{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T12:19:34Z","timestamp":1760098774265,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":97,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2008339","CNS-2147217"],"award-info":[{"award-number":["CNS-2008339","CNS-2147217"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1145\/3634737.3661139","type":"proceedings-article","created":{"date-parts":[[2024,6,28]],"date-time":"2024-06-28T11:51:38Z","timestamp":1719575498000},"page":"498-511","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["PowSpectre: Powering Up Speculation Attacks with TSX-based Replay"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6132-3343","authenticated-orcid":false,"given":"Md Hafizul Islam","family":"Chowdhuryy","sequence":"first","affiliation":[{"name":"University of Central Florida, Orlando, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9025-3460","authenticated-orcid":false,"given":"Zhenkai","family":"Zhang","sequence":"additional","affiliation":[{"name":"Clemson University, Clemson, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0360-5641","authenticated-orcid":false,"given":"Fan","family":"Yao","sequence":"additional","affiliation":[{"name":"University of Central Florida, Orlando, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,7]]},"reference":[{"volume-title":"d.]","year":"2020","key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. 2020.2 IPU - Intel RAPL Interface Advisory. https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00389.html"},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. Introduction to Cache Allocation Technology in the Intel\u00ae Xeon\u00ae Processor E5 v4 Family. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/introduction-to-cache-allocation-technology.html"},{"key":"e_1_3_2_1_3_1","unstructured":"[n. d.]. microcode-20201110 release: Intel INTEL-SA-00381. https:\/\/github.com\/intel\/Intel-Linux-Processor-Microcode-Data-Files\/releases\/tag\/microcode-20201110\/"},{"key":"e_1_3_2_1_4_1","unstructured":"[n. d.]. microcode-20220510 release. https:\/\/github.com\/intel\/Intel-Linux-Processor-Microcode-Data-Files\/releases\/tag\/microcode-20220510\/"},{"key":"e_1_3_2_1_5_1","unstructured":"[n. d.]. PLATYPUS: With Great Power comes Great Leakage. https:\/\/platypusattack.com\/"},{"key":"e_1_3_2_1_6_1","unstructured":"[n. d.]. Running Average Power Limit Energy Reporting \/ CVE-2020-8694 CVE-2020-8695 \/ INTEL-SA-00389. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/advisory-guidance\/running-average-power-limit-energy-reporting.html"},{"key":"e_1_3_2_1_7_1","unstructured":"[n. d.]. TAA - TSX Asynchronous Abort. https:\/\/www.intel.com\/content\/www\/us\/en\/newsroom\/news\/ucsf-propel-medical-device-innovations.html"},{"volume-title":"On the power of simple branch prediction analysis","author":"Acii\u00e7mez Onur","key":"e_1_3_2_1_8_1","unstructured":"Onur Acii\u00e7mez, \u00c7etin Kaya Ko\u00e7, and Jean-Pierre Seifert. 2007. On the power of simple branch prediction analysis. In IEEE ISCA."},{"key":"e_1_3_2_1_9_1","volume-title":"Sohaib ul Hassan, Cesar Pereida Garcia, and Nicola Tuveri.","author":"Aldaya Alejandro Cabrera","year":"2019","unstructured":"Alejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida Garcia, and Nicola Tuveri. 2019. Port Contention for Fun and Profit. In IEEE S&P."},{"key":"e_1_3_2_1_10_1","unstructured":"Enrico Barberis Pietro Frigo Marius Muench Herbert Bos and Cristiano Giuffrida. 2022. Branch history injection: On the effectiveness of hardware mitigations against cross-privilege Spectre-v2 attacks. In USENIX Security."},{"volume-title":"Pearson correlation coefficient","author":"Benesty Jacob","key":"e_1_3_2_1_11_1","unstructured":"Jacob Benesty, Jingdong Chen, Yiteng Huang, and Israel Cohen. 2009. Pearson correlation coefficient. In Springer Noise reduction in speech processing."