{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:27:14Z","timestamp":1766442434634,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":125,"publisher":"ACM","funder":[{"name":"National Science Foundation (NSF)","award":["CNS-2207231, OAC-2419821"],"award-info":[{"award-number":["CNS-2207231, OAC-2419821"]}]},{"DOI":"10.13039\/100002418","name":"Intel Corporation","doi-asserted-by":"publisher","award":["Trustworthy Data Center of Future grant"],"award-info":[{"award-number":["Trustworthy Data Center of Future grant"]}],"id":[{"id":"10.13039\/100002418","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Advanced Micro Devices, Inc. (AMD)","award":["AMD University Program"],"award-info":[{"award-number":["AMD University Program"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765069","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:37:25Z","timestamp":1763854645000},"page":"2594-2608","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["BOLT: Bandwidth-Optimized Lightning-Fast Oblivious Map powered by Secure HBM Accelerators"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-8140-9177","authenticated-orcid":false,"given":"Yitong","family":"Guo","sequence":"first","affiliation":[{"name":"Indiana University, Bloomington, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9922-4351","authenticated-orcid":false,"given":"Hongbo","family":"Chen","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-6888-0721","authenticated-orcid":false,"given":"Haobin Hiroki","family":"Chen","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5852-4195","authenticated-orcid":false,"given":"Yukui","family":"Luo","sequence":"additional","affiliation":[{"name":"SUNY Binghamton, Binghamton, New York, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0607-4946","authenticated-orcid":false,"given":"XiaoFeng","family":"Wang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Sinagpore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7837-5791","authenticated-orcid":false,"given":"Chenghong","family":"Wang","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2023. Vitis Security Library. https:\/\/www.amd.com\/en\/products\/software\/a daptive-socs-and-fpgas\/vitis\/vitis-libraries\/vitis-security.html. Accessed: 2023-06--10."},{"key":"e_1_3_2_1_2_1","unstructured":"Advanced Micro Devices Inc. 2023. Alveo U55C Data Center Accelerator Card | AMD. https:\/\/www.amd.com\/en\/products\/accelerators\/alveo\/u55c\/a-u55cp00g- pq-g.html. Accessed: 2023-05--22."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3140659.3080232"},{"key":"e_1_3_2_1_4_1","unstructured":"Amazon Web Services. [n.d.]. Amazon Simple Storage Service (S3). https: \/\/aws.amazon.com\/s3\/. Accessed: 2025-07--10."},{"key":"e_1_3_2_1_5_1","unstructured":"Amazon Web Services. 2017. Amazon EC2 F1 Instances -- Customizable FPGAs for Hardware Acceleration Are Now Generally Available. https:\/\/aws.amazon .com\/about-aws\/whats-new\/2017\/04\/amazon-ec2-f1-instances-customizablefpgas- for-hardware-acceleration-are-now-generally-available\/ Accessed: 2025-03--16."},{"key":"e_1_3_2_1_6_1","unstructured":"Amazon Web Services. 2024. Amazon EC2 F2 Instances. https:\/\/aws.amazon.c om\/ec2\/instance-types\/f2\/ Accessed: 2025-03--16."},{"key":"e_1_3_2_1_7_1","unstructured":"AMD. [n.d.]. AMD Instinct MI325x Series Accelerators. https:\/\/www.amd.com\/en\/products\/accelerators\/instinct\/mi300\/mi325x.html"},{"key":"e_1_3_2_1_8_1","volume-title":"Accessed","author":"AMD.","year":"2023","unstructured":"AMD. 2023. UltraRAM Introduction. https:\/\/docs.amd.com\/r\/en-US\/am007-versal-memory\/UltraRAM-Introduction. Accessed: April 13, 2025."},{"key":"e_1_3_2_1_9_1","unstructured":"AMD. 2024. AMD Alveo V80 Data Center Accelerator Card. https:\/\/www.amd.com\/en\/products\/accelerators\/alveo\/v80.html. Accessed: 2025-03--25."},{"key":"e_1_3_2_1_10_1","volume-title":"AMD EPYC Embedded 9004 and 8004 Series Product Brief. https: \/\/www.amd.com\/content\/dam\/amd\/en\/documents\/products\/embedded\/epyc\/ epyc-embedded-9004-and-8004-series-product-brief.pdf Accessed","author":"AMD.","year":"2025","unstructured":"AMD. 2024. AMD EPYC Embedded 9004 and 8004 Series Product Brief. https: \/\/www.amd.com\/content\/dam\/amd\/en\/documents\/products\/embedded\/epyc\/ epyc-embedded-9004-and-8004-series-product-brief.pdf Accessed: March 4, 2025."