{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T21:30:18Z","timestamp":1773523818661,"version":"3.50.1"},"reference-count":97,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2023,9,15]],"date-time":"2023-09-15T00:00:00Z","timestamp":1694736000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2024,2,29]]},"abstract":"<jats:p>According to the World Economic Forum, cyberattacks are considered as one of the most important sources of risk to companies and institutions worldwide. Attacks can target the network, software, and\/or hardware. Over the years, much knowledge has been developed to understand and mitigate cyberattacks. However, new threats have appeared in recent years regarding software attacks that exploit hardware vulnerabilities. This article defines these attacks as architectural attacks. Today, both industry and academia have only limited comprehension of architectural attacks, which represents a critical issue for the design of future systems. To this end, this work proposes a new taxonomy, a new attack model, and a complete survey of existing architectural attacks. As a result, it provides the tools to understand architectural attacks in more depth and to start building improved designs and protection mechanisms.<\/jats:p>","DOI":"10.1145\/3604803","type":"journal-article","created":{"date-parts":[[2023,6,14]],"date-time":"2023-06-14T11:52:26Z","timestamp":1686743546000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Survey on Architectural Attacks: A Unified Classification and Attack Model"],"prefix":"10.1145","volume":"56","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8021-9368","authenticated-orcid":false,"given":"Tara","family":"Ghasempouri","sequence":"first","affiliation":[{"name":"Tallinn University of Technology, Estonia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8113-020X","authenticated-orcid":false,"given":"Jaan","family":"Raik","sequence":"additional","affiliation":[{"name":"Tallinn University of Technology, Estonia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1851-8161","authenticated-orcid":false,"given":"Cezar","family":"Reinbrecht","sequence":"additional","affiliation":[{"name":"Delft University of Technology, The Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8961-0387","authenticated-orcid":false,"given":"Said","family":"Hamdioui","sequence":"additional","affiliation":[{"name":"Delft University of Technology, The Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9911-4846","authenticated-orcid":false,"given":"Mottaqiallah","family":"Taouil","sequence":"additional","affiliation":[{"name":"Delft University of Technology, The Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,9,15]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"Fortune Business Insights. 2022. Cyber Security Market Size. Retrieved from https:\/\/www.fortunebusinessinsights.com\/industry-reports\/cyber-security-market-101165 Fortune Business Insights. 2022. Cyber Security Market Size. Retrieved from https:\/\/www.fortunebusinessinsights.com\/industry-reports\/cyber-security-market-101165"},{"key":"e_1_3_1_3_2","unstructured":"Cybersecurity and Infrastructure security agency. 2021. 5G Security and Resilience. Retrieved in 2022 from https:\/\/www.cisa.gov\/5g. Cybersecurity and Infrastructure security agency. 2021. 5G Security and Resilience. Retrieved in 2022 from https:\/\/www.cisa.gov\/5g."},{"key":"e_1_3_1_4_2","volume-title":"Cyber security basic defenses and attack trends. Homeland Security Technology Challenges","author":"C\u00e1rdenas Alvaro A.","year":"2008","unstructured":"Alvaro A. C\u00e1rdenas , Tanya Roosta , Gelareh Taban , and Shankar Sastry . 2008. Cyber security basic defenses and attack trends. Homeland Security Technology Challenges ( 2008 ), 73\u2013101. Alvaro A. C\u00e1rdenas, Tanya Roosta, Gelareh Taban, and Shankar Sastry. 2008. Cyber security basic defenses and attack trends. Homeland Security Technology Challenges (2008), 73\u2013101."