{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:07:05Z","timestamp":1763154425785,"version":"3.45.0"},"reference-count":71,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tdsc.2025.3583792","type":"journal-article","created":{"date-parts":[[2025,6,27]],"date-time":"2025-06-27T13:48:50Z","timestamp":1751032130000},"page":"6327-6344","source":"Crossref","is-referenced-by-count":0,"title":["InstPro: Provenance-Based Transient Execution Attack Detection and Investigation on Instruction Execution Traces"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2424-6410","authenticated-orcid":false,"given":"Yang","family":"Zheng","sequence":"first","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0658-0742","authenticated-orcid":false,"given":"Yu","family":"Wen","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-6749-0305","authenticated-orcid":false,"given":"Ruoyu","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronics Engineering, Nanyang Technology University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yanna","family":"Wu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Boyang","family":"Zhang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1521-3967","authenticated-orcid":false,"given":"Dan","family":"Meng","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"249","article-title":"A systematic evaluation of transient execution attacks and defenses","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Canella","year":"2019"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3442479"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3386263.3407583"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3603619"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"ref6","first-page":"973","article-title":"Meltdown: Reading kernel memory from user space","volume-title":"Proc. 27th USENIX Secur. Symp., USENIX Secur. 2018","author":"Lipp","year":"2018"},{"key":"ref7","first-page":"1397","article-title":"DOLMA: Securing speculation with the principle of transient non-observability","volume-title":"Proc. 30th USENIX Secur. Symp., USENIX Secur. 2021","author":"Loughlin","year":"2021"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833707"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2022.3144287"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2019.00058"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304060"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278522"},{"key":"ref13","first-page":"699","article-title":"Retrofitting fine grain isolation in the firefox renderer","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Narayan","year":"2020"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179355"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2021.3082471"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358273"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/iolts50870.2020.9159708"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3418783"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD50377.2020.00096"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3089882"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2022.3149745"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00093"},{"key":"ref23","first-page":"1","article-title":"Fast, robust and accurate detection of cache-based spectre attack phases","volume-title":"Proc. 41st IEEE\/ACM Int. Conf. Comput.-Aided Des.","author":"Pashrashid","year":"2022"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.23919\/DATE56975.2023.10137180"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2022.3171810"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/DAC56929.2023.10247890"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3272748"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2876857"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/2024716.2024718"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.1992.753330"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/123465.123468"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2009.2030595"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2002.1106821"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/1134760.1220164"},{"key":"ref35","first-page":"373","article-title":"IFRA: Instruction footprint recording and analysis for post-silicon bug localization in processors","volume-title":"Proc. 45th Annu. Des. Automat. Conf.","author":"Park","year":"2008"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-011-0152-x"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2254064.2254108"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2015.2454508"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.86"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2018.8342124"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-018-0018-3"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00025"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/12.908991"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/WWC.2003.1249061"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/DATE.2007.364389"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833632"},{"article-title":"Spectre mitigations in microsoft\u2019s c\/c compiler","year":"2018","author":"Kocher","key":"ref47"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00011"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2953709"},{"key":"ref50","first-page":"1397","article-title":"DOLMA: Securing speculation with the principle of transient non-observability","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Loughlin","year":"2021"},{"article-title":"GNU binutils","year":"1986","author":"Foundation","key":"ref51"},{"article-title":"Spec benchmark 2006","year":"2006","author":"Corporation","key":"ref52"},{"article-title":"stress-ng benchmark","year":"2015","author":"King","key":"ref53"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3037697.3037716"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2017.18"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3539605"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/359545.359563"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3645109"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.23919\/DATE56975.2023.10136966"},{"key":"ref60","first-page":"719","article-title":"Flush reload: A high resolution, low noise, l3 cache side-channel attack","volume-title":"Proc. 23rd USENIX Conf. Secur. Symp.","author":"Yarom","year":"2014"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/11564751_74"},{"article-title":"Meltdownprime and spectreprime: Automatically-synthesized attacks exploiting invalidation-based coherence protocols","year":"2018","author":"Trippel","key":"ref63"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/mdat.2024.3352537"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/mdat.2024.3352537"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363224"},{"key":"ref67","first-page":"373","article-title":"$\\lbrace${AIRTAG$\\rbrace$}: Towards automated attack investigation by unsupervised learning with log texts","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Ding","year":"2023"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00026"},{"key":"ref69","first-page":"1415","article-title":"Osiris: Automated discovery of microarchitectural side channels","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Weber","year":"2021"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560578"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/PACT58117.2023.00030"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11242243\/11053669.pdf?arnumber=11053669","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:01:04Z","timestamp":1763154064000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11053669\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":71,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3583792","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"type":"print","value":"1545-5971"},{"type":"electronic","value":"1941-0018"},{"type":"electronic","value":"2160-9209"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}