{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:02:32Z","timestamp":1782975752982,"version":"3.54.5"},"reference-count":66,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100006785","name":"Google Research Scholar Award","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006785","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00192","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"732-749","source":"Crossref","is-referenced-by-count":0,"title":["RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction\/Data Cache Incoherence"],"prefix":"10.1109","author":[{"given":"Fabian","family":"Thomas","sequence":"first","affiliation":[{"name":"CISPA Helmholtz Center, for Information Security"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Schwarz","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center, for Information Security"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813708"},{"key":"ref2","article-title":"ARMageddon: Cache Attacks on Mobile Devices","volume-title":"USENIX Security","author":"Lipp","year":"2016"},{"key":"ref3","article-title":"Peep with a mirror: breaking the integrity of android app sandboxing via unprivileged cache side channel","volume-title":"USENIX Security Symposium","author":"Lin","year":"2024"},{"key":"ref4","volume-title":"Cache-Timing Attacks on AES","author":"Bernstein","year":"2005"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"ref6","article-title":"Flush+Reload: a High Resolution, Low Noise, L3 Cache Side-Channel Attack","volume-title":"USENIX Security","author":"Yarom","year":"2014"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"ref8","volume-title":"performance.now resolution","year":"2019"},{"key":"ref9","volume-title":"Disable JavaScript","year":"2019"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653687"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382230"},{"key":"ref12","article-title":"Intel SGX Explained","volume-title":"Cryptology ePrint Archive, Report 2016\/086","author":"Costan","year":"2016"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-09484-2_7"},{"key":"ref14","article-title":"Rapid Prototyping for Microarchitectural Attacks","volume-title":"USENIX Security","author":"Easdon","year":"2022"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70972-7_13"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23271"},{"key":"ref17","article-title":"Prime+Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSX","volume-title":"USENIX Security Symposium","author":"Disselkoen","year":"2017"},{"key":"ref18","article-title":"(M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels","volume-title":"USENIX Security","author":"Zhang","year":"2023"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3566097.3567917"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.11"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3765061"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3744833"},{"key":"ref23","article-title":"Synchronization Storage Channels (S2 C): Timer-less Cache SideChannel Attacks on the Apple M1 via Hardware Synchronization Instructions","volume-title":"USENIX Security","author":"Yu","year":"2023"},{"key":"ref24","article-title":"The gates of time: Improving cache attacks with transient execution","volume-title":"USENIX Security Symposium","author":"Katzman","year":"2023"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446729"},{"key":"ref26","article-title":"Bending microarchitectural weird machines towards practicality","volume-title":"USENIX Security","author":"Wang","year":"2024"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690313"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-1992-13-404"},{"key":"ref30","volume-title":"Arm Architecture Reference Manual for A-profile architecture","year":"2023"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384746"},{"key":"ref32","article-title":"Cache Missing for Fun and Profit","volume-title":"BSDCan","author":"Percival","year":"2005"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.45"},{"key":"ref34","article-title":"Telling Your Secrets Without Page Faults: Stealthy Page Table-Based Attacks on Enclaved Execution","volume-title":"USENIX Security Symposium","author":"Van Bulck","year":"2017"},{"key":"ref35","article-title":"A Systematic Evaluation of Transient Execution Attacks and Defenses","author":"Canella","journal-title":"USENIX Security, 2019, extended classification tree and PoCs at"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"ref37","article-title":"Meltdown: Reading Kernel Memory from User Space","volume-title":"USENIX Security","author":"Lipp","year":"2018"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354252"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00087"},{"key":"ref40","article-title":"Speculative Probing: Hacking Blind in the Spectre Era","volume-title":"CCS","author":"G\u00f6kta\u015f","year":"2020"},{"key":"ref41","article-title":"Half-Double: Hammering From the Next Row Over","volume-title":"USENIX Security Symposium","author":"Kogler","year":"2022"},{"key":"ref42","article-title":"ret2spec: Speculative Execution Using Return Stack Buffers","volume-title":"CCS","author":"Maisuradze","year":"2018"},{"key":"ref43","volume-title":"LazyFP: Leaking FPU Register State using Microarchitectural Side-Channels","author":"Stecklina","year":"2018"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179399"},{"key":"ref45","volume-title":"Intel 64 and IA-32 Architectures Software Developer\u2019s Manual Combined Volumes: 1, 2A, 2B, 2C, 2D, 3A, 3B, 3C, 3D and 4","year":"2024"},{"key":"ref46","volume-title":"Loongarch reference manual-volume 1: Basic architecture, version 1.10","year":"2023"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230253"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3676641.3716020"},{"key":"ref49","article-title":"Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels","volume-title":"USENIX Security","author":"Kogler","year":"2023"},{"key":"ref50","volume-title":"A Spectre proof-of-concept for a Spectre-proof web","author":"R\u00f6ttger","year":"2021"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17146-8_9"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-016-0141-6"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484816"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00028"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23027"},{"key":"ref56","article-title":"Peeping Tom in the Neighborhood: Keystroke Eavesdropping on Multi-User Systems","volume-title":"USENIX Security Symposium","author":"Zhang","year":"2009"},{"key":"ref57","article-title":"Timing Analysis of Keystrokes and Timing Attacks on SSH","volume-title":"USENIX Security Symposium","author":"Song","year":"2001"},{"key":"ref58","volume-title":"Porting just-in-time compilers to Apple silicon","year":"2020"},{"key":"ref59","volume-title":"W\\^{}X now mandatory in OpenBSD","year":"2016"},{"key":"ref60","article-title":"Rage against the machine clear: A systematic analysis of machine clears and their implications for transient execution attacks","author":"Ragab","year":"2021","journal-title":"USENIX Security"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/3676641.3716274"},{"key":"ref62","article-title":"HyperDegrade: From GHz to MHz Effective CPU Frequencies","volume-title":"USENIX Security Symposium","author":"Aldaya","year":"2022"},{"key":"ref63","article-title":"\u00c6PIC Leak: Architecturally Leaking Uninitialized Data from the Microarchitecture","volume-title":"USENIX Security","author":"Borrello","year":"2022"},{"key":"ref64","article-title":"RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in ClosedSource RISC-V CPUs","volume-title":"CCS","author":"Thomas","year":"2025"},{"key":"ref65","article-title":"CacheWarp: Software-based Fault Injection using Selective State Reset","volume-title":"USENIX Security","author":"Zhang","year":"2024"},{"key":"ref66","volume-title":"Zenbleed","author":"Ormandy","year":"2023"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573426.pdf?arnumber=11573426","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:35:28Z","timestamp":1782970528000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573426\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":66,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00192","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}