I am a researcher at TU Berlin, working on what becomes possible once an attacker holds the device in their hands — the physical access threat model.
That spans side-channel and fault injection attacks — and the countermeasures against them — through to the hardware, firmware and instrumentation needed to carry the work out. Much of it involves building the tools first.