},{"key":"e_1_3_2_1_12_1","volume-title":"Specrop: Speculative exploitation of ROP chains. In USENIX RAID.","author":"Bhattacharyya Atri","year":"2020","unstructured":"Atri Bhattacharyya, Andr\u00e9s S\u00e1nchez, Esmaeil M Koruyeh, Nael Abu-Ghazaleh, Chengyu Song, and Mathias Payer. 2020. Specrop: Speculative exploitation of ROP chains. In USENIX RAID."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Atri Bhattacharyya Alexandra Sandulescu Matthias Neugschwandtner Alessandro Sorniotti Babak Falsafi Mathias Payer and Anil Kurmus. 2019. SMoTherSpectre: Exploiting Speculative Execution through Port Contention. In ACM CCS.","DOI":"10.1145\/3319535.3363194"},{"key":"e_1_3_2_1_14_1","volume-title":"Casa: End-to-end quantitative security analysis of randomly mapped caches","author":"Bourgeat Thomas","year":"2020","unstructured":"Thomas Bourgeat, Jules Drean, Yuheng Yang, Lillian Tsai, Joel Emer, and Mengjia Yan. 2020. Casa: End-to-end quantitative security analysis of randomly mapped caches. In IEEE MICRO."},{"volume-title":"MI6: Secure Enclaves in a Speculative Out-of-Order Processor","author":"Bourgeat Thomas","key":"e_1_3_2_1_15_1","unstructured":"Thomas Bourgeat, Ilia Lebedev, Andrew Wright, Sizhuo Zhang, Arvind, and Srinivas Devadas. 2019. MI6: Secure Enclaves in a Speculative Out-of-Order Processor. In IEEE MICRO."},{"key":"e_1_3_2_1_16_1","volume-title":"Jo Van Bulck, and Yuval Yarom","author":"Canella Claudio","year":"2019","unstructured":"Claudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss, Moritz Lipp, Marina Minkin, Daniel Moghimi, Frank Piessens, Michael Schwarz, Berk Sunar, Jo Van Bulck, and Yuval Yarom. 2019. Fallout: Leaking Data on Meltdown-resistant CPUs. In ACM CCS."},{"key":"e_1_3_2_1_17_1","volume-title":"Michael Schwarz, Moritz Lipp","author":"Canella Claudio","year":"2019","unstructured":"Claudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp, Benjamin Von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, and Daniel Gruss. 2019. A systematic evaluation of transient execution attacks and defenses. In USENIX Security."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3385970"},{"key":"e_1_3_2_1_19_1","volume-title":"Sgxpectre: Stealing intel secrets from SGX enclaves via speculative execution","author":"Chen Guoxing","year":"2019","unstructured":"Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten H Lai. 2019. Sgxpectre: Stealing intel secrets from SGX enclaves via speculative execution. In IEEE EuroS&P."},{"key":"e_1_3_2_1_20_1","volume-title":"Cc-hunter: Uncovering covert timing channels on shared processor hardware","author":"Chen Jie","year":"2014","unstructured":"Jie Chen and Guru Venkataramani. 2014. Cc-hunter: Uncovering covert timing channels on shared processor hardware. In IEEE MICRO."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Sanchuan Chen Xiaokuan Zhang Michael K. Reiter and Yinqian Zhang. 2017. Detecting Privileged Side-Channel Attacks in Shielded Execution with D\u00e9j\u00e0 Vu. In ACM ASIACCS.","DOI":"10.1145\/3052973.3053007"},{"volume-title":"R-SAW: New Side Channels Exploiting Read Asymmetry in MLC Phase Change Memories","author":"Islam Chowdhuryy Md Hafizul","key":"e_1_3_2_1_22_1","unstructured":"Md Hafizul Islam Chowdhuryy, Rickard Ewetz, Amro Awad, and Fan Yao. 2021. R-SAW: New Side Channels Exploiting Read Asymmetry in MLC Phase Change Memories. In IEEE SEED."},{"key":"e_1_3_2_1_23_1","volume-title":"Understanding and Characterizing Side Channels Exploiting Phase-Change Memories","author":"Islam Chowdhuryy Md Hafizul","year":"2023","unstructured":"Md Hafizul Islam Chowdhuryy, Rickard Ewetz, Amro Awad, and Fan Yao. 2023. Understanding and Characterizing Side Channels Exploiting Phase-Change Memories. IEEE Micro (2023)."