},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jcss.2014.02.005"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CCAA.2016.7813791"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2006.25"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2021.3063998"},{"key":"e_1_3_1_9_2","volume-title":"Topics in Cryptology (CT-RSA\u201910)","author":"Bogdanov Andrey","unstructured":"Andrey Bogdanov , Thomas Eisenbarth , Christof Paar , and Malte Wienecke . 2010. Differential cache-collision timing attacks on AES with applications to embedded CPUs . In Topics in Cryptology (CT-RSA\u201910) , Josef Pieprzyk (Ed.). Springer , Berlin , 235\u2013251. Andrey Bogdanov, Thomas Eisenbarth, Christof Paar, and Malte Wienecke. 2010. Differential cache-collision timing attacks on AES with applications to embedded CPUs. In Topics in Cryptology (CT-RSA\u201910), Josef Pieprzyk (Ed.). Springer, Berlin, 235\u2013251."},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-016-0141-6"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-017-0025-y"},{"key":"e_1_3_1_16_2","volume-title":"Proceedings of the 23rd USENIX.","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner . 2014 . FLUSH+RELOAD: A high resolution, low noise, L3 cache side-channel attack . In Proceedings of the 23rd USENIX. Yuval Yarom and Katrina Falkner. 2014. FLUSH+RELOAD: A high resolution, low noise, L3 cache side-channel attack. In Proceedings of the 23rd USENIX."},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.5555\/3361338.3361356"},{"key":"e_1_3_1_18_2","volume-title":"Spectre attacks: Exploiting speculative execution","author":"Kocher Paul","unstructured":"Paul Kocher , Jann Horn , Anders Fogh , Daniel Genkin , Daniel Gruss , Werner Haas , Moritz Lipp , Stefan Mangard , Thomas Prescher , Michael Schwarz , and Yuval Yarom . 2019. Spectre attacks: Exploiting speculative execution . In IEEE SP. Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre attacks: Exploiting speculative execution. In IEEE SP."},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/1134285.1134500"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/ETS48528.2020.9131603"},{"key":"e_1_3_1_22_2","volume-title":"Retrieved","author":"Bernstein Daniel J.","year":"2005","unstructured":"Daniel J. Bernstein . 2005 . Cache Timing Attacks on AES . Retrieved December 12, 2016. Daniel J. Bernstein. 2005. Cache Timing Attacks on AES. Retrieved December 12, 2016."},{"key":"e_1_3_1_23_2","doi-asserted-by":"crossref","unstructured":"Joseph Bonneau and Ilya Mironov. 2006. Cache-collision timing attacks against AES. In CHES. 201\u2013215. Joseph Bonneau and Ilya Mironov. 2006. Cache-collision timing attacks against AES. In CHES . 201\u2013215.","DOI":"10.1007\/11894063_16"},{"key":"e_1_3_1_24_2","unstructured":"Christopher Domas. 2017. Breaking the x86 ISA. Retrieved in 2022 from https:\/\/www.blackhat.com\/docs\/us-17\/thursday\/us-17-Domas-Breaking-The-x86-ISA.pdf Christopher Domas. 2017. Breaking the x86 ISA. Retrieved in 2022 from https:\/\/www.blackhat.com\/docs\/us-17\/thursday\/us-17-Domas-Breaking-The-x86-ISA.pdf"},{"key":"e_1_3_1_25_2","volume-title":"Proceedings of the 26th USENIX Conference on Security Symposium(SEC\u201917)","author":"Koppe Philipp","year":"2017","unstructured":"Philipp Koppe , Benjamin Kollenda , Marc Fyrbiak , Christian Kison , Robert Gawlik , Christof Paar , and Thorsten Holz . 2017 . Reverse engineering \\(\\times\\) 86 processor microcode . In Proceedings of the 26th USENIX Conference on Security Symposium(SEC\u201917) , 1163\u20131180. Philipp Koppe, Benjamin Kollenda, Marc Fyrbiak, Christian Kison, Robert Gawlik, Christof Paar, and Thorsten Holz. 2017. Reverse engineering \\(\\times\\) 86 processor microcode. In Proceedings of the 26th USENIX Conference on Security Symposium(SEC\u201917), 1163\u20131180."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISPASS.2010.5452013"},{"key":"e_1_3_1_27_2","unstructured":"Christopher Domas. 2018. GOD MODE unlocked: Hardware backdoors in x86 CPUs. Retrieved in 2022 from https:\/\/i.blackhat.com\/us-18\/Thu-August-9\/us-18-Domas-God-Mode-Unlocked-Hardware-Backdoors-In-x86-CPUs.pdf Christopher Domas. 