{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:01:57Z","timestamp":1782975717811,"version":"3.54.5"},"reference-count":52,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100014037","name":"Department of Defense (DoD) through the National Defense Science & Engineering Graduate (NDSEG) Fellowship Program","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100014037","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100017048","name":"ACE, one of the seven centers in JUMP 2.0","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100017048","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000028","name":"Semiconductor Research Corporation (SRC) program sponsored by DARPA","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00015","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"602-620","source":"Crossref","is-referenced-by-count":0,"title":["Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFI"],"prefix":"10.1109","author":[{"given":"Dani\u00ebl","family":"Trujillo","sequence":"first","affiliation":[{"name":"MIT CSAIL"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jagadish","family":"Kotra","sequence":"additional","affiliation":[{"name":"AMD"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Kaplan","sequence":"additional","affiliation":[{"name":"AMD"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mengjia","family":"Yan","sequence":"additional","affiliation":[{"name":"MIT CSAIL"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3399742"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00253"},{"key":"ref3","first-page":"3825","article-title":"RETBLEED: Arbitrary speculative code execution with return instructions","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Wikner"},{"key":"ref4","first-page":"7303","article-title":"Inception: Exposing new attack surfaces with training in transient execution","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Trujillo"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3613424.3614275"},{"key":"ref6","first-page":"971","article-title":"Branch history injection: On the effectiveness of hardware mitigations against cross-privilege spectre-v2 attacks","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Barberis"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/mdat.2024.3352537"},{"key":"ref8","article-title":"Branch privilege injection: Compromising spectre v2 hardware mitigations by exploiting branch predictor race conditions","volume-title":"USENIX Security Symposium, 2025","author":"R\u00fcegge"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243761"},{"key":"ref10","first-page":"1139","article-title":"Efficiently mitigating transient execution attacks using the unmapped speculation contract","volume-title":"14th USENIX Symposium on Operating Systems Design and Implementation (OSDI 20)","author":"Behrens"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA59077.2024.00059"},{"key":"ref12","year":"2018","journal-title":"Speculative execution side channel mitigations"},{"key":"ref13","author":"Turner","year":"2018","journal-title":"Retpoline: a software construct for preventing branch-target-injection"},{"key":"ref14","year":"2022","journal-title":"Post-barrier return stack buffer predictions \/ cve-2022-26373 \/ intel-sa-00706"},{"key":"ref15","author":"Phillips","year":"2022","journal-title":"[patch 0\/3] x86\/speculation: Support automatic ibrs"},{"key":"ref16","year":"2018","journal-title":"Indirect branch restricted speculation"},{"key":"ref17","year":"2022","journal-title":"Technical guidance for mitigating branchtype confusion"},{"key":"ref18","year":"2023","journal-title":"Speculative return stack overflow (srso)"},{"key":"ref19","year":"2024","journal-title":"Branch history injection and intra-mode branch target injection \/ cve-2022-0001, cve-2022-0002 \/ intel-sa-00598"},{"key":"ref20","author":"Corbet","year":"2022","journal-title":"A call to reconsider address-space isolation"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2018.00042"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2020.3014456"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358274"},{"key":"ref24","first-page":"1","article-title":"Safespec: Banishing the spectre of a meltdown with leakage-free speculation","volume-title":"2019 56th ACM\/IEEE Design Automation Conference (DAC)","author":"Khasawneh"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480074"},{"key":"ref26","year":"2020","journal-title":"Software optimization guide for the amd zen4 microarchitecture"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378526"},{"key":"ref29","author":"Zijlstra","year":"2022","journal-title":"[patch v3 00\/59] x86\/retbleed: Call depth tracking mitigation"},{"key":"ref30","article-title":"You cannot always win the race: Analyzing the lfence\/jmp mitigation for branch target injection","author":"Milburn","year":"2022","journal-title":"arXiv preprint"},{"key":"ref31","article-title":"Inspectre gadget: Inspecting the residual attack surface of cross-privilege spectre v2","author":"Wiebing","year":"2024","journal-title":"USENIX Security"},{"key":"ref32","year":"2022","journal-title":"Software techniques for managing speculation on amd processors"},{"key":"ref33","year":"2022","journal-title":"Retpoline: A branch target injection mitigation"},{"key":"ref34","year":"2025","journal-title":"Indirect branch predictor delayed updates"},{"key":"ref35","year":"2019","journal-title":"Control-flow enforcement technology specification"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607219"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363194"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24221"},{"key":"ref39","author":"Zomer","year":"2023","journal-title":"Finding gadgets for cpu side-channels with static analysis tools"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-64322-8_14"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607248"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417289"},{"key":"ref43","first-page":"1","article-title":"SpecROP: Speculative exploitation of ROP chains","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020)","author":"Bhattacharyya"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00158"},{"key":"ref45","first-page":"1433","article-title":"Swivel: Hardening WebAssembly against spectre","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Narayan"},{"key":"ref46","author":"Pizlo","year":"2018","journal-title":"What spectre and meltdown mean for webkit"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00036"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00011"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359640"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3544497.3544502"},{"key":"ref51","year":"2023","journal-title":"memtier_benchmark: A high-throughput benchmarking tool for redis and memcached"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00033"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573418.pdf?arnumber=11573418","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:35:25Z","timestamp":1782970525000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573418\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":52,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00015","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}