},{"volume-title":"BranchSpec: Information Leakage Attacks Exploiting Speculative Branch Instruction Executions","author":"Islam Chowdhuryy Md Hafizul","key":"e_1_3_2_1_24_1","unstructured":"Md Hafizul Islam Chowdhuryy, Hang Liu, and Fan Yao. 2020. BranchSpec: Information Leakage Attacks Exploiting Speculative Branch Instruction Executions. In IEEE ICCD."},{"key":"e_1_3_2_1_25_1","volume-title":"Leaking Secrets through Modern Branch Predictor in the Speculative World","author":"Islam Chowdhuryy Md Hafizul","year":"2021","unstructured":"Md Hafizul Islam Chowdhuryy and Fan Yao. 2021. Leaking Secrets through Modern Branch Predictor in the Speculative World. IEEE TC (2021)."},{"volume-title":"BeKnight: Guarding Against Information Leakage in Speculatively Updated Branch Predictors","author":"Islam Chowdhuryy Md Hafizul","key":"e_1_3_2_1_26_1","unstructured":"Md Hafizul Islam Chowdhuryy, Zhenkai Zhang, and Fan Yao. 2023. BeKnight: Guarding Against Information Leakage in Speculatively Updated Branch Predictors. In IEEE ICCAD."},{"key":"e_1_3_2_1_27_1","volume-title":"Arie Haenel, Daniel Genkin, Angelos D Keromytis, Yossi Oren, and Yuval Yarom.","author":"Cohen Yaakov","year":"2022","unstructured":"Yaakov Cohen, Kevin Sam Tharayil, Arie Haenel, Daniel Genkin, Angelos D Keromytis, Yossi Oren, and Yuval Yarom. 2022. HammerScope: Observing DRAM Power Consumption Using Rowhammer. ACM CCS (2022)."},{"key":"e_1_3_2_1_28_1","volume-title":"Xiang Cheng, Yuan Xiao, Cedric Xing, Ilya Alexandrovich, Taesoo Kim, Frank Piessens, Mona Vij, and Mark Silberstein.","author":"Constable Scott","year":"2023","unstructured":"Scott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao, Cedric Xing, Ilya Alexandrovich, Taesoo Kim, Frank Piessens, Mona Vij, and Mark Silberstein. 2023. AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX Enclaves. In USENIX Security 23."},{"key":"e_1_3_2_1_29_1","unstructured":"Intel Corporation. [n. d.]. Intel\u00ae Software Guard Extensions SSL. https:\/\/github.com\/intel\/intel-sgx-ssl"},{"key":"e_1_3_2_1_30_1","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX Explained. IACR Cryptol. ePrint Arch. (2016)."},{"key":"e_1_3_2_1_31_1","volume-title":"Shweta Shinde, Prateek Saxena, and Zhiping Cai.","author":"Cui Jinhua","year":"2021","unstructured":"Jinhua Cui, Jason Zhijingcheng Yu, Shweta Shinde, Prateek Saxena, and Zhiping Cai. 2021. SmashEx: Smashing SGX Enclaves Using Exceptions. In ACM CCS."},{"key":"e_1_3_2_1_32_1","unstructured":"Craig Disselkoen David Kohlbrenner Leo Porter and Dean Tullsen. 2017. Prime+Abort: A Timer-FreeHigh-Precision L3 Cache Attack using Intel TSX. In USENIX Security."},{"volume-title":"Jump over ASLR: Attacking branch predictors to bypass ASLR","author":"Evtyushkin Dmitry","key":"e_1_3_2_1_33_1","unstructured":"Dmitry Evtyushkin, Dmitry Ponomarev, and Nael Abu-Ghazaleh. 2016. Jump over ASLR: Attacking branch predictors to bypass ASLR. In IEEE MICRO."},{"key":"e_1_3_2_1_34_1","volume-title":"ECE, and Dmitry Ponomarev.","author":"Evtyushkin Dmitry","year":"2018","unstructured":"Dmitry Evtyushkin, Ryan Riley, Nael CSE Abu-Ghazaleh, ECE, and Dmitry Ponomarev. 2018. Branchscope: A new side-channel attack on directional branch predictor. In ACM ASPLOS."},{"key":"e_1_3_2_1_35_1","volume-title":"Fan Yao, Milo\u0161 Doroslova\u010dki, and Guru Venkataramani.","author":"Fang Hongyu","year":"2018","unstructured":"Hongyu Fang, Sai Santosh Dayapule, Fan Yao, Milo\u0161 Doroslova\u010dki, and Guru Venkataramani. 2018. A noise-resilient detection method against advanced cache timing channel attack. In IEEE ACSSC."},{"key":"e_1_3_2_1_36_1","unstructured":"GPG. 2013. Mitigate a flush+reload cache attack on RSA secret exponents. (2013). https:\/\/github.com\/gpg\/libgcrypt\/commit\/e2202ff2b"},{"key":"e_1_3_2_1_37_1","unstructured":"Ben Gras Kaveh Razavi Herbert Bos and Cristiano Giuffrida. 2018. Translation leak-aside buffer: Defeating cache side-channel protections with TLB attacks. In USENIX Security."