2018. GOD MODE unlocked: Hardware backdoors in x86 CPUs. Retrieved in 2022 from https:\/\/i.blackhat.com\/us-18\/Thu-August-9\/us-18-Domas-God-Mode-Unlocked-Hardware-Backdoors-In-x86-CPUs.pdf"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/RTAS.2013.6531080"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISPASS.2001.990684"},{"key":"e_1_3_1_30_2","volume-title":"Computational Science (ICCS\u201904), Marian Bubak, Geert Dick van Albada, Peter M","author":"Dongarra Jack","unstructured":"Jack Dongarra , Shirley Moore , Philip Mucci , Keith Seymour , and Haihang You . 2004. Accurate cache and TLB characterization using hardware counters . In Computational Science (ICCS\u201904), Marian Bubak, Geert Dick van Albada, Peter M . A. Sloot, and Jack Dongarra (Eds.). Springer , Berlin, Heidelberg , 432\u2013439. Jack Dongarra, Shirley Moore, Philip Mucci, Keith Seymour, and Haihang You. 2004. Accurate cache and TLB characterization using hardware counters. In Computational Science (ICCS\u201904), Marian Bubak, Geert Dick van Albada, Peter M. A. Sloot, and Jack Dongarra (Eds.). Springer, Berlin, Heidelberg, 432\u2013439."},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/RTAS.2015.7108453"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274281"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/2989081.2989114"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/SIPS.2005.1579858"},{"key":"e_1_3_1_35_2","unstructured":"One Aleph. 1996. Smashing the stack for fun and profit. Retrieved in 2022 from http:\/\/www.shmoo.com\/phrack\/Phrack49\/p49-14. One Aleph. 1996. Smashing the stack for fun and profit. Retrieved in 2022 from http:\/\/www.shmoo.com\/phrack\/Phrack49\/p49-14."},{"key":"e_1_3_1_36_2","volume-title":"Defeating compiler-level buffer overflow protection. The USENIX Magazine","author":"Alexander Steven","year":"2005","unstructured":"Steven Alexander . 2005. Defeating compiler-level buffer overflow protection. The USENIX Magazine ; login ( 2005 ). Retrieved in 2022 from https:\/\/www.usenix.org\/publications\/login\/june-2005-volume-30-number-3\/defeating-compiler-level-buffer-overflow-protection Steven Alexander. 2005. Defeating compiler-level buffer overflow protection. The USENIX Magazine; login (2005). Retrieved in 2022 from https:\/\/www.usenix.org\/publications\/login\/june-2005-volume-30-number-3\/defeating-compiler-level-buffer-overflow-protection"},{"key":"e_1_3_1_37_2","volume-title":"Proceedings of the USENIX Annual Technical Conference, General Track, 251\u2013262","author":"Baratloo Arash","unstructured":"Arash Baratloo , Navjot Singh , and Timothy K. Tsai . 2000. Transparent run-time defense against stack-smashing attacks . In Proceedings of the USENIX Annual Technical Conference, General Track, 251\u2013262 . Arash Baratloo, Navjot Singh, and Timothy K. Tsai. 2000. Transparent run-time defense against stack-smashing attacks. In Proceedings of the USENIX Annual Technical Conference, General Track, 251\u2013262."},{"key":"e_1_3_1_38_2","volume-title":"PRoceedings of the USENIX Security Symposium","volume":"12","author":"Bhatkar Sandeep","year":"2003","unstructured":"Sandeep Bhatkar , Daniel C. DuVarney , and Ron Sekar . 2003 . Address obfuscation: An efficient approach to combat a broad range of memory error exploits . In PRoceedings of the USENIX Security Symposium , Vol. 12 , 291\u2013301. Sandeep Bhatkar, Daniel C. DuVarney, and Ron Sekar. 2003. Address obfuscation: An efficient approach to combat a broad range of memory error exploits. In PRoceedings of the USENIX Security Symposium, Vol. 12, 291\u2013301."},{"key":"e_1_3_1_39_2","volume-title":"Proceeding of the USENIX Security Symposium, 161\u2013176","author":"Carlini Nicholas","unstructured":"Nicholas Carlini , Antonio Barresi , Mathias Payer , David Wagner , and Thomas R. Gross . 2015. Control-flow bending: On the effectiveness of control-flow integrity . In Proceeding of the USENIX Security Symposium, 161\u2013176 . Nicholas Carlini, Antonio Barresi, Mathias Payer, David Wagner, and Thomas R. Gross. 2015. Control-flow bending: On the effectiveness of control-flow integrity. In Proceeding of the USENIX Security Symposium, 161\u2013176."},{"key":"e_1_3_1_40_2","volume-title":"Proceedings of the USENIX Security Symposium","volume":"98","author":"Cowan Crispan","year":"1998","unstructured":"Crispan Cowan , Calton Pu , Dave Maier , Jonathan Walpole , Peat Bakke , Steve Beattie , Aaron Grier , Perry Wagle , Qian Zhang , and Heather Hinton . 