{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:42:21Z","timestamp":1785512541531,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":77,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,28]],"date-time":"2023-10-28T00:00:00Z","timestamp":1698451200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Swiss State Secretariat for Education, Research and Innovation","award":["MB22.00057"],"award-info":[{"award-number":["MB22.00057"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,28]]},"DOI":"10.1145\/3613424.3614275","type":"proceedings-article","created":{"date-parts":[[2023,12,8]],"date-time":"2023-12-08T17:22:15Z","timestamp":1702056135000},"page":"49-61","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":20,"title":["Phantom: Exploiting Decoder-detectable Mispredictions"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-3453-538X","authenticated-orcid":false,"given":"Johannes","family":"Wikner","sequence":"first","affiliation":[{"name":"ETH Z\u00fcrich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-1485-2110","authenticated-orcid":false,"given":"Dani\u00ebl","family":"Trujillo","sequence":"additional","affiliation":[{"name":"ETH Z\u00fcrich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8588-7100","authenticated-orcid":false,"given":"Kaveh","family":"Razavi","sequence":"additional","affiliation":[{"name":"ETH Z\u00fcrich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,12,8]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1266999"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00066"},{"key":"e_1_3_2_1_3_1","volume-title":"Retrieved","author":"AMD.","year":"2018","unstructured":"AMD. 2018 . Indirect Branch Control Extension. (2018) . Retrieved September 18, 2023 from https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/processor-tech-docs\/white-papers\/111006-architecture-guidelines-update-amd64-technology-indirect-branch-control-extension.pdf AMD. 2018. Indirect Branch Control Extension. (2018). Retrieved September 18, 2023 from https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/processor-tech-docs\/white-papers\/111006-architecture-guidelines-update-amd64-technology-indirect-branch-control-extension.pdf"},{"key":"e_1_3_2_1_4_1","volume-title":"Retrieved","author":"AMD.","year":"2022","unstructured":"AMD. 2022 . Technical Guidance for Mitigating Branch Type Confusion . Retrieved September 18, 2023 from https:\/\/www.amd.com\/system\/files\/documents\/technical-guidance-for-mitigating-branch-type-confusion_v7_20220712.pdf Accessed on 1.8. 2022. AMD. 2022. Technical Guidance for Mitigating Branch Type Confusion. Retrieved September 18, 2023 from https:\/\/www.amd.com\/system\/files\/documents\/technical-guidance-for-mitigating-branch-type-confusion_v7_20220712.pdf Accessed on 1.8.2022."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.44"},{"key":"e_1_3_2_1_6_1","volume-title":"Retrieved","author":"ARM.","year":"2020","unstructured":"ARM. 2020 . Straight-line Speculation . Retrieved September 18, 2023 from https:\/\/developer.arm.com\/-\/media\/Arm Developer Community\/PDF\/Security Update 08 June 2020\/Straight-line_Speculation-v1.0.pdf ARM. 2020. Straight-line Speculation. Retrieved September 18, 2023 from https:\/\/developer.arm.com\/-\/media\/Arm Developer Community\/PDF\/Security Update 08 June 2020\/Straight-line_Speculation-v1.0.pdf"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA56546.2023.10070938"},{"key":"e_1_3_2_1_8_1","unstructured":"Enrico Barberis Pietro Frigo Marius Muench Herbert Bos and Cristiano Giuffrida. 2022. Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 Attacks. In USENIX Security.  Enrico Barberis Pietro Frigo Marius Muench Herbert Bos and Cristiano Giuffrida. 2022. Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 Attacks. In USENIX Security."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363194"},{"key":"e_1_3_2_1_11_1","volume-title":"Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. In SEC.","author":"Bulck Jo\u00a0Van","year":"2018","unstructured":"Jo\u00a0Van Bulck , Marina Minkin , Ofir Weisse , Daniel Genkin , Baris Kasikci , Frank Piessens , Mark Silberstein , Thomas\u00a0 F. Wenisch , Yuval Yarom , and Raoul Strackx . 2018 . Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. In SEC. Jo\u00a0Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas\u00a0F. Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. In SEC."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363219"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384747"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1118299.1118506"},{"key":"e_1_3_2_1_15_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Dai Miles","year":"2022","unstructured":"Miles Dai , Riccardo Paccagnella , Miguel Gomez-Garcia , John McCalpin , and Mengjia Yan . 2022 . Don\u2019t Mesh Around:{ Side-Channel} Attacks and Mitigations on Mesh Interconnects . In 31st USENIX Security Symposium (USENIX Security 22) . 2857\u20132874. Miles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John McCalpin, and Mengjia Yan. 2022. Don\u2019t Mesh Around:{ Side-Channel} Attacks and Mitigations on Mesh Interconnects. In 31st USENIX Security Symposium (USENIX Security 22). 2857\u20132874."},{"key":"e_1_3_2_1_16_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Disselkoen Craig","year":"2017","unstructured":"Craig Disselkoen , David Kohlbrenner , Leo Porter , and Dean Tullsen . 2017 . Prime+abort: A timer-free high-precision l3 cache attack using intel { TSX} . In 26th USENIX Security Symposium (USENIX Security 17) . 51\u201367. Craig Disselkoen, David Kohlbrenner, Leo Porter, and Dean Tullsen. 2017. Prime+abort: A timer-free high-precision l3 cache attack using intel { TSX}. In 26th USENIX Security Symposium (USENIX Security 17). 51\u201367."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3173204"},{"key":"e_1_3_2_1_19_1","unstructured":"Thomas Gleixner. 2022. LKML: [patch 00\/38] x86\/retbleed: Call depth tracking mitigation. https:\/\/lore.kernel.org\/lkml\/f9fd86acac4f49bc8f90b403978e9df3@AcuMS.aculab.com\/t\/  Thomas Gleixner. 2022. LKML: [patch 00\/38] x86\/retbleed: Call depth tracking mitigation. https:\/\/lore.kernel.org\/lkml\/f9fd86acac4f49bc8f90b403978e9df3@AcuMS.aculab.com\/t\/"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417289"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU.. In NDSS Vol.\u00a017. 26.  Ben Gras Kaveh Razavi Erik Bosman Herbert Bos and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU.. In NDSS Vol.\u00a017. 26.","DOI":"10.14722\/ndss.2017.23271"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00011"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380428"},{"key":"e_1_3_2_1_25_1","volume-title":"Sok: Analysis of root causes and defense strategies for attacks on microarchitectural optimizations.","author":"Holtryd Nadja\u00a0Ramh\u00f6j","year":"2023","unstructured":"Nadja\u00a0Ramh\u00f6j Holtryd , Madhavan Manivannan , and Per Stenstr\u00f6m . 2023 . Sok: Analysis of root causes and defense strategies for attacks on microarchitectural optimizations. (2023), 631\u2013650. Nadja\u00a0Ramh\u00f6j Holtryd, Madhavan Manivannan, and Per Stenstr\u00f6m. 2023. Sok: Analysis of root causes and defense strategies for attacks on microarchitectural optimizations. (2023), 631\u2013650."},{"key":"e_1_3_2_1_26_1","volume-title":"Retrieved","author":"Horn Jann","year":"2018","unstructured":"Jann Horn . 