},{"key":"e_1_3_2_1_38_1","unstructured":"Daniel Gruss Julian Lettner Felix Schuster Olya Ohrimenko Istvan Haller and Manuel Costa. 2017. Strong and Efficient Cache Side-Channel Protection using Hardware Transactional Memory. In USENIX Security."},{"key":"e_1_3_2_1_39_1","first-page":"055","article-title":"Accurate tracking of transactional read and write sets with speculation","volume":"10","author":"Gschwind Michael Karl","year":"2018","unstructured":"Michael Karl Gschwind, Valentina Salapura, and Chung-Lung K Shum. 2018. Accurate tracking of transactional read and write sets with speculation. US Patent 10,055,230.","journal-title":"US Patent"},{"key":"e_1_3_2_1_40_1","unstructured":"Michael K Gschwind Valentina Salapura and Chung-Lung K Shum. 2020. Read and write sets for ranges of instructions of transactions."},{"key":"e_1_3_2_1_41_1","volume-title":"A Giray Ya\u011fl\u0131k\u00e7\u0131, Mohammed Alser, Ivan Puddu, and Onur Mutlu.","author":"Haj-Yahya Jawad","year":"2021","unstructured":"Jawad Haj-Yahya, Lois Orosa, Jeremie S Kim, Juan G\u00f3mez Luna, A Giray Ya\u011fl\u0131k\u00e7\u0131, Mohammed Alser, Ivan Puddu, and Onur Mutlu. 2021. IChannels: Exploiting Current Management Mechanisms to Create Covert Channels in Modern Processors. In IEEE ISCA."},{"key":"e_1_3_2_1_42_1","volume-title":"Nils Ole Tippenhauer, and Saman Zonouz","author":"Han Yi","year":"2022","unstructured":"Yi Han, Matthew Chan, Zahra Aref, Nils Ole Tippenhauer, and Saman Zonouz. 2022. Hiding in Plain Sight? On the Efficacy of Power Side Channel-Based Control Flow Monitoring. In USENIX Security."},{"key":"e_1_3_2_1_43_1","volume-title":"TSGX: Defeating SGX Side Channel Attack with Support of TPM","author":"Hongwei Zhou","year":"2021","unstructured":"Zhou Hongwei, Ke Zhipeng, Zhang Yuchen, Wu Dangyang, and Yuan Jinhui. 2021. TSGX: Defeating SGX Side Channel Attack with Support of TPM. In IEEE ACCTCS."},{"volume-title":"Understanding contention-based channels and using them for defense","author":"Hunger Casen","key":"e_1_3_2_1_44_1","unstructured":"Casen Hunger, Mikhail Kazdagli, Ankit Rawat, Alex Dimakis, Sriram Vishwanath, and Mohit Tiwari. 2015. Understanding contention-based channels and using them for defense. In IEEE HPCA."},{"volume-title":"Deep Dive: Indirect Branch Predictor Barrier. https:\/\/software.intel.com\/security-software-guidance\/deep-dives\/deep-dive-indirect-branch-predictor-barrier","year":"2018","key":"e_1_3_2_1_45_1","unstructured":"Intel. 2018. Deep Dive: Indirect Branch Predictor Barrier. https:\/\/software.intel.com\/security-software-guidance\/deep-dives\/deep-dive-indirect-branch-predictor-barrier"},{"volume-title":"Deep Dive: Indirect Branch Restricted Speculation. https:\/\/software.intel.com\/security-software-guidance\/insights\/deep-dive-indirect-branch-restricted-speculation","year":"2018","key":"e_1_3_2_1_46_1","unstructured":"Intel. 2018. Deep Dive: Indirect Branch Restricted Speculation. https:\/\/software.intel.com\/security-software-guidance\/insights\/deep-dive-indirect-branch-restricted-speculation"},{"volume-title":"Deep Dive: Single Thread Indirect Branch Predictors. https:\/\/software.intel.com\/security-software-guidance\/deep-dives\/deep-dive-single-thread-indirect-branch-predictors","year":"2018","key":"e_1_3_2_1_47_1","unstructured":"Intel. 2018. Deep Dive: Single Thread Indirect Branch Predictors. https:\/\/software.intel.com\/security-software-guidance\/deep-dives\/deep-dive-single-thread-indirect-branch-predictors"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Yeongjin Jang Sangho Lee and Taesoo Kim. 2016. Breaking kernel address space layout randomization with intel tsx. In ACM CCS.","DOI":"10.1145\/2976749.2978321"},{"volume-title":"Powert channels: A novel class of covert communicationexploiting power management vulnerabilities","author":"Khatamifard S Karen","key":"e_1_3_2_1_49_1","unstructured":"S Karen Khatamifard, Longfei Wang, Amitabh Das, Selcuk Kose, and Ulya R Karpuzcu. 