{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T04:50:51Z","timestamp":1782449451874,"version":"3.54.5"},"publisher-location":"Cham","reference-count":49,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032078933","type":"print"},{"value":"9783032078940","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,18]],"date-time":"2025-10-18T00:00:00Z","timestamp":1760745600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,18]],"date-time":"2025-10-18T00:00:00Z","timestamp":1760745600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-07894-0_15","type":"book-chapter","created":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T19:06:51Z","timestamp":1760728011000},"page":"283-302","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Cache Demote for\u00a0Fast Eviction Set Construction and\u00a0Page Table Attribute Leakage"],"prefix":"10.1007","author":[{"given":"Taehun","family":"Kim","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hyerean","family":"Jang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Youngjoo","family":"Shin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,18]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Aldaya, A.C., Brumley, B.B., ul\u00a0Hassan, S., Garc\u00eda, C.P., Tuveri, N.: Port contention for fun and profit. In: IEEE Symposium on Security and Privacy (SP), pp. 870\u2013887 (2019)","DOI":"10.1109\/SP.2019.00066"},{"key":"15_CR2","unstructured":"Atul, K.: intel labs\u2019 contributions to latest intel$$\\text{\\textregistered} $$ Xeon$$\\text{\\textregistered} $$ scalable processor. https:\/\/community.intel.com\/t5\/Blogs\/Tech-Innovation\/Data-Center\/Intel-Labs-Contributions-to-Latest-Intel-Xeon-Scalable-Processor\/post\/1441731"},{"key":"15_CR3","doi-asserted-by":"crossref","unstructured":"Barr, T.W., Cox, A.L., Rixner, S.: Translation caching: skip, don\u2019t walk (the page table). In: International Symposium on Computer Architecture (2010)","DOI":"10.1145\/1815961.1815970"},{"key":"15_CR4","doi-asserted-by":"crossref","unstructured":"Bhattacharyya, A., et al.: SMoTherSpectre: exploiting speculative execution through port contention. In: ACM SIGSAC Conference on Computer and Communications Security, pp. 785\u2013800 (2019)","DOI":"10.1145\/3319535.3363194"},{"key":"15_CR5","doi-asserted-by":"crossref","unstructured":"Canella, C., Schwarz, M., Haubenwallner, M., Schwarzl, M., Gruss, D.: KASLR: break it, fix it, repeat. In: ACM Asia Conference on Computer and Communications Security, pp. 481\u2013493 (2020)","DOI":"10.1145\/3320269.3384747"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Cassell, B., Szepesi, T., Wong, B., Brecht, T., Ma, J., Liu, X.: Nessie: a decoupled, client-driven key-value store using RDMA. IEEE Trans. Parallel Distrib. Syst. 28(12), 3537\u20133552 (2017)","DOI":"10.1109\/TPDS.2017.2729545"},{"key":"15_CR7","doi-asserted-by":"crossref","unstructured":"Chen, Y., Hajiabadi, A., Pei, L., Carlson, T.E.: PrefetCHX: cross-core cache-agnostic prefetcher-based side-channel attacks. In: IEEE International Symposium on High-Performance Computer Architecture, pp. 395\u2013408 (2024)","DOI":"10.1109\/HPCA57654.2024.00037"},{"key":"15_CR8","doi-asserted-by":"crossref","unstructured":"Choi, H., Kim, S., Shin, S.: AVX timing side-channel attacks against address space layout randomization. In: ACM\/IEEE Design Automation Conference, pp.