"10.1016\/j.cose.2026.105029_b8","series-title":"NDSS","first-page":"1","article-title":"IoTFuzzer: Discovering memory corruptions in IoT through app-based fuzzing","author":"Chen","year":"2018"},{"key":"10.1016\/j.cose.2026.105029_b9","unstructured":"Clements, A.A., Almakhdhub, N.S., Bagchi, S., Payer, M., 2018. {ACES}: Automatic compartments for embedded systems. In: 27th USENIX Security Symposium. USENIX Security 18, pp. 65\u201382."},{"key":"10.1016\/j.cose.2026.105029_b10","unstructured":"Costin, A., Zaddach, J., Francillon, A., Balzarotti, D., 2014. A {Large-scale} analysis of the security of embedded firmwares. In: 23rd USENIX Security Symposium. USENIX Security 14, pp. 95\u2013110."},{"key":"10.1016\/j.cose.2026.105029_b11","series-title":"26th USENIX Security Symposium","first-page":"131","article-title":"Efficient protection of path-sensitive control security","author":"Ding","year":"2017"},{"key":"10.1016\/j.cose.2026.105029_b12","series-title":"Proceedings of the 38th ACM International Conference on Supercomputing","first-page":"376","article-title":"RTT-UAF: Reuse time tracking for use-after-free detection","author":"Du","year":"2024"},{"key":"10.1016\/j.cose.2026.105029_b13","series-title":"31st USENIX Security Symposium","first-page":"2281","article-title":"Holistic control-flow protection on real-time embedded systems with kage","author":"Du","year":"2022"},{"key":"10.1016\/j.cose.2026.105029_b14","series-title":"Network and Distributed System Security Symposium","article-title":"Stack bounds protection with low fat pointers","author":"Duck","year":"2017"},{"key":"10.1016\/j.cose.2026.105029_b15","series-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1307","article-title":"DangZero: Efficient use-after-free detection via direct page table access","author":"Gorter","year":"2022"},{"key":"10.1016\/j.cose.2026.105029_b16","series-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","first-page":"517","article-title":"TypeSan: Practical type confusion detection","author":"Haller","year":"2016"},{"key":"10.1016\/j.cose.2026.105029_b17","series-title":"31st USENIX Security Symposium","first-page":"2497","article-title":"FreeWill: Automatically diagnosing use-after-free bugs via reference miscounting detection on binaries","author":"He","year":"2022"},{"issue":"5","key":"10.1016\/j.cose.2026.105029_b18","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1145\/347636.348916","article-title":"Which pointer analysis should I use?","volume":"25","author":"Hind","year":"2000","journal-title":"SIGSOFT Softw. Eng. Notes"},{"key":"10.1016\/j.cose.2026.105029_b19","series-title":"2020 USENIX Annual Technical Conference","first-page":"249","article-title":"FuZZan: Efficient sanitizer metadata design for fuzzing","author":"Jeon","year":"2020"},{"key":"10.1016\/j.cose.2026.105029_b20","series-title":"NDSS","article-title":"Preventing use-after-free with dangling pointers nullification","author":"Lee","year":"2015"},{"key":"10.1016\/j.cose.2026.105029_b21","series-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1901","article-title":"PACMem: Enforcing spatial and temporal memory safety via ARM pointer authentication","author":"Li","year":"2022"},{"key":"10.1016\/j.cose.2026.105029_b22","unstructured":"Microelectronics, S., 2020. Reference manual. https:\/\/www.st.com\/en\/microcontrollers-microprocessors\/stm32l5-series.html."},{"key":"10.1016\/j.cose.2026.105029_b23","series-title":"2021 IEEE East-West Design & Test Symposium","first-page":"1","article-title":"Control-flow integrity for real-time operating systems: Open issues and challenges","author":"Moghadam","year":"2021"},{"issue":"6","key":"10.1016\/j.cose.2026.105029_b24","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1145\/1543135.1542504","article-title":"SoftBound: highly compatible and complete spatial memory safety for c","volume":"44","author":"Nagarakatte","year":"2009","journal-title":"SIGPLAN Not."},{"key":"10.1016\/j.cose.2026.105029_b25","series-title":"Proceedings of the 30th ACM SIGPLAN Conference on Programming Language Design and Implementation","first-page":"245","article-title":"SoftBound: highly compatible and complete spatial memory safety for c","author":"Nagarakatte","year":"2009"},{"key":"10.1016\/j.cose.2026.105029_b26","series-title":"Proceedings of the 2010 International Symposium on Memory Management","first-page":"31","article-title":"CETS: compiler enforced temporal safety for C","author":"Nagarakatte","year":"2010"},{"issue":"3","key":"10.1016\/j.cose.2026.105029_b27","doi-asserted-by":"crossref","first-page":"477","DOI":"10.1145\/1065887.1065892","article-title":"CCured: type-safe retrofitting of legacy software","volume":"27","author":"Necula","year":"2005","journal-title":"ACM Trans. Program. Lang. Syst."},{"key":"10.1016\/j.cose.2026.105029_b28","series-title":"26th USENIX Security Symposium","first-page":"33","article-title":"Ninja: Towards transparent tracing and debugging on ARM","author":"Ning","year":"2017"},{"key":"10.1016\/j.cose.2026.105029_b29","series-title":"Juliet C\/C++ 1.3","author":"NIST","year":"2017"},{"key":"10.1016\/j.cose.2026.105029_b30","series-title":"BEEBS: Open benchmarks for energy measurements on embedded platforms","author":"Pallister","year":"2013"},{"key":"10.1016\/j.cose.2026.105029_b31","series-title":"Proceedings of the Sixth Workshop on CPS&IoT Security and Privacy","first-page":"55","article-title":"EmbedWatch: Fat pointer solution for detecting spatial memory errors in embedded systems","author":"Rusconi","year":"2024"},{"key":"10.1016\/j.cose.2026.105029_b32","unstructured":"SafeStack, SafeStack. https:\/\/clang.llvm.org\/docs\/SafeStack.html."