2018 . Issue 1528: Speculative Execution, Variant 4: Speculative Store Bypass . Retrieved September 18, 2023 from https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1528 Jann Horn. 2018. Issue 1528: Speculative Execution, Variant 4: Speculative Store Bypass. Retrieved September 18, 2023 from https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1528"},{"key":"e_1_3_2_1_27_1","unstructured":"Jan Horn. 2018. Reading privileged memory with a side-channel. https:\/\/googleprojectzero.blogspot.com\/2018\/01\/reading-privileged-memory-with-side.html.  Jan Horn. 2018. Reading privileged memory with a side-channel. https:\/\/googleprojectzero.blogspot.com\/2018\/01\/reading-privileged-memory-with-side.html."},{"key":"e_1_3_2_1_28_1","volume-title":"Retrieved","author":"Open Source\u00a0Security Inc.","year":"2023","unstructured":"Open Source\u00a0Security Inc. 2018. Respectre : The State of the Art in Spectre Defenses . Retrieved September 18, 2023 from https:\/\/grsecurity.net\/respectre_announce Open Source\u00a0Security Inc.2018. Respectre: The State of the Art in Spectre Defenses. Retrieved September 18, 2023 from https:\/\/grsecurity.net\/respectre_announce"},{"key":"e_1_3_2_1_29_1","volume-title":"Retrieved","author":"Intel Corp.","year":"2023","unstructured":"Intel Corp. 2018. Indirect Branch Restricted Speculation. (2018) . Retrieved September 18, 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/indirect-branch-restricted-speculation.html Intel Corp.2018. Indirect Branch Restricted Speculation. (2018). Retrieved September 18, 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/indirect-branch-restricted-speculation.html"},{"key":"e_1_3_2_1_30_1","volume-title":"Retrieved","author":"Intel Corp.","year":"2018","unstructured":"Intel Corp. 2018 . Speculative Execution Side Channel Mitigations. (2018) . Retrieved September 18, 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/speculative-execution-side-channel-mitigations.html Intel Corp. 2018. Speculative Execution Side Channel Mitigations. (2018). Retrieved September 18, 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/speculative-execution-side-channel-mitigations.html"},{"key":"e_1_3_2_1_31_1","volume-title":"Retrieved","author":"Intel Corp.","year":"2022","unstructured":"Intel Corp. 2022 . Retpoline: A Branch Target Injection Mitigation. (2022) . Retrieved September 18, 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/retpoline-branch-target-injection-mitigation.html Intel Corp. 2022. Retpoline: A Branch Target Injection Mitigation. (2022). Retrieved September 18, 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/retpoline-branch-target-injection-mitigation.html"},{"key":"e_1_3_2_1_32_1","volume-title":"Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux Kernel. In NDSS.","author":"Johannesmeyer Brian","year":"2022","unstructured":"Brian Johannesmeyer , Jakob Koschel , Kaveh Razavi , Herbert Bos , and Cristiano Giuffrida . 2022 . Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux Kernel. In NDSS. Brian Johannesmeyer, Jakob Koschel, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2022. Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux Kernel. In NDSS."},{"key":"e_1_3_2_1_33_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Kemerlis P","year":"2014","unstructured":"Vasileios\u00a0 P Kemerlis , Michalis Polychronakis , and Angelos\u00a0 D Keromytis . 2014 . ret2dir: Rethinking kernel isolation . In 23rd USENIX Security Symposium (USENIX Security 14) . 957\u2013972. Vasileios\u00a0P Kemerlis, Michalis Polychronakis, and Angelos\u00a0D Keromytis. 2014. ret2dir: Rethinking kernel isolation. In 23rd USENIX Security Symposium (USENIX Security 14). 957\u2013972."