2019. Powert channels: A novel class of covert communicationexploiting power management vulnerabilities. In IEEE HPCA."},{"key":"e_1_3_2_1_50_1","volume-title":"DAWG: A defense against cache timing attacks in speculative execution processors","author":"Kiriansky Vladimir","year":"2018","unstructured":"Vladimir Kiriansky, Ilia Lebedev, Saman Amarasinghe, Srinivas Devadas, and Joel Emer. 2018. DAWG: A defense against cache timing attacks in speculative execution processors. In IEEE MICRO."},{"volume-title":"Spectre attacks: Exploiting speculative execution","author":"Kocher Paul","key":"e_1_3_2_1_51_1","unstructured":"Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre attacks: Exploiting speculative execution. In IEEE S&P."},{"volume-title":"Differential power analysis","author":"Kocher Paul","key":"e_1_3_2_1_52_1","unstructured":"Paul Kocher, Joshua Jaffe, and Benjamin Jun. 1999. Differential power analysis. In Springer Annual international cryptology conference."},{"key":"e_1_3_2_1_53_1","unstructured":"Andreas Kogler Jonas Juffinger Lukas Giner Lukas Gerlach Martin Schwarzl Michael Schwarz Daniel Gruss and Stefan Mangard. 2023. Collide+ Power: Leaking Inaccessible Data with Software-based Power Side Channels. In USENIX Security."},{"volume-title":"Are Crossbar Memories Secure? New Security Vulnerabilities in Crossbar Memories","author":"Kommareddy Vamsee Reddy","key":"e_1_3_2_1_54_1","unstructured":"Vamsee Reddy Kommareddy, Baogang Zhang, Fan Yao, Rickard Ewetz, and Amro Awad. 2019. Are Crossbar Memories Secure? New Security Vulnerabilities in Crossbar Memories. In IEEE CAL."},{"key":"e_1_3_2_1_55_1","unstructured":"Sangho Lee Ming-Wei Shih Prasun Gera Taesoo Kim Hyesoon Kim and Marcus Peinado. 2017. Inferring fine-grained control flow inside SGX enclaves with branch shadowing. In USENIX Security."},{"key":"e_1_3_2_1_56_1","unstructured":"Moritz Lipp Daniel Gruss and Michael Schwarz. 2022. Amd prefetch attacks through power and time. In USENIX Security."},{"key":"e_1_3_2_1_57_1","volume-title":"PLATYPUS: Software-based Power Side-Channel Attacks on x86","author":"Lipp Moritz","year":"2021","unstructured":"Moritz Lipp, Andreas Kogler, David Oswald, Michael Schwarz, Catherine Easdon, Claudio Canella, and Daniel Gruss. 2021. PLATYPUS: Software-based Power Side-Channel Attacks on x86. In IEEE S&P."},{"key":"e_1_3_2_1_58_1","volume-title":"Meltdown: Reading kernel memory from user space. In USENIX Security.","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, et al. 2018. Meltdown: Reading kernel memory from user space. In USENIX Security."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"crossref","unstructured":"Chen Liu Abhishek Chakraborty Nikhil Chawla and Neer Roggel. 2022. Frequency throttling side-channel attack. In ACM CCS.","DOI":"10.1145\/3548606.3560682"},{"key":"e_1_3_2_1_60_1","volume-title":"Catalyst: Defeating last-level cache side channel attacks in cloud computing","author":"Liu Fangfei","year":"2016","unstructured":"Fangfei Liu, Qian Ge, Yuval Yarom, Frank Mckeen, Carlos Rozas, Gernot Heiser, and Ruby B Lee. 2016. Catalyst: Defeating last-level cache side channel attacks in cloud computing. In IEEE HPCA."},{"volume-title":"Last-level cache side-channel attacks are practical","author":"Liu Fangfei","key":"e_1_3_2_1_61_1","unstructured":"Fangfei Liu, Yuval Yarom, Qian Ge, Gernot Heiser, and Ruby B Lee. 2015. Last-level cache side-channel attacks are practical. In IEEE S&P."},{"key":"e_1_3_2_1_62_1","volume-title":"Timewarp: Rethinking timekeeping and performance monitoring mechanisms to mitigate side-channel attacks","author":"Martin Robert","year":"2012","unstructured":"Robert Martin, John Demme, and Simha Sethumadhavan. 