},{"key":"e_1_3_2_1_11_1","unstructured":"AMD. 2024. Asymmetric Hardware Root of Trust (HWRoT) Authentication Required. https:\/\/docs.amd.com\/r\/en-US\/ug1304-versal-acap-ssdg\/Asymmetric- Hardware-Root-of-Trust-A-HWRoT-Authentication-Required Accessed: 2024-06--22."},{"key":"e_1_3_2_1_12_1","volume-title":"Byotee: Towards building your own trusted execution environments using fpga. arXiv preprint arXiv:2203.04214","author":"Armanuzzaman Md","year":"2022","unstructured":"Md Armanuzzaman and Ziming Zhao. 2022. Byotee: Towards building your own trusted execution environments using fpga. arXiv preprint arXiv:2203.04214 (2022)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.5555\/1540612"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-45724-2_14"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623125"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080230"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MOCAST.2016.7495160"},{"key":"e_1_3_2_1_18_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Batina Lejla","year":"2019","unstructured":"Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. CSI NN: Reverse engineering of neural network architectures through electromagnetic side channel. In 28th USENIX Security Symposium (USENIX Security 19). 515--532."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813649"},{"key":"e_1_3_2_1_20_1","volume-title":"Revisiting leakage abuse attacks. Cryptology ePrint Archive","author":"Blackstone Laura","year":"2019","unstructured":"Laura Blackstone, Seny Kamara, and Tarik Moataz. 2019. Revisiting leakage abuse attacks. Cryptology ePrint Archive (2019)."},{"key":"e_1_3_2_1_21_1","volume-title":"5th USENIX Workshop on Hot Topics in Cloud Computing (HotCloud 13)","author":"Blott Michaela","year":"2013","unstructured":"Michaela Blott, Kimon Karras, Ling Liu, Kees Vissers, Jeremia B\u00e4r, and Zsolt Istv\u00e1n. 2013. Achieving 10gbps line-rate key-value stores with {FPGAs}. In 5th USENIX Workshop on Hot Topics in Cloud Computing (HotCloud 13)."},{"volume-title":"Summer school on machine learning","author":"Boucheron St\u00e9phane","key":"e_1_3_2_1_22_1","unstructured":"St\u00e9phane Boucheron, G\u00e1bor Lugosi, and Olivier Bousquet. 2003. Concentration inequalities. In Summer school on machine learning. Springer, 208--240."},{"key":"e_1_3_2_1_23_1","volume-title":"Towards Practical Oblivious Map. Cryptology ePrint Archive","author":"Cao Xinle","year":"2024","unstructured":"Xinle Cao,Weiqi Feng, Jian Liu, Jinjin Zhou, Wenjing Fang, LeiWang, Quanqing Xu, Chuanhui Yang, and Kui Ren. 2024. Towards Practical Oblivious Map. Cryptology ePrint Archive (2024)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813700"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.14778\/3625054.3625067"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA47549.2020.00038"},{"key":"e_1_3_2_1_27_1","volume-title":"ShieldCXL: A Practical Obliviousness Support with Sealed CXL Memory. ACM Transactions on Architecture and Code Optimization","author":"Choi Kwanghoon","year":"2024","unstructured":"Kwanghoon Choi, Igjae Kim, Sunho Lee, and Jaehyuk Huh. 2024. ShieldCXL: A Practical Obliviousness Support with Sealed CXL Memory. ACM Transactions on Architecture and Code Optimization (2024)."},{"volume-title":"Cryptographers' Track at the RSA Conference","author":"Chuengsatiansup Chitchanok","key":"e_1_3_2_1_28_1","unstructured":"Chitchanok Chuengsatiansup, Daniel Genkin, Yuval Yarom, and Zhiyuan Zhang. 2022. Side-channeling the Kalyna key expansion. In Cryptographers' Track at the RSA Conference. Springer, 272--296."},{"key":"e_1_3_2_1_29_1","volume-title":"Programming Tricks: Reducing Key Size. https:\/\/github.com\/memcached\/memcached\/wiki\/ProgrammingTricks#reducingkey- size. Accessed: 2025-03--23.","author":"Contributors Memcached","year":"2025","unstructured":"Memcached Contributors. 2025. Programming Tricks: Reducing Key Size. https:\/\/github.com\/memcached\/memcached\/wiki\/ProgrammingTricks#reducingkey- size. Accessed: 2025-03--23."},{"key":"e_1_3_2_1_30_1","unstructured":"OpenDSA Project Contributors. 2023. Heap Memory. https:\/\/opendsa-server.cs. vt.edu\/ODSA\/Books\/CS2\/html\/HeapMem.html. Accessed: 2025-04-07."},{"key":"e_1_3_2_1_31_1","volume-title":"Cooper et al","author":"Brian","year":"2010","unstructured":"Brian F. Cooper et al. 2010. Yahoo! Cloud Serving Benchmark (YCSB). https:\/\/github.com\/brianfrankcooper\/YCSB. Accessed: 2025-03--21."