},{"key":"e_1_3_2_1_34_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution. In 40th IEEE Symposium on Security and Privacy (S&P\u201919)","author":"Kocher Paul","year":"2019","unstructured":"Paul Kocher , Jann Horn , Anders Fogh , Daniel Genkin , Daniel Gruss , Werner Haas , Mike Hamburg , Moritz Lipp , Stefan Mangard , Thomas Prescher , Michael Schwarz , and Yuval Yarom . 2019 . Spectre Attacks: Exploiting Speculative Execution. In 40th IEEE Symposium on Security and Privacy (S&P\u201919) . Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre Attacks: Exploiting Speculative Execution. In 40th IEEE Symposium on Security and Privacy (S&P\u201919)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/646761.706156"},{"key":"e_1_3_2_1_36_1","volume-title":"USENIX Security Symposium. 69\u201381","author":"Kohlbrenner David","year":"2017","unstructured":"David Kohlbrenner and Hovav Shacham . 2017 . On the effectiveness of mitigations against floating-point timing channels .. In USENIX Security Symposium. 69\u201381 . David Kohlbrenner and Hovav Shacham. 2017. On the effectiveness of mitigations against floating-point timing channels.. In USENIX Security Symposium. 69\u201381."},{"key":"e_1_3_2_1_37_1","volume-title":"12th USENIX Workshop on Offensive Technologies (WOOT 18)","author":"Koruyeh Esmaeil\u00a0Mohammadian","year":"2018","unstructured":"Esmaeil\u00a0Mohammadian Koruyeh , Khaled\u00a0 N. Khasawneh , Chengyu Song , and Nael Abu-Ghazaleh . 2018 . Spectre Returns! Speculation Attacks using the Return Stack Buffer . In 12th USENIX Workshop on Offensive Technologies (WOOT 18) . USENIX Association. Esmaeil\u00a0Mohammadian Koruyeh, Khaled\u00a0N. Khasawneh, Chengyu Song, and Nael Abu-Ghazaleh. 2018. Spectre Returns! Speculation Attacks using the Return Stack Buffer. In 12th USENIX Workshop on Offensive Technologies (WOOT 18). USENIX Association."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00027"},{"key":"e_1_3_2_1_39_1","volume-title":"USENIX Security Symposium, Vol.\u00a019","author":"Lee Sangho","year":"2017","unstructured":"Sangho Lee , Ming-Wei Shih , Prasun Gera , Taesoo Kim , Hyesoon Kim , and Marcus Peinado . 2017 . Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing .. In USENIX Security Symposium, Vol.\u00a019 . 16\u201318. Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing.. In USENIX Security Symposium, Vol.\u00a019. 16\u201318."},{"key":"e_1_3_2_1_40_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Lipp Moritz","year":"2022","unstructured":"Moritz Lipp , Daniel Gruss , and Michael Schwarz . 2022 . AMD Prefetch Attacks through Power and Time . In 31st USENIX Security Symposium (USENIX Security 22) . 643\u2013660. Moritz Lipp, Daniel Gruss, and Michael Schwarz. 2022. AMD Prefetch Attacks through Power and Time. In 31st USENIX Security Symposium (USENIX Security 22). 643\u2013660."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384746"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00063"},{"key":"e_1_3_2_1_43_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp , Michael Schwarz , Daniel Gruss , Thomas Prescher , Werner Haas , Anders Fogh , Jann Horn , Stefan Mangard , Paul Kocher , Daniel Genkin , Yuval Yarom , and Mike Hamburg . 2018 . Meltdown: Reading Kernel Memory from User Space . In 27th USENIX Security Symposium (USENIX Security 18) . Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In 27th USENIX Security Symposium (USENIX Security 18)."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243761"},{"key":"e_1_3_2_1_45_1","volume-title":"Retrieved","year":"2018","unstructured":"Microsoft. 2018 . Spectre mitigations in MSVC . Retrieved September 18, 2023 from https:\/\/devblogs.microsoft.com\/cppblog\/spectre-mitigations-in-msvc\/ Microsoft. 