2012. Timewarp: Rethinking timekeeping and performance monitoring mechanisms to mitigate side-channel attacks. In IEEE ISCA."},{"key":"e_1_3_2_1_63_1","volume-title":"Cachezoom: How SGX amplifies the power of cache attacks","author":"Moghimi Ahmad","year":"2017","unstructured":"Ahmad Moghimi, Gorka Irazoqui, and Thomas Eisenbarth. 2017. Cachezoom: How SGX amplifies the power of cache attacks. In Springer CHES."},{"key":"e_1_3_2_1_64_1","unstructured":"OpenSSL. [n. d.]. OpenSSL 1.1.0 Series Release Notes. https:\/\/www.openssl.org\/news\/openssl-1.1.0-notes.html"},{"key":"e_1_3_2_1_65_1","volume-title":"Autarky: Closing controlled channels with self-paging enclaves. In ACM EuroSys. 1--16.","author":"Orenbach Meni","year":"2020","unstructured":"Meni Orenbach, Andrew Baumann, and Mark Silberstein. 2020. Autarky: Closing controlled channels with self-paging enclaves. In ACM EuroSys. 1--16."},{"volume-title":"Cache attacks and countermeasures: the case of AES","author":"Osvik Dag Arne","key":"e_1_3_2_1_66_1","unstructured":"Dag Arne Osvik, Adi Shamir, and Eran Tromer. 2006. Cache attacks and countermeasures: the case of AES. In Springer CT-RSA."},{"key":"e_1_3_2_1_67_1","volume-title":"DRAMA: Exploiting DRAM addressing for Cross-CPU attacks. In USENIX Security.","author":"Pessl Peter","year":"2016","unstructured":"Peter Pessl, Daniel Gruss, Cl\u00e9mentine Maurice, Michael Schwarz, and Stefan Mangard. 2016. DRAMA: Exploiting DRAM addressing for Cross-CPU attacks. In USENIX Security."},{"key":"e_1_3_2_1_68_1","volume-title":"Frontal Attack: Leaking Control-Flow in SGX via the CPU Frontend. In USENIX Security.","author":"Puddu Ivan","year":"2021","unstructured":"Ivan Puddu, Moritz Schneider, Miro Haller, and Srdjan \u010capkun. 2021. Frontal Attack: Leaking Control-Flow in SGX via the CPU Frontend. In USENIX Security."},{"volume-title":"I see dead \u03bcops: Leaking secrets via Intel\/AMD micro-op caches","author":"Ren Xida","key":"e_1_3_2_1_69_1","unstructured":"Xida Ren, Logan Moody, Mohammadkazem Taram, Matthew Jordan, Dean M Tullsen, and Ashish Venkat. 2021. I see dead \u03bcops: Leaking secrets via Intel\/AMD micro-op caches. In IEEE ISCA."},{"volume-title":"CleanupSpec: An 'Undo' Approach to Safe Speculation","author":"Saileshwar Gururaj","key":"e_1_3_2_1_70_1","unstructured":"Gururaj Saileshwar and Moinuddin K Qureshi. 2019. CleanupSpec: An 'Undo' Approach to Safe Speculation. In IEEE MICRO."},{"key":"e_1_3_2_1_71_1","volume-title":"Julian Stecklina, Thomas Prescher, and Daniel Gruss.","author":"Schwarz Michael","year":"2019","unstructured":"Michael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck, Julian Stecklina, Thomas Prescher, and Daniel Gruss. 2019. ZombieLoad: Cross-Privilege-Boundary Data Sampling. In ACM CCS."},{"key":"e_1_3_2_1_72_1","volume-title":"Alenka Zajic, and Milos Prvulovic.","author":"Sehatbakhsh Nader","year":"2020","unstructured":"Nader Sehatbakhsh, Baki Berkay Yilmaz, Alenka Zajic, and Milos Prvulovic. 2020. A new side-channel vulnerability on modern computers by exploiting electromagnetic emanations from the power management unit. In IEEE HPCA."},{"key":"e_1_3_2_1_73_1","volume-title":"Rosita: Towards automatic elimination of power-analysis leakage in ciphers. arXiv preprint arXiv:1912.05183","author":"Shelton Madura A","year":"2019","unstructured":"Madura A Shelton, Niels Samwel, Lejla Batina, Francesco Regazzoni, Markus Wagner, and Yuval Yarom. 2019. Rosita: Towards automatic elimination of power-analysis leakage in ciphers. arXiv preprint arXiv:1912.05183 (2019)."},{"key":"e_1_3_2_1_74_1","volume-title":"Lockeddown: Exploiting contention on host-gpu pcie bus for fun and profit","author":"Side Mert","year":"2022","unstructured":"Mert Side, Fan Yao, and Zhenkai Zhang. 2022. Lockeddown: Exploiting contention on host-gpu pcie bus for fun and profit. In IEEE EuroS&P."