\u00a01\u20136 (2023)","DOI":"10.1109\/DAC56929.2023.10247741"},{"key":"15_CR9","unstructured":"Gras, B., Razavi, K., Bos, H., Giuffrida, C.: Translation leak-aside buffer: defeating cache side-channel protections with TLB attacks. In: USENIX Security Symposium, pp. 955\u2013972 (2018)"},{"key":"15_CR10","doi-asserted-by":"crossref","unstructured":"Gruss, D., Lipp, M., Schwarz, M., Fellner, R., Maurice, C., Mangard, S.: KASLR is dead: long live KASLR. In: International Symposium on Engineering Secure Software and Systems, pp. 161\u2013176 (2017)","DOI":"10.1007\/978-3-319-62105-0_11"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"Gruss, D., Maurice, C., Fogh, A., Lipp, M., Mangard, S.: Prefetch side-channel attacks: Bypassing SMAP and kernel ASLR. In: ACM SIGSAC Conference on Computer and Communications Security, pp. 368\u2013379 (2016)","DOI":"10.1145\/2976749.2978356"},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Gruss, D., Maurice, C., Wagner, K., Mangard, S.: Flush+flush: a fast and stealthy cache attack. In: International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 279\u2013299 (2016)","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"15_CR13","unstructured":"Gruss, D., Spreitzer, R., Mangard, S.: Cache template attacks: automating attacks on inclusive last-level caches. In: USENIX Security Symposium, pp. 897\u2013912 (2015)"},{"key":"15_CR14","doi-asserted-by":"crossref","unstructured":"G\u00fclmezo\u011flu, B., Inci, M.S., Irazoqui, G., Eisenbarth, T., Sunar, B.: A faster and more realistic flush+reload attack on AES. In: International Workshop on Constructive Side-Channel Analysis and Secure Design, pp. 111\u2013126 (2015)","DOI":"10.1007\/978-3-319-21476-4_8"},{"key":"15_CR15","unstructured":"Gupta, A., Weber, W.D., Mowry, T.: Reducing memory and traffic requirements for scalable directory-based cache coherence schemes. In: Scalable Shared Memory Multiprocessors (1990)"},{"key":"15_CR16","unstructured":"Intel: Architecture day 2021. https:\/\/download.intel.com\/newsroom\/2021\/client-computing\/intel-architecture-day-2021-presentation.pdf"},{"key":"15_CR17","unstructured":"Intel: Intel$$\\text{\\textregistered} $$ 64 and IA-32 architectures optimization reference manual. https:\/\/www.intel.com\/content\/www\/us\/en\/content-details\/814198\/intel-64-and-ia-32-architectures-optimization-reference-manual-volume-1.html"},{"key":"15_CR18","unstructured":"Intel: Intel$$\\text{\\textregistered} $$ 64 and IA-32 architectures software developer\u2019s manual combined volumes 3A, 3B, 3C, and 3D: system programming guide. https:\/\/cdrdv2.intel.com\/v1\/dl\/getContent\/671447"},{"key":"15_CR19","unstructured":"Intel: Intel$$\\text{\\textregistered} $$ 64 and IA-32 architectures software developer\u2019s manual, Volume 2 (2A, 2B, 2C, & 2D): instruction set reference, A-Z. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-sdm.html"},{"key":"15_CR20","unstructured":"Intel: Intel$$\\text{\\textregistered} $$ architecture instruction set extensions and future features, programming reference. https:\/\/cdrdv2-public.intel.com\/819680\/architecture-instruction-set-extensions-programming-reference.pdf"},{"key":"15_CR21","unstructured":"Intel: Intel$$\\text{\\textregistered} $$ Xeon$$\\text{\\textregistered} $$ Silver 4510T processor. https:\/\/www.intel.com\/content\/www\/us\/en\/products\/sku\/236638\/intel-xeon-silver-4510t-processor-30m-cache-2-00-ghz\/specifications.html"},{"key":"15_CR22","doi-asserted-by":"crossref","unstructured":"Irazoqui, G., Eisenbarth, T., Sunar, B.: S\\$a: A shared cache attack that works across cores and defies VM sandboxing\u2013and its application to AES. In: IEEE Symposium on Security and Privacy, pp. 591\u2013604 (2015)","DOI":"10.1109\/SP.2015.42"},{"key":"15_CR23","doi-asserted-by":"crossref","unstructured":"Irazoqui, G., Eisenbarth, T., Sunar, B.: Systematic reverse engineering of cache slice selection in intel processors. In: Euromicro Conference on Digital System Design, pp. 