2018. Spectre mitigations in MSVC. Retrieved September 18, 2023 from https:\/\/devblogs.microsoft.com\/cppblog\/spectre-mitigations-in-msvc\/"},{"key":"e_1_3_2_1_46_1","volume-title":"You cannot always win the race: Analyzing the lfence\/jmp mitigation for branch target injection. arXiv preprint arXiv:2203.04277","author":"Milburn Alyssa","year":"2022","unstructured":"Alyssa Milburn , Ke Sun , and Henrique Kawakami . 2022. You cannot always win the race: Analyzing the lfence\/jmp mitigation for branch target injection. arXiv preprint arXiv:2203.04277 ( 2022 ). arXiv:2203.04277 Alyssa Milburn, Ke Sun, and Henrique Kawakami. 2022. You cannot always win the race: Analyzing the lfence\/jmp mitigation for branch target injection. arXiv preprint arXiv:2203.04277 (2022). arXiv:2203.04277"},{"key":"e_1_3_2_1_47_1","volume-title":"Hide and Seek with Spectres: Efficient Discovery of Speculative Information Leaks with Random Testing. arXiv preprint arXiv:2301.07642","author":"Oleksenko Oleksii","year":"2023","unstructured":"Oleksii Oleksenko , Marco Guarnieri , Boris K\u00f6pf , and Mark Silberstein . 2023. Hide and Seek with Spectres: Efficient Discovery of Speculative Information Leaks with Random Testing. arXiv preprint arXiv:2301.07642 ( 2023 ). arxiv:2301.07642 Oleksii Oleksenko, Marco Guarnieri, Boris K\u00f6pf, and Mark Silberstein. 2023. Hide and Seek with Spectres: Efficient Discovery of Speculative Information Leaks with Random Testing. arXiv preprint arXiv:2301.07642 (2023). arxiv:2301.07642"},{"key":"e_1_3_2_1_48_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Oleksenko Oleksii","year":"2020","unstructured":"Oleksii Oleksenko , Bohdan Trach , Mark Silberstein , and Christof Fetzer . 2020 . SpecFuzz: Bringing Spectre-type vulnerabilities to the surface . In 29th USENIX Security Symposium (USENIX Security 20) . 1481\u20131498. Oleksii Oleksenko, Bohdan Trach, Mark Silberstein, and Christof Fetzer. 2020. SpecFuzz: Bringing Spectre-type vulnerabilities to the surface. In 29th USENIX Security Symposium (USENIX Security 20). 1481\u20131498."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813708"},{"key":"e_1_3_2_1_50_1","volume-title":"RSA conference. 1\u201320","author":"Osvik Dag\u00a0Arne","year":"2006","unstructured":"Dag\u00a0Arne Osvik , Adi Shamir , and Eran Tromer . 2006 . Cache attacks and countermeasures: the case of AES. In Cryptographers\u2019 track at the RSA conference. 1\u201320 . Dag\u00a0Arne Osvik, Adi Shamir, and Eran Tromer. 2006. Cache attacks and countermeasures: the case of AES. In Cryptographers\u2019 track at the RSA conference. 1\u201320."},{"key":"e_1_3_2_1_51_1","volume-title":"USENIX Security Symposium. 645\u2013662","author":"Paccagnella Riccardo","year":"2021","unstructured":"Riccardo Paccagnella , Licheng Luo , and Christopher\u00a0 W Fletcher . 2021 . Lord of the Ring (s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are Practical .. In USENIX Security Symposium. 645\u2013662 . Riccardo Paccagnella, Licheng Luo, and Christopher\u00a0W Fletcher. 2021. Lord of the Ring (s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are Practical.. In USENIX Security Symposium. 645\u2013662."},{"key":"e_1_3_2_1_52_1","unstructured":"Colin Percival. 2005. Cache missing for fun and profit.  Colin Percival. 2005. Cache missing for fun and profit."},{"key":"e_1_3_2_1_53_1","volume-title":"Retrieved","author":"Phillips Kim","year":"2022","unstructured":"Kim Phillips . 2022 . LKML: [PATCH 0\/3] x86\/speculation: Support Automatic IBRS . Retrieved September 18, 2023 from https:\/\/lkml.org\/lkml\/2022\/11\/4\/1199 Kim Phillips. 2022. LKML: [PATCH 0\/3] x86\/speculation: Support Automatic IBRS. Retrieved September 18, 2023 from https:\/\/lkml.org\/lkml\/2022\/11\/4\/1199"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484816"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24466"},{"key":"e_1_3_2_1_56_1","volume-title":"Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution Attacks. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Ragab Hany","year":"2021","unstructured":"Hany Ragab , Enrico Barberis , Herbert Bos , and Cristiano Giuffrida . 2021 . Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution Attacks. In 30th USENIX Security Symposium (USENIX Security 21) . 1451\u20131468. Hany Ragab, Enrico Barberis, Herbert Bos, and Cristiano Giuffrida. 2021. Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution Attacks. In 30th USENIX Security Symposium (USENIX Security 21). 1451\u20131468."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Hany Ragab Alyssa Milburn Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2021. CrossTalk: Speculative Data Leaks Across Cores Are Real. In S&P.  Hany Ragab Alyssa Milburn Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2021. CrossTalk: Speculative Data Leaks Across Cores Are Real. In S&P.","DOI":"10.1109\/SP40001.2021.00020"},{"key":"e_1_3_2_1_58_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Reis Charles","year":"2019","unstructured":"Charles Reis , Alexander Moshchuk , and Nasko Oskov . 2019 . Site isolation: Process separation for web sites within the browser . In 28th USENIX Security Symposium (USENIX Security 19) . 1661\u20131678. Charles Reis, Alexander Moshchuk, and Nasko Oskov. 2019. Site isolation: Process separation for web sites within the browser. In 28th USENIX Security Symposium (USENIX Security 19). 1661\u20131678."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA52012.2021.00036"},{"key":"e_1_3_2_1_60_1","unstructured":"Michael Schwarz Moritz Lipp Daniel Moghimi Jo Van\u00a0Bulck Julian Stecklina Thomas Prescher and Daniel Gruss. 2019. ZombieLoad: Cross-Privilege-Boundary Data Sampling. In CCS.  Michael Schwarz Moritz Lipp Daniel Moghimi Jo Van\u00a0Bulck Julian Stecklina Thomas Prescher and Daniel Gruss. 2019. ZombieLoad: Cross-Privilege-Boundary Data Sampling. In CCS."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_14"},{"key":"e_1_3_2_1_62_1","unstructured":"Junaid Shahid and Ofir Weisse. 2022. https:\/\/lwn.net\/Articles\/909469\/. https:\/\/lwn.net\/ml\/linux-kernel\/20220223052223.1202152-1-junaids@google.com\/ accessed on 02.02.2023.  Junaid Shahid and Ofir Weisse. 2022. https:\/\/lwn.net\/Articles\/909469\/. https:\/\/lwn.net\/ml\/linux-kernel\/20220223052223.1202152-1-junaids@google.com\/ accessed on 02.02.2023."},{"key":"e_1_3_2_1_63_1","volume-title":"Retrieved","author":"Sneddon Daniel","year":"2022","unstructured":"Daniel Sneddon . 2022 . [PATCH 5.4 14\/15] x86\/speculation: Add RSB VM Exit protections . Retrieved September 18, 2023 from https:\/\/lkml.org\/lkml\/2022\/8\/9\/728 Daniel Sneddon. 2022. [PATCH 5.4 14\/15] x86\/speculation: Add RSB VM Exit protections. Retrieved September 18, 2023 from https:\/\/lkml.org\/lkml\/2022\/8\/9\/728"},{"key":"e_1_3_2_1_64_1","volume-title":"Retrieved","author":"Turner Paul","year":"2018","unstructured":"Paul Turner . 2018 . Retpoline: a software construct for preventing branch-target-injection. (2018) . Retrieved September 18, 2023 from https:\/\/support.google.com\/faqs\/answer\/7625886 Paul Turner. 2018. Retpoline: a software construct for preventing branch-target-injection. (2018). Retrieved September 18, 2023 from https:\/\/support.google.com\/faqs\/answer\/7625886"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00089"},{"key":"e_1_3_2_1_66_1","volume-title":"RIDL: Rogue In-flight Data Load. In S&P.","author":"van Schaik Stephan","year":"2019","unstructured":"Stephan van Schaik , Alyssa Milburn , Sebastian \u00d6sterlund , Pietro Frigo , Giorgi Maisuradze , Kaveh Razavi , Herbert Bos , and Cristiano Giuffrida . 