1998 . Stackguard: Automatic adaptive detection and prevention of buffer-overflow attacks . In Proceedings of the USENIX Security Symposium , Vol. 98 . 63\u201378. Crispan Cowan, Calton Pu, Dave Maier, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, Qian Zhang, and Heather Hinton. 1998. Stackguard: Automatic adaptive detection and prevention of buffer-overflow attacks. In Proceedings of the USENIX Security Symposium, Vol. 98. 63\u201378."},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/2768566.2768569"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2006.166"},{"key":"e_1_3_1_43_2","unstructured":"Gerardo Richarte. 2002. Four different tricks to bypass stackshield and stackguard protection. Retrieved in 2022 from https:\/\/www.cs.purdue.edu\/homes\/xyzhang\/spring07\/Papers\/defeat-stackguard.pdf Gerardo Richarte. 2002. Four different tricks to bypass stackshield and stackguard protection. Retrieved in 2022 from https:\/\/www.cs.purdue.edu\/homes\/xyzhang\/spring07\/Papers\/defeat-stackguard.pdf"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_3_1_45_2","unstructured":"Nathan P. Smith. 1997. Stack smashing vulnerabilities in the UNIX operating system. Retrieved in 2022 from https:\/\/www.zdnet.com\/article\/stackclash-vulnerabilities-rip-root-holes-in-linux-systems\/ Nathan P. Smith. 1997. Stack smashing vulnerabilities in the UNIX operating system. Retrieved in 2022 from https:\/\/www.zdnet.com\/article\/stackclash-vulnerabilities-rip-root-holes-in-linux-systems\/"},{"key":"e_1_3_1_46_2","volume-title":"Proceedings of the USENIX Security Symposium","volume":"10","author":"Sovarel Ana Nora","year":"2005","unstructured":"Ana Nora Sovarel , David Evans , and Nathanael Paul . 2005 . Where\u2019s the FEEB? The effectiveness of instruction set randomization . In Proceedings of the USENIX Security Symposium , Vol. 10 . Ana Nora Sovarel, David Evans, and Nathanael Paul. 2005. Where\u2019s the FEEB? The effectiveness of instruction set randomization. In Proceedings of the USENIX Security Symposium, Vol. 10."},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62105-0_11"},{"key":"e_1_3_1_48_2","volume-title":"Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 300\u2013321","author":"Gruss Daniel","year":"2016","unstructured":"Daniel Gruss , Cl\u00e9mentine Maurice , and Stefan Mangard . 2016 . Rowhammer. js: A remote software-induced fault attack in javascript . In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 300\u2013321 . Daniel Gruss, Cl\u00e9mentine Maurice, and Stefan Mangard. 2016. Rowhammer. js: A remote software-induced fault attack in javascript. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 300\u2013321."},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/3152701.3152709"},{"key":"e_1_3_1_50_2","volume-title":"Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu.","author":"Kim Yoongu","year":"2014","unstructured":"Yoongu Kim , Ross Daly , Jeremie Kim , Chris Fallin , Ji Hye Lee , Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu. 2014 . Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors. In ACM SIGARCH Computer Architecture News, Vol. 42 . IEEE Press , IEEE, 361\u2013372. Yoongu Kim, Ross Daly, Jeremie Kim, Chris Fallin, Ji Hye Lee, Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu. 2014. Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors. In ACM SIGARCH Computer Architecture News, Vol. 42. IEEE Press, IEEE, 361\u2013372."},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00102"},{"key":"e_1_3_1_52_2","volume-title":"Proceedings of the USENIX Security Symposium, 565\u2013581","author":"Pessl Peter","year":"2016","unstructured":"Peter Pessl , Daniel Gruss , Cl\u00e9mentine Maurice , Michael Schwarz , and Stefan Mangard . 2016 . DRAMA: Exploiting DRAM addressing for cross-CPU attacks . In Proceedings of the USENIX Security Symposium, 565\u2013581 . Peter Pessl, Daniel Gruss, Cl\u00e9mentine Maurice, Michael Schwarz, and Stefan Mangard. 2016. DRAMA: Exploiting DRAM addressing for cross-CPU attacks. In Proceedings of the USENIX Security Symposium, 565\u2013581."