},{"key":"e_1_3_2_1_75_1","volume-title":"Microscope: Enabling microarchitectural replay attacks","author":"Skarlatos Dimitrios","year":"2019","unstructured":"Dimitrios Skarlatos, Mengjia Yan, Bhargava Gopireddy, Read Sprabery, Josep Torrellas, and Christopher W Fletcher. 2019. Microscope: Enabling microarchitectural replay attacks. In IEEE ISCA."},{"key":"e_1_3_2_1_76_1","volume-title":"Dmitry Ponomarev, and O\u011fuz Ergin.","author":"Townley Daniel","year":"2022","unstructured":"Daniel Townley, Kerem Ar\u0131kan, Yu David Liu, Dmitry Ponomarev, and O\u011fuz Ergin. 2022. Composable Cachelets: Protecting Enclaves from Cache Side-Channel Attacks. In USENIX Security."},{"key":"e_1_3_2_1_77_1","unstructured":"Paul Turner. 2018. Retpoline: a software construct for preventing branch-target-injection. https:\/\/support.google.com\/faqs\/answer\/7625886"},{"key":"e_1_3_2_1_78_1","volume-title":"Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution. In USENIX Security.","author":"Bulck Jo Van","year":"2018","unstructured":"Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution. In USENIX Security."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"crossref","unstructured":"Jo Van Bulck Frank Piessens and Raoul Strackx. 2017. SGX-Step: A Practical Attack Framework for Precise Enclave Execution Control. In ACM SsyTEX.","DOI":"10.1145\/3152701.3152706"},{"key":"e_1_3_2_1_80_1","volume-title":"Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt Logic. In ACM CCS.","author":"Bulck Jo Van","year":"2018","unstructured":"Jo Van Bulck, Frank Piessens, and Raoul Strackx. 2018. Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt Logic. In ACM CCS."},{"key":"e_1_3_2_1_81_1","volume-title":"RIDL: Rogue In-Flight Data Load","author":"van Schaik Stephan","year":"2019","unstructured":"Stephan van Schaik, Alyssa Milburn, Sebastian Osterlund, Pietro Frigo, Giorgi Maisuradze, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2019. RIDL: Rogue In-Flight Data Load. In IEEE S&P."},{"volume-title":"CacheOut: Leaking Data on Intel CPUs via Cache Evictions","author":"van Schaik Stephan","key":"e_1_3_2_1_82_1","unstructured":"Stephan van Schaik, Marina Minkin, Andrew Kwong, Daniel Genkin, and Yuval Yarom. 2021. CacheOut: Leaking Data on Intel CPUs via Cache Evictions. In IEEE S&P."},{"key":"e_1_3_2_1_83_1","volume-title":"Gunter","author":"Wang Wenhao","year":"2017","unstructured":"Wenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang, XiaoFeng Wang, Vincent Bindschaedler, Haixu Tang, and Carl A. Gunter. 2017. Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGX. In ACM CCS."},{"key":"e_1_3_2_1_84_1","volume-title":"Hovav Shacham, Christopher W Fletcher, and David Kohlbrenner.","author":"Wang Yingchen","year":"2022","unstructured":"Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham, Christopher W Fletcher, and David Kohlbrenner. 2022. Hertzbleed: Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86. In USENIX Security."},{"volume-title":"DVFS frequently leaks secrets: Hertzbleed attacks beyond SIKE, cryptography, and CPU-only data","author":"Wang Yingchen","key":"e_1_3_2_1_85_1","unstructured":"Yingchen Wang, Riccardo Paccagnella, Alan Wandke, Zhao Gang, Grant Garrett-Grossman, Christopher W Fletcher, David Kohlbrenner, and Hovav Shacham. 2023. DVFS frequently leaks secrets: Hertzbleed attacks beyond SIKE, cryptography, and CPU-only data. In IEEE S&P."},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"crossref","unstructured":"Haocheng Xiao and Sam Ainsworth. 2023. Hacky racers: Exploiting instruction-level parallelism to generate stealthy fine-grained timers. In ACM ASPLOS.","DOI":"10.1145\/3575693.3575700"},{"key":"e_1_3_2_1_87_1","volume-title":"Survey of Transient Execution Attacks. Comput. Surveys","author":"Xiong Wenjie","year":"2021","unstructured":"Wenjie Xiong and Jakub Szefer. 2021. Survey of Transient Execution Attacks. Comput. Surveys (2021)."