2019 . RIDL: Rogue In-flight Data Load. In S&P. Stephan van Schaik, Alyssa Milburn, Sebastian \u00d6sterlund, Pietro Frigo, Giorgi Maisuradze, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2019. RIDL: Rogue In-flight Data Load. In S&P."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833794"},{"key":"e_1_3_2_1_68_1","volume-title":"oo7: Low-overhead defense against spectre attacks via program analysis","author":"Wang Guanhua","year":"2019","unstructured":"Guanhua Wang , Sudipta Chattopadhyay , Ivan Gotovchits , Tulika Mitra , and Abhik Roychoudhury . 2019. oo7: Low-overhead defense against spectre attacks via program analysis . IEEE Transactions on Software Engineering ( 2019 ). Guanhua Wang, Sudipta Chattopadhyay, Ivan Gotovchits, Tulika Mitra, and Abhik Roychoudhury. 2019. oo7: Low-overhead defense against spectre attacks via program analysis. IEEE Transactions on Software Engineering (2019)."},{"key":"e_1_3_2_1_69_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Wang Yingchen","year":"2022","unstructured":"Yingchen Wang , Riccardo Paccagnella , Elizabeth\u00a0Tang He , Hovav Shacham , Christopher\u00a0 W Fletcher , and David Kohlbrenner . 2022 . Hertzbleed: Turning Power { Side-Channel} Attacks Into Remote Timing Attacks on x86 . In 31st USENIX Security Symposium (USENIX Security 22) . 679\u2013697. Yingchen Wang, Riccardo Paccagnella, Elizabeth\u00a0Tang He, Hovav Shacham, Christopher\u00a0W Fletcher, and David Kohlbrenner. 2022. Hertzbleed: Turning Power { Side-Channel} Attacks Into Remote Timing Attacks on x86. In 31st USENIX Security Symposium (USENIX Security 22). 679\u2013697."},{"key":"e_1_3_2_1_70_1","volume-title":"The AMD Branch (Mis)predictor: Just Set it and Forget it!Retrieved","author":"Wieczorkiewicz Pawel","year":"2023","unstructured":"Pawel Wieczorkiewicz . 2022. The AMD Branch (Mis)predictor: Just Set it and Forget it!Retrieved September 18, 2023 from https:\/\/grsecurity.net\/amd_branch_mispredictor_just_set_it_and_forget_it Pawel Wieczorkiewicz. 2022. The AMD Branch (Mis)predictor: Just Set it and Forget it!Retrieved September 18, 2023 from https:\/\/grsecurity.net\/amd_branch_mispredictor_just_set_it_and_forget_it"},{"key":"e_1_3_2_1_71_1","volume-title":"Retrieved","author":"Wieczorkiewicz Pawel","year":"2022","unstructured":"Pawel Wieczorkiewicz . 2022 . The AMD Branch (Mis)predictor Part 2: Where No CPU has Gone Before (CVE-2021-26341) . Retrieved September 18, 2023 from https:\/\/grsecurity.net\/amd_branch_mispredictor_part_2_where_no_cpu_has_gone_before Pawel Wieczorkiewicz. 2022. The AMD Branch (Mis)predictor Part 2: Where No CPU has Gone Before (CVE-2021-26341). Retrieved September 18, 2023 from https:\/\/grsecurity.net\/amd_branch_mispredictor_part_2_where_no_cpu_has_gone_before"},{"key":"e_1_3_2_1_72_1","volume-title":"Spring: Spectre Returning in the Browser with Speculative Load Queuing and Deep Stacks. In 16th IEEE Workshop on Offensive Technologies (WOOT\u201922)","author":"Wikner Johannes","year":"2022","unstructured":"Johannes Wikner , Cristiano Giuffrida , Herbert Bos , and Kaveh Razavi . 2022 . Spring: Spectre Returning in the Browser with Speculative Load Queuing and Deep Stacks. In 16th IEEE Workshop on Offensive Technologies (WOOT\u201922) . IEEE. Johannes Wikner, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. 2022. Spring: Spectre Returning in the Browser with Speculative Load Queuing and Deep Stacks. In 16th IEEE Workshop on Offensive Technologies (WOOT\u201922). IEEE."},{"key":"e_1_3_2_1_73_1","volume-title":"Retbleed: Arbitrary Speculative Code Execution with Return Instructions. In 31st USENIX Security Symposium (USENIX Security 22)","author":"Wikner Johannes","year":"2022","unstructured":"Johannes Wikner and Kaveh Razavi . 