{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T14:29:21Z","timestamp":1787495361279,"version":"build-2736575974"},"publisher-location":"Singapore","reference-count":24,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819248049","type":"print"},{"value":"9789819248056","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,8,24]],"date-time":"2026-08-24T00:00:00Z","timestamp":1787529600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,8,24]],"date-time":"2026-08-24T00:00:00Z","timestamp":1787529600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-981-92-4805-6_31","type":"book-chapter","created":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T13:46:29Z","timestamp":1787492789000},"page":"467-482","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Pitfall: Uncovering and\u00a0Exploiting the\u00a0Store Forwarding Predictor on\u00a0Intel CPUs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1834-4958","authenticated-orcid":false,"given":"Chang","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4185-7214","authenticated-orcid":false,"given":"Xin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-6495-2275","authenticated-orcid":false,"given":"Dapeng","family":"Ju","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2573-963X","authenticated-orcid":false,"given":"Yongqiang","family":"Lyu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5779-9026","authenticated-orcid":false,"given":"Dongsheng","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,8,24]]},"reference":[{"key":"31_CR1","unstructured":"Alexa: The top 1 million sites on the web (2023). https:\/\/www.alexa.com\/topsites"},{"key":"31_CR2","unstructured":"Canella, C., et al.: A systematic evaluation of transient execution attacks and defenses. In: USENIX Security Symposium, pp. 249\u2013266 (2019)"},{"key":"31_CR3","unstructured":"Constable, S., et al.: AEX-Notify: thwarting precise single-stepping attacks through interrupt awareness for intel SGX enclaves. In: USENIX Security Symposium, pp. 4051\u20134068 (2023)"},{"key":"31_CR4","doi-asserted-by":"crossref","unstructured":"Cook, J., Drean, J., Behrens, J., Yan, M.: There\u2019s always a bigger fish: a clarifying analysis of a machine-learning-assisted side-channel attack. In: International Symposium on Computer Architecture (ISCA), pp. 204\u2013217 (2022)","DOI":"10.1145\/3470496.3527416"},{"key":"31_CR5","doi-asserted-by":"crossref","unstructured":"Feng, Y., et al.: Fish and chips: on the root causes of co-located website-fingerprinting attacks. IEEE Trans. Dependable Secure Comput. (2025)","DOI":"10.1109\/TDSC.2025.3617019"},{"key":"31_CR6","doi-asserted-by":"crossref","unstructured":"Feng, Y., et al.: TimeGaps channels: exploiting CPU halted time for fun and profit. In: International Symposium on Computer Architecture (ISCA) (2026)","DOI":"10.1109\/ISCA66397.2026.00048"},{"key":"31_CR7","unstructured":"Kim, J., Chuang, J., Genkin, D., Yarom, Y.: FLOP: breaking the apple M3 CPU via false load output predictions. In: USENIX Security Symposium, pp. 2595\u20132614 (2025)"},{"key":"31_CR8","doi-asserted-by":"crossref","unstructured":"Kim, J., Genkin, D., Yarom, Y.: SLAP: data speculation attacks via load address prediction on apple silicon. In: IEEE Symposium on Security and Privacy (S&P), pp. 3549\u20133566 (2025)","DOI":"10.1109\/SP61157.2025.00098"},{"key":"31_CR9","unstructured":"Liu, C., et al.: Thrend: mitigating counting thread-based fine-grained timing on arm and apple CPUs. In: Design Automation Conference (DAC) (2026)"},{"key":"31_CR10","doi-asserted-by":"crossref","unstructured":"Liu, C., Feng, S., Li, Y., Wang, D., Carlson, T.E.: HoBBy: hardening unbalanced branches against control flow attacks on intel SGX and AMD SEV. In: Design Automation Conference (DAC) (2025)","DOI":"10.1109\/DAC63849.2025.11132915"},{"key":"31_CR11","doi-asserted-by":"crossref","unstructured":"Liu, C., et al.: MDPeek: breaking balanced branches in SGX with memory disambiguation unit side channels. In: Architectural Support for Programming Languages and Operating Systems (ASPLOS), pp. 622\u2013638 (2025)","DOI":"10.1145\/3676641.3716004"},{"key":"31_CR12","doi-asserted-by":"crossref","unstructured":"Liu, C., et al.: SSBench: automated characterization of memory dependence predictors on modern CPUs. In: International Symposium on Computer Architecture (ISCA) (2026)","DOI":"10.1109\/ISCA66397.2026.00127"},{"key":"31_CR13","doi-asserted-by":"crossref","unstructured":"Liu, C., et al.: Uncovering and exploiting AMD speculative memory access predictors for fun and profit. In: IEEE International Symposium on High-Performance Computer Architecture (HPCA), pp. 31\u201345 (2024)","DOI":"10.1109\/HPCA57654.2024.00014"},{"key":"31_CR14","doi-asserted-by":"crossref","unstructured":"Liu, C., et al.: SSBleed: non-speculative side-channel attacks via speculative store bypass on Armv9 CPUs. In: IEEE International Symposium on High-Performance Computer Architecture (HPCA) (2026)","DOI":"10.1109\/HPCA68181.2026.11408465"},{"key":"31_CR15","doi-asserted-by":"crossref","unstructured":"Mose, K.H., Kim, S.S., Ros, A., Jones, T.M., Mullins, R.D.: Mascot: predicting memory dependencies and opportunities for speculative memory bypassing. In: IEEE International Symposium on High-Performance Computer Architecture (HPCA), pp. 59\u201371 (2025)","DOI":"10.1109\/HPCA61900.2025.00016"},{"key":"31_CR16","unstructured":"Oleksenko, O., Trach, B., Silberstein, M., Fetzer, C.: SpecFuzz: bringing spectre-type vulnerabilities to the surface. In: USENIX Security Symposium, pp. 1481\u20131498 (2020)"},{"key":"31_CR17","doi-asserted-by":"crossref","unstructured":"Rauscher, F., Gruss, D.: Cross-core interrupt detection: exploiting user and virtualized IPIs. In: ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 94\u2013108 (2024)","DOI":"10.1145\/3658644.3690242"},{"key":"31_CR18","unstructured":"Wiebing, S., de\u00a0Faveri\u00a0Tron, A., Bos, H., Giuffrida, C.: InSpectre gadget: inspecting the residual attack surface of cross-privilege spectre v2. In: USENIX Security Symposium, pp. 577\u2013594 (2024)"},{"key":"31_CR19","doi-asserted-by":"crossref","unstructured":"Wiebing, S., Giuffrida, C.: Training solo: on the limitations of domain isolation against spectre-v2 attacks. In: IEEE Symposium on Security and Privacy (S&P), pp. 3599\u20133616 (2025)","DOI":"10.1109\/SP61157.2025.00253"},{"key":"31_CR20","doi-asserted-by":"crossref","unstructured":"Zhang, X., et al.: Towards practical interrupt side channel attacks on macOS for apple silicon. In: International Symposium on Computer Architecture (ISCA) (2026)","DOI":"10.1109\/ISCA66397.2026.00044"},{"key":"31_CR21","doi-asserted-by":"crossref","unstructured":"Zhang, X., et al.: Fantastic interrupts and where to find them: exploiting non-movable interrupts on x86. IEEE Transactions on Information Forensics and Security (2025)","DOI":"10.1109\/TIFS.2025.3577482"},{"key":"31_CR22","doi-asserted-by":"crossref","unstructured":"Zhang, Xet al.: AmpereBleed: exploiting on-chip current sensors for circuit-free attacks on ARM-FPGA SoCs. In: Design Automation Conference (DAC) (2025)","DOI":"10.1109\/DAC63849.2025.11132575"},{"key":"31_CR23","doi-asserted-by":"crossref","unstructured":"Zhang, X., et al.: ThermalScope: a practical interrupt side channel attack based on thermal event interrupts. In: Design Automation Conference (DAC) (2024)","DOI":"10.1145\/3649329.3656525"},{"key":"31_CR24","doi-asserted-by":"crossref","unstructured":"Zhang, X., et al.: SegScope: probing fine-grained interrupts via architectural footprints. In: IEEE International Symposium on High-Performance Computer Architecture (HPCA), pp. 424\u2013438 (2024)","DOI":"10.1109\/HPCA57654.2024.00039"}],"container-title":["Lecture Notes in Computer Science","Advanced Parallel Processing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-4805-6_31","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T13:46:34Z","timestamp":1787492794000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-4805-6_31"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8,24]]},"ISBN":["9789819248049","9789819248056"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-4805-6_31","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,8,24]]},"assertion":[{"value":"24 August 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"APPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Advanced Parallel Processing Technologies","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Brussels","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"appt2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.appt-conference.com\/2026","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}