},{"key":"e_1_3_1_53_2","volume-title":"Proceedings of the 2018 USENIX Annual Technical Conference. USENIX Association.","author":"Tatar Andrei","year":"2018","unstructured":"Andrei Tatar , Radhesh Krishnan , Elias Athanasopoulos , Cristiano Giuffrida , Herbert Bos , and Kaveh Razavi . 2018 . Throwhammer: Rowhammer attacks over the network and defenses . In Proceedings of the 2018 USENIX Annual Technical Conference. USENIX Association. Andrei Tatar, Radhesh Krishnan, Elias Athanasopoulos, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. 2018. Throwhammer: Rowhammer attacks over the network and defenses. In Proceedings of the 2018 USENIX Annual Technical Conference. USENIX Association."},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978406"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASET.2017.7983658"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/IPDPS.2016.59"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCAS.2017.8050256"},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/1450135.1450180"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSD.2007.4341520"},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2015.2448684"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2002.1176268"},{"key":"e_1_3_1_62_2","volume-title":"Proceedings of the 9th International Symposium on Networks-on-Chip. ACM, 8.","author":"Rajesh J. S.","year":"2015","unstructured":"J. S. Rajesh , Dean Michael Ancajas , Koushik Chakraborty , and Sanghamitra Roy . 2015 . Runtime detection of a bandwidth denial attack from a rogue network-on-chip . In Proceedings of the 9th International Symposium on Networks-on-Chip. ACM, 8. J. S. Rajesh, Dean Michael Ancajas, Koushik Chakraborty, and Sanghamitra Roy. 2015. Runtime detection of a bandwidth denial attack from a rogue network-on-chip. In Proceedings of the 9th International Symposium on Networks-on-Chip. ACM, 8."},{"key":"e_1_3_1_63_2","volume-title":"Proceedings of the 16th Iberchip Workshop (IWS\u201910)","author":"Sep\u00falveda J.","unstructured":"J. Sep\u00falveda , M. Strum , and W. J. Chau . 2010. A hybrid switching approach for NoC-based systems to avoid denial-of-service SoC attacks . In Proceedings of the 16th Iberchip Workshop (IWS\u201910) . 23\u201325. J. Sep\u00falveda, M. Strum, and W. J. Chau. 2010. A hybrid switching approach for NoC-based systems to avoid denial-of-service SoC attacks. In Proceedings of the 16th Iberchip Workshop (IWS\u201910). 23\u201325."},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/ReConFig.2015.7393301"},{"key":"e_1_3_1_65_2","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Bulck Jo Van","year":"2018","unstructured":"Jo Van Bulck , Marina Minkin , Ofir Weisse , Daniel Genkin , Baris Kasikci , Frank Piessens , Mark Silberstein , Thomas F. Wenisch , Yuval Yarom , and Raoul Strackx . 2018 . Foreshadow: Extracting the keys to the intel SGX Kingdom with Transient Out-of-Order Execution . In 27th USENIX Security Symposium (USENIX Security 18) . USENIX Association, Baltimore, MD, 991\u20131008. 978-1-939133-04-5 https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/bulck. Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F. Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the intel SGX Kingdom with Transient Out-of-Order Execution. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, 991\u20131008. 978-1-939133-04-5 https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/bulck."},{"key":"e_1_3_1_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3173204"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","unstructured":"Moritz Lipp Michael Schwarz Daniel Gruss Thomas Prescher Werner Haas Stefan Mangard Paul Kocher Daniel Genkin Yuval Yarom and Mike Hamburg. 2018. Meltdown. DOI:10.48550\/ARXIV.1801.01207 10.48550\/ARXIV.1801.01207 Moritz Lipp Michael Schwarz Daniel Gruss Thomas Prescher Werner Haas Stefan Mangard Paul Kocher Daniel Genkin Yuval Yarom and Mike Hamburg. 2018. Meltdown. DOI:10.48550\/ARXIV.1801.01207","DOI":"10.48550\/ARXIV.1801.01207"},{"key":"e_1_3_1_68_2","volume-title":"Speculose: Analyzing the security implications of speculative execution in CPUs. CoRR abs\/1801.04084","author":"Maisuradze Giorgi","year":"2018","unstructured":"Giorgi Maisuradze and Christian Rossow . 