
The CEA's technology research division (DRT) develop a broad portfolio of technologies in the fields of information and communication, energy and health. CEA technology research division leverages a unique innovation-driven culture and unrivalled expertise to develop and disseminate new technologies for industry, effectively bridging the gap between the worlds of research and industry. CEA-List is a research institute specialized in smart digital systems, located in the heart of the Paris-Saclay science and technology cluster, and in Grenoble in the heard of French Alps.
Within the DSCIN department of CEA List, the LECA and LFIM laboratories invest R&D efforts in the analysis of the robustness of embedded systems against fault-injection attacks.
The Innovative Functions for Mixed Circuits Laboratory (LFIM) is focused on electronic design and software systems that meet requirements in terms of energy efficiency, size, operating reliability, real-time performance and safety. These systems are used in a wide range of fields, including embedded systems (transport, energy, connected objects), and consumer and professional electronics. The technologies developed within the laboratory draw on the latest advances in nanoelectronics, automation, embedded artificial intelligence and cryptographic acceleration. They respond to the societal challenges of sustainable development and trust in digital systems, while offering new applications made possible by new information and communication technologies. To this end, the LFIM studies, designs and integrates digital and mixed processing architectures on silicon for application needs in the fields of IoT, radio frequency circuits and cyber-physical systems.
Mathematics, information, scientific, software
Fixed-term contract
Formal Modeling of Clock Glitch Attacks for Security Verification of Processors H/F
Executive
12
Embedded processors are increasingly deployed in security-critical applications, making their protection against physical attacks a major challenge. Among these threats, clock glitch attacks remain a powerful and accessible fault injection technique, especially relevant for IoT and embedded systems due to their low-cost implementation.
Recent research at Inria Rennes led to the development of TRAITOR [1-2], an experimental platform capable of generating synchronous clock perturbations and characterizing their impact on processor microarchitectures. These experiments suggest that clock glitches induce sampling faults on sensitive sequential elements, but the corresponding fault models remain to be formally validated.
In parallel, CEA-List has developed µArchiFI [3-4], a formal framework enabling pre-silicon analysis of fault injection effects at RTL level, from hardware implementation details up to software execution. While µArchiFI currently supports fault models representative of laser-based attacks, formal modeling of clock glitch effects remains an open challenge.
Research objective and activities
The goal of this postdoctoral project is to develop the first formal methodology for analyzing processor robustness against clock glitch attacks by combining experimental characterization of clock glitches using the TRAITOR platform, and formal verification of their impact using the µArchiFI framework. The project will establish a bridge between physical fault injection experiments and formal security verification, enabling rigorous evaluation of hardware/software countermeasures.
The postdoctoral researcher will contribute to the following tasks:
Research environment
The researcher will join a joint effort between CEA-List (Grenoble, Saclay) and Inria Rennes (PACAP team), combining expertise in: hardware security, fault injection attacks, processor microarchitecture analysis, formal verification, embedded systems, numerical systems designs. The project builds on complementary developments from both teams: TRAITOR for experimental fault injection and µArchiFI for formal securi
Applicants should hold a PhD in computer science, electrical engineering, embedded systems, or a related field.
Strong candidates will have experience in one or more of the following areas:
hardware security and fault injection attacks,
formal methods and verification,
RTL design and digital circuits,
processor architectures (RISC-V experience is a plus),
embedded software.
The position offers an opportunity to work at the intersection of hardware security, formal methods, and secure processor design, combining theoretical research with experimental validation.
Location: CEA-List (Grenoble or Paris-Saclay)
Duration: 12 months with possible extensions
Keywords: Hardware security · Clock glitch attacks · Fault injection · Formal verification · RISC-V · Secure processors · Embedded systems · RTL analysis
Grenoble
France, Auvergne-Rhône-Alpes
Master's or doctorate degree
01/10/2026

The CEA is the French Alternative Energies and Atomic Energy Commission ("Commissariat à l'énergie atomique et aux énergies alternatives"). It is a public body established in October 1945 by General de Gaulle. A leader in research, development and innovation, the CEA mission statement has two main objectives: To become the leading technological research organization in Europe and to ensure that the nuclear deterrent remains effective in the future.
The CEA is active in four main areas: low-carbon energies, defense and security, information technologies and health technologies. In each of these fields, the CEA maintains a cross-disciplinary culture of engineers and researchers, building on the synergies between fundamental and technological research.
The civilian programs of the CEA received 49% of their funding from the French government, and 30% from external sources (partner companies and the European Union).
The CEA had a budget of 4,3 billion euros.
The CEA is based in ten research centers in France, each specializing in specific fields. The laboratories are located in the Paris region, the Rhône-Alpes, the Rhône valley, the Provence-Alpes-Côte d'Azur region, Aquitaine, Central France and Burgundy. The CEA benefits from the strong regional identities of these laboratories and the partnerships forged with other research centers, local authorities and universities.