629\u2013636 (2015)","DOI":"10.1109\/DSD.2015.56"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Jang, H., Kim, T., Shin, Y.: SYSBUMPS: exploiting speculative execution in system calls for breaking KASLR in MACOS for apple silicon. In: ACM SIGSAC Conference on Computer and Communications Security (2024)","DOI":"10.1145\/3658644.3690189"},{"key":"15_CR25","doi-asserted-by":"crossref","unstructured":"Jang, Y., Lee, S., Kim, T.: Breaking kernel address space layout randomization with Intel TSX. In: ACM SIGSAC Conference on Computer and Communications Security, pp. 380\u2013392 (2016)","DOI":"10.1145\/2976749.2978321"},{"key":"15_CR26","doi-asserted-by":"crossref","unstructured":"Kim, S., Han, M., Baek, W.: DPRIME+DABORT: a high-precision and timer-free directory-based side-channel attack in non-inclusive cache hierarchies using intel TSX. In: IEEE International Symposium on High-Performance Computer Architecture, pp. 67\u201381 (2022)","DOI":"10.1109\/HPCA53966.2022.00014"},{"key":"15_CR27","doi-asserted-by":"crossref","unstructured":"Kim, S., Shin, S., Choi, H.: AVX-TSCHA: leaking information through AVX extensions in commercial processors. Comput. Secur. 134, 103437 (2023)","DOI":"10.1016\/j.cose.2023.103437"},{"key":"15_CR28","doi-asserted-by":"crossref","unstructured":"Kim, T., Park, H., Lee, S., Shin, S., Hur, J., Shin, Y.: Devious: device-driven side-channel attacks on the IOMMU. In: IEEE Symposium on Security and Privacy, pp. 2288\u20132305 (2023)","DOI":"10.1109\/SP46215.2023.10179283"},{"key":"15_CR29","doi-asserted-by":"crossref","unstructured":"Kim, T., Shin, Y.: ThermalBleed: a practical thermal side-channel attack. IEEE Access 10, 25718\u201325731 (2022)","DOI":"10.1109\/ACCESS.2022.3156596"},{"key":"15_CR30","unstructured":"Lipp, M., Gruss, D., Schwarz, M.: AMD prefetch attacks through power and time. In: USENIX Security Symposium (2022)"},{"key":"15_CR31","unstructured":"Lipp, M., et al..: Meltdown: reading kernel memory from user space. In: USENIX Security Symposium, pp. 973\u2013990 (2018)"},{"key":"15_CR32","doi-asserted-by":"crossref","unstructured":"Liu, F., Yarom, Y., Ge, Q., Heiser, G., Lee, R.B.: Last-level cache side-channel attacks are practical. In: IEEE Symposium on Security and Privacy, pp. 605\u2013622 (2015)","DOI":"10.1109\/SP.2015.43"},{"key":"15_CR33","doi-asserted-by":"crossref","unstructured":"Maurice, C., Le\u00a0Scouarnec, N., Neumann, C., Heen, O., Francillon, A.: Reverse engineering intel last-level cache complex addressing using performance counters. In: International Symposium on Research in Attacks, Intrusions, and Defenses, pp. 48\u201365 (2015)","DOI":"10.1007\/978-3-319-26362-5_3"},{"key":"15_CR34","doi-asserted-by":"crossref","unstructured":"Oren, Y., Kemerlis, V.P., Sethumadhavan, S., Keromytis, A.D.: The spy in the sandbox: practical cache attacks in Javascript and their implications. In: ACM SIGSAC Conference on Computer and Communications Security, pp. 1406\u20131418 (2015)","DOI":"10.1145\/2810103.2813708"},{"key":"15_CR35","doi-asserted-by":"crossref","unstructured":"Purnal, A., Turan, F., Verbauwhede, I.: Prime+scope: overcoming the observer effect for high-precision cache contention attacks. In: ACM SIGSAC Conference on Computer and Communications Security, pp. 2906\u20132920 (2021)","DOI":"10.1145\/3460120.3484816"},{"key":"15_CR36","doi-asserted-by":"crossref","unstructured":"Qureshi, M.K.: New attacks and defense for encrypted-address cache. In: ACM\/IEEE International Symposium on Computer Architecture, pp. 360\u2013371 (2019)","DOI":"10.1145\/3307650.3322246"},{"key":"15_CR37","doi-asserted-by":"crossref","unstructured":"Rauscher, F., Fiedler, C., Kogler, A., Gruss, D.: A systematic evaluation of novel and existing cache side channels. In: Network and Distributed System Security Symposium (2025)","DOI":"10.14722\/ndss.2025.230253"},{"key":"15_CR38","unstructured":"Schwarz, M., Canella, C., Giner, L., Gruss, D.: Store-to-leak forwarding: leaking data on meltdown-resistant CPUS (updated and extended version). arXiv:1905.05725 (2019)"},{"key":"15_CR39","unstructured":"Shusterman, A., Agarwal, A., O\u2019Connell, S., Genkin, D., Oren, Y., Yarom, Y.: Prime+probe 1, Javascript 0: Overcoming browser-based side-channel defenses. In: USENIX Security Symposium, pp. 2863\u20132880 (2021)"},{"key":"15_CR40","unstructured":"Song, W., Liu, P.: Dynamically finding minimal eviction sets can be quicker than you think for side-channel attacks against the LLC. In: International Symposium on Research in Attacks, Intrusions, and Defenses, pp. 427\u2013442 (2019)"},{"key":"15_CR41","unstructured":"Trujillo, D., Wikner, J., Razavi, K.: Inception: exposing new attack surfaces with training in transient execution. In: USENIX Security Symposium (2023)"},{"key":"15_CR42","doi-asserted-by":"crossref","unstructured":"Vila, P., K\u00f6pf, B., Morales, J.F.: Theory and practice of finding eviction sets. In: IEEE Symposium on Security and Privacy, pp. 39\u201354 (2019)","DOI":"10.1109\/SP.2019.00042"},{"key":"15_CR43","unstructured":"Weber, D., Ibrahim, A., Nemati, H., Schwarz, M., Rossow, C.: Osiris: automated discovery of microarchitectural side channels. In: USENIX Security Symposium, pp. 1415\u20131432 (2021)"},{"key":"15_CR44","doi-asserted-by":"crossref","unstructured":"Wikner, J., Trujillo, D., Razavi, K.: Phantom: exploiting decoder-detectable mispredictions. In: IEEE\/ACM International Symposium on Microarchitecture (2023)","DOI":"10.1145\/3613424.3614275"},{"key":"15_CR45","doi-asserted-by":"crossref","unstructured":"Xue, Z., Han, J., Song, W.: CTPP: a fast and stealth algorithm for searching eviction sets on intel processors. In: International Symposium on Research in Attacks, Intrusions, and Defenses, pp. 151\u2013163 (2023)","DOI":"10.1145\/3607199.3607202"},{"key":"15_CR46","doi-asserted-by":"crossref","unstructured":"Yan, M., Sprabery, R., Gopireddy, B., Fletcher, C., Campbell, R., Torrellas, J.: Attack directories, not caches: side channel attacks in a non-inclusive world. In: IEEE Symposium on Security and Privacy, pp. 888\u2013904 (2019)","DOI":"10.1109\/SP.2019.00004"},{"key":"15_CR47","unstructured":"Yarom, Y., Falkner, K.: Flush+reload: a high resolution, low noise, l3 cache side-channel attack. In: USENIX Security Symposium, pp. 719\u2013732 (2014)"},{"key":"15_CR48","unstructured":"Yarom, Y., Ge, Q., Liu, F., Lee, R.B., Heiser, G.: Mapping the intel last-level cache. Cryptology ePrint Archive (2015)"},{"key":"15_CR49","doi-asserted-by":"crossref","unstructured":"Zhao, Z.N., Morrison, A., Fletcher, C.W., Torrellas, J.: Last-level cache side-channel attacks are feasible in the modern public cloud. In: ACM International Conference on Architectural Support for Programming Languages and Operating Systems, pp. 582\u2013600 (2024)","DOI":"10.1145\/3620665.3640403"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-07894-0_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T04:34:13Z","timestamp":1782448453000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-07894-0_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,18]]},"ISBN":["9783032078933","9783032078940"],"references-count":49,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-07894-0_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,18]]},"assertion":[{"value":"18 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}