2018 . Speculose: Analyzing the security implications of speculative execution in CPUs. CoRR abs\/1801.04084 (2018), 10\u201330. Giorgi Maisuradze and Christian Rossow. 2018. Speculose: Analyzing the security implications of speculative execution in CPUs. CoRR abs\/1801.04084 (2018), 10\u201330."},{"key":"e_1_3_1_69_2","volume-title":"Daniel Genkin, Daniel Gruss, Berk Sunar, Frank Piessens, and Yuval Yarom.","author":"Minkin Marina","year":"2019","unstructured":"Marina Minkin , Daniel Moghimi , Moritz Lipp , Michael Schwarz , Jo Van Bulck , Daniel Genkin, Daniel Gruss, Berk Sunar, Frank Piessens, and Yuval Yarom. 2019 . Fallout : Reading kernel writes from user space. (2019). Marina Minkin, Daniel Moghimi, Moritz Lipp, Michael Schwarz, Jo Van Bulck, Daniel Genkin, Daniel Gruss, Berk Sunar, Frank Piessens, and Yuval Yarom. 2019. Fallout: Reading kernel writes from user space. (2019)."},{"key":"e_1_3_1_70_2","volume-title":"12th USENIX Workshop on Offensive Technologies WOOT 18(seriesWOOT\u201918)","author":"Mohammadian Koruyeh Esmaeil","year":"2018","unstructured":"Koruyeh Esmaeil Mohammadian , Khasawneh Khaled N., Song Chengyu , and Abu-Ghazaleh Nael . 2018 . Spectre returns! speculation attacks using the return stack buffer . In 12th USENIX Workshop on Offensive Technologies WOOT 18(seriesWOOT\u201918) . USENIX Association, Baltimore, 10\u201330. Koruyeh Esmaeil Mohammadian, Khasawneh Khaled N., Song Chengyu, and Abu-Ghazaleh Nael. 2018. Spectre returns! speculation attacks using the return stack buffer. In 12th USENIX Workshop on Offensive Technologies WOOT 18(seriesWOOT\u201918). USENIX Association, Baltimore, 10\u201330."},{"key":"e_1_3_1_71_2","volume-title":"Netspectre: Read arbitrary memory over network. arXiv preprint arXiv:1807.10535","author":"Schwarz Michael","year":"2018","unstructured":"Michael Schwarz , Martin Schwarzl , Moritz Lipp , and Daniel Gruss . 2018 . Netspectre: Read arbitrary memory over network. arXiv preprint arXiv:1807.10535 (2018). Michael Schwarz, Martin Schwarzl, Moritz Lipp, and Daniel Gruss. 2018. Netspectre: Read arbitrary memory over network. arXiv preprint arXiv:1807.10535 (2018)."},{"key":"e_1_3_1_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243822"},{"key":"e_1_3_1_73_2","volume-title":"RIDL: Rogue in-flight data load. In S&P","author":"van Schaik Stephan","year":"2019","unstructured":"Stephan van Schaik , Alyssa Milburn , Sebastian \u00d6sterlund , Pietro Frigo , Giorgi Maisuradze , Kaveh Razavi , Herbert Bos , and Cristiano Giuffrida . 2019 . RIDL: Rogue in-flight data load. In S&P . IEEE , CA. Stephan van Schaik, Alyssa Milburn, Sebastian \u00d6sterlund, Pietro Frigo, Giorgi Maisuradze, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2019. RIDL: Rogue in-flight data load. In S&P. IEEE, CA."},{"key":"e_1_3_1_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.44"},{"key":"e_1_3_1_75_2","volume-title":"LazyFP: Leaking FPU register state using microarchitectural side-channels. arXiv preprint arXiv:1806.07480","author":"Stecklina Julian","year":"2018","unstructured":"Julian Stecklina and Thomas Prescher . 2018. LazyFP: Leaking FPU register state using microarchitectural side-channels. arXiv preprint arXiv:1806.07480 ( 2018 ). Julian Stecklina and Thomas Prescher. 2018. LazyFP: Leaking FPU register state using microarchitectural side-channels. arXiv preprint arXiv:1806.07480 (2018)."},{"key":"e_1_3_1_76_2","volume-title":"Smart, and Yuval Yarom","author":"Benger Naomi","year":"2014","unstructured":"Naomi Benger , Joop Pol , Nigel P. Smart, and Yuval Yarom . 2014 . Ooh Aah... Just a Little Bit : A Small Amount of Side Channel Can Go a Long Way. In CHES. New York, NY , 75\u201392. Naomi Benger, Joop Pol, Nigel P. Smart, and Yuval Yarom. 2014. Ooh Aah... Just a Little Bit: A Small Amount of Side Channel Can Go a Long Way. In CHES. New York, NY, 75\u201392."},{"key":"e_1_3_1_77_2","doi-asserted-by":"publisher","unstructured":"Tara Ghasempouri Jaan Raik Kolin Paul Cezar Reinbrecht Said Hamdioui and Mottaqiallah. 