2022 . Retbleed: Arbitrary Speculative Code Execution with Return Instructions. In 31st USENIX Security Symposium (USENIX Security 22) . 3825\u20133842. Johannes Wikner and Kaveh Razavi. 2022. Retbleed: Arbitrary Speculative Code Execution with Return Instructions. In 31st USENIX Security Symposium (USENIX Security 22). 3825\u20133842."},{"key":"e_1_3_2_1_74_1","unstructured":"Dan Williams. 2018. LKML: [PATCH v6 02\/13] array_index_nospec: sanitize speculative array de-references. (2018). https:\/\/lore.kernel.org\/lkml\/151727414808.33451.1873237130672785331.stgit@dwillia2-desk3.amr.corp.intel.com\/.  Dan Williams. 2018. LKML: [PATCH v6 02\/13] array_index_nospec: sanitize speculative array de-references. (2018). https:\/\/lore.kernel.org\/lkml\/151727414808.33451.1873237130672785331.stgit@dwillia2-desk3.amr.corp.intel.com\/."},{"key":"e_1_3_2_1_75_1","volume-title":"A Secret-Free Hypervisor: Rethinking Isolation in the Age of Speculative Vulnerabilities","author":"Xia Hongyan","unstructured":"Hongyan Xia , David Zhang , Wei Liu , Istvan Haller , Bruce Sherwin , and David Chisnall . 2022. A Secret-Free Hypervisor: Rethinking Isolation in the Age of Speculative Vulnerabilities . In IEEE S&P \u201922. IEEE , 370\u2013385. Hongyan Xia, David Zhang, Wei Liu, Istvan Haller, Bruce Sherwin, and David Chisnall. 2022. A Secret-Free Hypervisor: Rethinking Isolation in the Age of Speculative Vulnerabilities. In IEEE S&P \u201922. IEEE, 370\u2013385."},{"key":"e_1_3_2_1_76_1","volume-title":"USENIX Security Symposium. 719\u2013732","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner . 2014 . FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack . In USENIX Security Symposium. 719\u2013732 . Yuval Yarom and Katrina Falkner. 2014. FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. In USENIX Security Symposium. 719\u2013732."},{"key":"e_1_3_2_1_77_1","unstructured":"Zhiyuan Zhang Mingtian Tao Sioli O\u2019Connell Chitchanok Chuengsatiansup Daniel Genkin and Yuval Yarom. 2023. BunnyHop: Exploiting the Instruction Prefetcher. (2023).  Zhiyuan Zhang Mingtian Tao Sioli O\u2019Connell Chitchanok Chuengsatiansup Daniel Genkin and Yuval Yarom. 2023. BunnyHop: Exploiting the Instruction Prefetcher. (2023)."},{"key":"e_1_3_2_1_78_1","volume-title":"Retrieved","author":"Zomer Jordy","year":"2023","unstructured":"Jordy Zomer and Alexandra Sandulescu . 2023 . Linux Kernel: Spectre-v1 gadgets . Retrieved September 18, 2023 from https:\/\/github.com\/google\/security-research\/security\/advisories\/GHSA-m7j5-797w-vmrh Jordy Zomer and Alexandra Sandulescu. 2023. Linux Kernel: Spectre-v1 gadgets. Retrieved September 18, 2023 from https:\/\/github.com\/google\/security-research\/security\/advisories\/GHSA-m7j5-797w-vmrh"}],"event":{"name":"MICRO '23: 56th Annual IEEE\/ACM International Symposium on Microarchitecture","location":"Toronto ON Canada","acronym":"MICRO '23","sponsor":["SIGMICRO ACM Special Interest Group on Microarchitectural Research and Processing"]},"container-title":["56th Annual IEEE\/ACM International Symposium on Microarchitecture"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3613424.3614275","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3613424.3614275","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:29Z","timestamp":1750178189000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3613424.3614275"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,28]]},"references-count":77,"alternative-id":["10.1145\/3613424.3614275","10.1145\/3613424"],"URL":"https:\/\/doi.org\/10.1145\/3613424.3614275","relation":{},"subject":[],"published":{"date-parts":[[2023,10,28]]},"assertion":[{"value":"2023-12-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}