},{"key":"10.1016\/j.cose.2026.105029_b33","series-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses","first-page":"381","article-title":"uSBS: Static binary sanitization of bare-metal embedded devices for fault observability","author":"Salehi","year":"2020"},{"key":"10.1016\/j.cose.2026.105029_b34","series-title":"2012 USENIX Annual Technical Conference","first-page":"309","article-title":"AddressSanitizer: A fast address sanity checker","author":"Serebryany","year":"2012"},{"key":"10.1016\/j.cose.2026.105029_b35","doi-asserted-by":"crossref","unstructured":"Shi, J., Li, W., Wang, W., Guan, L., 2024. Facilitating Non-Intrusive In-Vivo Firmware Testing with Stateless Instrumentation. In: 31st Network and Distributed System Security Symposium. NDSS.","DOI":"10.14722\/ndss.2024.23116"},{"key":"10.1016\/j.cose.2026.105029_b36","unstructured":"Slamaris, D., Embedded systems security and trustzone. https:\/\/embeddedsecurity.io\/sec-tz-basics."},{"key":"10.1016\/j.cose.2026.105029_b37","doi-asserted-by":"crossref","unstructured":"Steensgaard, B., 1996. Points-to analysis in almost linear time. In: Proceedings of the 23rd ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages. pp. 32\u201341.","DOI":"10.1145\/237721.237727"},{"key":"10.1016\/j.cose.2026.105029_b38","doi-asserted-by":"crossref","unstructured":"Sui, Y., Xue, J., 2016. SVF: interprocedural static value-flow analysis in LLVM. In: Proceedings of the 25th International Conference on Compiler Construction. pp. 265\u2013266.","DOI":"10.1145\/2892208.2892235"},{"key":"10.1016\/j.cose.2026.105029_b39","series-title":"2020 IEEE Symposium on Security and Privacy","first-page":"1433","article-title":"OAT: Attesting operation integrity of embedded devices","author":"Sun","year":"2020"},{"key":"10.1016\/j.cose.2026.105029_b40","series-title":"Proceedings of the 2013 IEEE Symposium on Security and Privacy","first-page":"48","article-title":"Sok: Eternal war in memory","author":"Szekeres","year":"2013"},{"key":"10.1016\/j.cose.2026.105029_b41","series-title":"2024 IEEE Real-Time Systems Symposium","first-page":"415","article-title":"Partial context-sensitive pointer integrity for real-time embedded systems","author":"Wang","year":"2024"},{"key":"10.1016\/j.cose.2026.105029_b42","series-title":"30th USENIX Security Symposium","first-page":"2453","article-title":"Preventing use-after-free attacks with fast forward allocation","author":"Wickman","year":"2021"},{"key":"10.1016\/j.cose.2026.105029_b43","doi-asserted-by":"crossref","unstructured":"Yadav, N., Ganapathy, V., 2023a. Whole-program control-flow path attestation. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. pp. 2680\u20132694.","DOI":"10.1145\/3576915.3616687"},{"key":"10.1016\/j.cose.2026.105029_b44","series-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","first-page":"2680","article-title":"Whole-program control-flow path attestation","author":"Yadav","year":"2023"},{"issue":"5","key":"10.1016\/j.cose.2026.105029_b45","doi-asserted-by":"crossref","first-page":"307","DOI":"10.1145\/949952.940113","article-title":"Protecting C programs from attacks via invalid pointer dereferences","volume":"28","author":"Yong","year":"2003","journal-title":"SIGSOFT Softw. Eng. Notes"},{"key":"10.1016\/j.cose.2026.105029_b46","series-title":"Network and Distributed System Security (NDSS) Symposium","article-title":"Statically discover cross-entry use-after-free vulnerabilities in the linux kernel","author":"Zhang","year":"2025"},{"key":"10.1016\/j.cose.2026.105029_b47","series-title":"Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems","first-page":"631","article-title":"BOGO: Buy spatial memory safety, get temporal memory safety (almost) free","author":"Zhang","year":"2019"},{"key":"10.1016\/j.cose.2026.105029_b48","unstructured":"Zhou, J., Du, Y., Shen, Z., Ma, L., Criswell, J., Walls, R.J., 2020. Silhouette: Efficient protected shadow stacks for embedded systems. In: 29th USENIX Security Symposium. USENIX Security 20, pp. 1219\u20131236."},{"key":"10.1016\/j.cose.2026.105029_b49","unstructured":"Zoia, M., et al., 2026. Source code of RemOTA. https:\/\/zenodo.org\/records\/15190636."}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826002051?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826002051?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T08:14:34Z","timestamp":1786781674000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404826002051"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":49,"alternative-id":["S0167404826002051"],"URL":"https:\/\/doi.org\/10.1016\/j.cose.2026.105029","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"RemOTA: Remote attestation for detecting use-after-free in low-power microcontrollers","name":"articletitle","label":"Article Title"},{"value":"Computers & Security","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cose.2026.105029","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"105029"}}