2021. Verifying cache architecture vulnerabilities using a formal security verification flow. Microelectron. Reliab. 119 (2021) 114085. DOI:10.1016\/j.microrel.2021.114085 10.1016\/j.microrel.2021.114085 Tara Ghasempouri Jaan Raik Kolin Paul Cezar Reinbrecht Said Hamdioui and Mottaqiallah. 2021. Verifying cache architecture vulnerabilities using a formal security verification flow. Microelectron. Reliab. 119 (2021) 114085. DOI:10.1016\/j.microrel.2021.114085","DOI":"10.1016\/j.microrel.2021.114085"},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/DDECS50862.2020.9095707"},{"key":"e_1_3_1_79_2","doi-asserted-by":"crossref","unstructured":"D. Gullasch E. Bangerter and S. Krenn. 2011. Cache games - bringing access-based cache attacks on AES to practice. In IEEE SP. 490\u2013505. D. Gullasch E. Bangerter and S. Krenn. 2011. Cache games - bringing access-based cache attacks on AES to practice. In IEEE SP . 490\u2013505.","DOI":"10.1109\/SP.2011.22"},{"key":"e_1_3_1_80_2","volume-title":"Thomas Eisenbarth, and Berk Sunar.","author":"Irazoqui Gorka","year":"2014","unstructured":"Gorka Irazoqui , Mehmet Sinan Inci , Thomas Eisenbarth, and Berk Sunar. 2014 . Wait a Minute! A fast, Cross-VM Attack on AES. Springer International Publishing , 299\u2013319. Gorka Irazoqui, Mehmet Sinan Inci, Thomas Eisenbarth, and Berk Sunar. 2014. Wait a Minute! A fast, Cross-VM Attack on AES. Springer International Publishing, 299\u2013319."},{"key":"e_1_3_1_81_2","doi-asserted-by":"crossref","unstructured":"F. Liu Y. Yarom Q. Ge G. Heiser and R. B. Lee. 2015. Last-level cache side-channel attacks are practical. In IEEE SP. San Jose CA 605\u2013622. F. Liu Y. Yarom Q. Ge G. Heiser and R. B. Lee. 2015. Last-level cache side-channel attacks are practical. In IEEE SP . San Jose CA 605\u2013622.","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_1_82_2","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_1_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSD51259.2020.00043"},{"key":"e_1_3_1_84_2","volume-title":"CSSE","volume":"3","author":"Xinjie Z.","unstructured":"Z. Xinjie , W. Tao , M. Dong , Z. Yuanyuan , and L. Zhaoyang . 2008. Robust first two rounds access driven Cache timing attack on AES . In CSSE , Vol. 3 . Hubei, China, 785\u2013788. Z. Xinjie, W. Tao, M. Dong, Z. Yuanyuan, and L. Zhaoyang. 2008. Robust first two rounds access driven Cache timing attack on AES. In CSSE, Vol. 3. Hubei, China, 785\u2013788."},{"key":"e_1_3_1_85_2","doi-asserted-by":"crossref","unstructured":"Younis A. Younis Kashif Kifayat Qi Shi and Bob Askwith. 2015. A new prime and probe cache side-channel attack for cloud computing. In CSIT 1718\u20131724. Younis A. Younis Kashif Kifayat Qi Shi and Bob Askwith. 2015. A new prime and probe cache side-channel attack for cloud computing. In CSIT 1718\u20131724.","DOI":"10.1109\/CIT\/IUCC\/DASC\/PICOM.2015.259"},{"key":"e_1_3_1_86_2","volume-title":"ACM SIGSAC.","author":"Zhang Yinqian","unstructured":"Yinqian Zhang , Ari Juels , Michael K. Reiter , and Thomas Ristenpart . 2014. Cross-tenant side-channel attacks in PaaS clouds . In ACM SIGSAC. Scottsdale, Arizona , 990\u20131003. Yinqian Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2014. Cross-tenant side-channel attacks in PaaS clouds. In ACM SIGSAC. Scottsdale, Arizona, 990\u20131003."},{"key":"e_1_3_1_87_2","volume-title":"2019 IFIP\/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC). IEEE, Cuzco, Peru, 204\u2013209","author":"Forlin B.","unstructured":"B. Forlin , C. Reinbrecht , and J. Sep\u00falveda . 2019. Attacking real-time MPSoCs: Preemptive NoCs are vulnerable . In 2019 IFIP\/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC). IEEE, Cuzco, Peru, 204\u2013209 . B. Forlin, C. Reinbrecht, and J. Sep\u00falveda. 2019. Attacking real-time MPSoCs: Preemptive NoCs are vulnerable. In 2019 IFIP\/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC). IEEE, Cuzco, Peru, 204\u2013209."},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2018.8342090"},{"key":"e_1_3_1_89_2","doi-asserted-by":"publisher","DOI":"10.1109\/SBCCI.2016.7724051"},{"key":"e_1_3_1_90_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.micpro.2016.12.010"},{"key":"e_1_3_1_91_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2017.57"},{"key":"e_1_3_1_92_2","doi-asserted-by":"crossref","unstructured":"C. Reinbrecht A. Susin L. Bossuet and J. Sepulveda. 