},{"volume-title":"InvisiSpec: Making speculative execution invisible in the cache hierarchy","author":"Yan Mengjia","key":"e_1_3_2_1_88_1","unstructured":"Mengjia Yan, Jiho Choi, Dimitrios Skarlatos, Adam Morrison, Christopher Fletcher, and Josep Torrellas. 2018. InvisiSpec: Making speculative execution invisible in the cache hierarchy. In IEEE MICRO."},{"volume-title":"Secure Hierarchy-Aware Cache Replacement Policy (SHARP): Defending Against Cache-Based Side Channel Atacks","author":"Yan Mengjia","key":"e_1_3_2_1_89_1","unstructured":"Mengjia Yan, Bhargava Gopireddy, Thomas Shull, and Josep Torrellas. 2017. Secure Hierarchy-Aware Cache Replacement Policy (SHARP): Defending Against Cache-Based Side Channel Atacks. In IEEE ISCA."},{"volume-title":"Attack Directories","author":"Yan Mengjia","key":"e_1_3_2_1_90_1","unstructured":"Mengjia Yan, Read Sprabery, Bhargava Gopireddy, Christopher Fletcher, Roy Campbell, and Josep Torrellas. 2019. Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive World. In IEEE S&P."},{"volume-title":"Are coherence protocol states vulnerable to information leakage?","author":"Yao Fan","key":"e_1_3_2_1_91_1","unstructured":"Fan Yao, Milos Doroslovacki, and Guru Venkataramani. 2018. Are coherence protocol states vulnerable to information leakage?. In IEEE HPCA."},{"key":"e_1_3_2_1_92_1","volume-title":"Covert timing channels exploiting cache coherence hardware: Characterization and defense","author":"Yao Fan","year":"2019","unstructured":"Fan Yao, Milo\u0161 Doroslova\u010dki, and Guru Venkataramani. 2019. Covert timing channels exploiting cache coherence hardware: Characterization and defense. Springer IJPP (2019)."},{"volume-title":"COTSknight: Practical defense against cache timing channel attacks using cache monitoring and partitioning technologies","author":"Yao Fan","key":"e_1_3_2_1_93_1","unstructured":"Fan Yao, Hongyu Fang, Milo\u0161 Doroslova\u010dki, and Guru Venkataramani. 2019. COTSknight: Practical defense against cache timing channel attacks using cache monitoring and partitioning technologies. In IEEE HOST."},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"crossref","unstructured":"Fan Yao Guru Venkataramani and Milo\u0161 Doroslova\u010dki. 2017. Covert timing channels exploiting non-uniform memory access based architectures. In ACM GLSVLSI.","DOI":"10.1145\/3060403.3060417"},{"key":"e_1_3_2_1_95_1","unstructured":"Yuval Yarom and Katrina Falkner. 2014. FLUSH+RELOAD: A High Resolution Low Noise L3 Cache Side-Channel Attack. In USENIX Security."},{"volume-title":"Graphics peeping unit: Exploiting em side-channel information of gpus to eavesdrop on your neighbors","author":"Zhan Zihao","key":"e_1_3_2_1_96_1","unstructured":"Zihao Zhan, Zhenkai Zhang, Sisheng Liang, Fan Yao, and Xenofon Koutsoukos. 2022. Graphics peeping unit: Exploiting em side-channel information of gpus to eavesdrop on your neighbors. In IEEE S&P."},{"key":"e_1_3_2_1_97_1","doi-asserted-by":"crossref","unstructured":"Zhenkai Zhang Sisheng Liang Fan Yao and Xing Gao. 2021. Red Alert for Power Leakage: Exploiting Intel RAPL-Induced Side Channels. In ACM CCS.","DOI":"10.1145\/3433210.3437517"}],"event":{"name":"ASIA CCS '24: 19th ACM Asia Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Singapore Singapore","acronym":"ASIA CCS '24"},"container-title":["Proceedings of the 19th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3661139","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T23:44:07Z","timestamp":1750290247000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3661139"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":97,"alternative-id":["10.1145\/3634737.3661139","10.1145\/3634737"],"URL":"https:\/\/doi.org\/10.1145\/3634737.3661139","relation":{},"subject":[],"published":{"date-parts":[[2024,7]]},"assertion":[{"value":"2024-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}