2016. Gossip NoC - Avoiding timing side-channel attacks through traffic management. In ISVLSI 16. IEEE Pittsburgh 601\u2013606. C. Reinbrecht A. Susin L. Bossuet and J. Sepulveda. 2016. Gossip NoC - Avoiding timing side-channel attacks through traffic management. In ISVLSI 16 . IEEE Pittsburgh 601\u2013606.","DOI":"10.1109\/ISVLSI.2016.25"},{"key":"e_1_3_1_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/LES.2014.2384744"},{"key":"e_1_3_1_94_2","doi-asserted-by":"crossref","unstructured":"W. Yao and E. Suh. 2012. Efficient timing channel protection for on-chip networks. In NOCS. Lyngby Denmark 142\u2013151. W. Yao and E. Suh. 2012. Efficient timing channel protection for on-chip networks. In NOCS . Lyngby Denmark 142\u2013151.","DOI":"10.1109\/NOCS.2012.24"},{"key":"e_1_3_1_95_2","volume-title":"Software Engineering Institute","author":"CERT Coordination Center 2015.","unstructured":"CERT Coordination Center 2015. Software Engineering Institute , Carnegie Mellon University . Retrieved from https:\/\/www.sei.cmu.edu\/about\/divisions\/cert\/index.cfm. CERT Coordination Center 2015. Software Engineering Institute, Carnegie Mellon University. Retrieved from https:\/\/www.sei.cmu.edu\/about\/divisions\/cert\/index.cfm."},{"key":"e_1_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1406"},{"key":"e_1_3_1_97_2","unstructured":"Chair of VLSI Design Diagnostics and Architecture. 2016. PoC - Pile of Cores. Technische Universit\u00e4. https:\/\/github.com\/VLSI-EDA\/PoC. Chair of VLSI Design Diagnostics and Architecture. 2016. PoC - Pile of Cores . Technische Universit\u00e4. https:\/\/github.com\/VLSI-EDA\/PoC."},{"key":"e_1_3_1_98_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_1_99_2","volume-title":"19th International Conference, DIMVA","author":"Lorenz Hetterich","year":"2022","unstructured":"Hetterich Lorenz and Schwarz Michael . 2022 . Detection of intrusions and malware, and vulnerability assessment . In 19th International Conference, DIMVA , Cagliari, Italy. Hetterich Lorenz and Schwarz Michael. 2022. Detection of intrusions and malware, and vulnerability assessment. In 19th International Conference, DIMVA, Cagliari, Italy."},{"key":"e_1_3_1_100_2","volume-title":"IEEE Symposium on Security and Privacy (SP).","author":"Junpeng Wan","year":"2022","unstructured":"Wan Junpeng , Bi Yanxiang , Zhou Zhe , and Li Zhou . 2022 . MeshUp: Stateless cache side-channel attack on CPU mesh . In IEEE Symposium on Security and Privacy (SP). Wan Junpeng, Bi Yanxiang, Zhou Zhe, and Li Zhou. 2022. MeshUp: Stateless cache side-channel attack on CPU mesh. In IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_1_101_2","volume-title":"IProceedings of the 49th Annual International Symposium on Computer Architecture.","author":"Joseph Ravichandran","year":"2022","unstructured":"Ravichandran Joseph , Na Weon Taek , Lang Jay , and Yan Mengjia . 2022 . PACMAN: Attacking ARM pointer authentication with speculative execution . In IProceedings of the 49th Annual International Symposium on Computer Architecture. Ravichandran Joseph, Na Weon Taek, Lang Jay, and Yan Mengjia. 2022. PACMAN: Attacking ARM pointer authentication with speculative execution. In IProceedings of the 49th Annual International Symposium on Computer Architecture."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3604803","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3604803","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:04Z","timestamp":1750178764000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3604803"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,15]]},"references-count":97,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,2,29]]}},"alternative-id":["10.1145\/3604803"],"URL":"https:\/\/doi.org\/10.1145\/3604803","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,9,15]]},"assertion":[{"value":"2022-06-30","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-05-31","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-09-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}