},{"key":"e_1_3_2_1_32_1","volume-title":"Intel Xeon Max Series Processors. https:\/\/www.intel. com\/content\/www\/us\/en\/products\/details\/processors\/xeon\/max-series.html Accessed","author":"Intel Corporation","year":"2025","unstructured":"Intel Corporation. 2024. Intel Xeon Max Series Processors. https:\/\/www.intel. com\/content\/www\/us\/en\/products\/details\/processors\/xeon\/max-series.html Accessed: March 16, 2025."},{"key":"e_1_3_2_1_33_1","volume-title":"Intel SGX explained. Cryptology ePrint Archive","author":"Costan Victor","year":"2016","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive (2016)."},{"key":"e_1_3_2_1_34_1","volume-title":"Thomas Eisenbarth, Daniel Genkin, Nadia Heninger, Ahmad Moghimi, and Yuval Yarom.","author":"Dall Fergus","year":"2018","unstructured":"Fergus Dall, Gabrielle De Micheli, Thomas Eisenbarth, Daniel Genkin, Nadia Heninger, Ahmad Moghimi, and Yuval Yarom. 2018. Cachequote: Efficiently recovering long-term secrets of SGX EPID via cache attacks. (2018)."},{"key":"e_1_3_2_1_35_1","volume-title":"Lara Magdalena Lazier, and Lukas Cavigelli","author":"Dhar Aritra","year":"2024","unstructured":"Aritra Dhar, Cl\u00e9ment Thorens, Lara Magdalena Lazier, and Lukas Cavigelli. 2024. Ascend-CC: Confidential Computing on Heterogeneous NPU for Emerging Generative AI Workloads. arXiv preprint arXiv:2407.11888 (2024)."},{"key":"e_1_3_2_1_36_1","volume-title":"International Conference on Security and Cryptography for Networks. Springer, 253--274","author":"Dittmer Sam","year":"2020","unstructured":"Sam Dittmer and Rafail Ostrovsky. 2020. Oblivious tight compaction inO(n) time with smaller constant. In International Conference on Security and Cryptography for Networks. Springer, 253--274."},{"key":"e_1_3_2_1_37_1","volume-title":"SE-PIM: In-Memory Acceleration of Data-Intensive Confidential Computing","author":"Duy Kha Dinh","year":"2022","unstructured":"Kha Dinh Duy and Hojoon Lee. 2022. SE-PIM: In-Memory Acceleration of Data-Intensive Confidential Computing. IEEE Transactions on Cloud Computing (2022)."},{"key":"e_1_3_2_1_38_1","volume-title":"A brief introduction to redis. arXiv preprint arXiv:2203.06559","author":"Eddelbuettel Dirk","year":"2022","unstructured":"Dirk Eddelbuettel. 2022. A brief introduction to redis. arXiv preprint arXiv:2203.06559 (2022)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.14778\/3364324.3364331"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3296957.3173204"},{"key":"e_1_3_2_1_41_1","unstructured":"Facebook. 2023. Facebook ORAM Repository. https:\/\/github.com\/facebook\/or am. Accessed: 2025-03--21."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616606"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM.2015.58"},{"key":"e_1_3_2_1_44_1","unstructured":"GeeksforGeeks. 2024. How to Store Data on Ethereum Blockchain? https: \/\/www.geeksforgeeks.org\/how-to-store-data-on-ethereum-blockchain\/ Accessed: 2025-03--24."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00070"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534972"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/28395.28416"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/233551.233553"},{"key":"e_1_3_2_1_49_1","volume-title":"Side-Channel- Assisted Reverse-Engineering of Encrypted DNN Hardware Accelerator IP and Attack Surface Exploration. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 1--1.","author":"Gongye Cheng","year":"2023","unstructured":"Cheng Gongye, Yukui Luo, Xiaolin Xu, and Yunsi Fei. 2023. Side-Channel- Assisted Reverse-Engineering of Encrypted DNN Hardware Accelerator IP and Attack Surface Exploration. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 1--1."},{"key":"e_1_3_2_1_50_1","volume-title":"Tlbleed: When protecting your cpu caches is not enough. Black Hat","author":"Gras Ben","year":"2018","unstructured":"Ben Gras, KAVEH Razavi, Herbert Bos, and Cristiano Giuffrida. 2018. Tlbleed: When protecting your cpu caches is not enough. Black Hat (2018)."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338508.3359568"},{"key":"e_1_3_2_1_52_1","volume-title":"AES-GCM-SIV: specification and analysis. Cryptology ePrint Archive","author":"Gueron Shay","year":"2017","unstructured":"Shay Gueron, Adam Langley, and Yehuda Lindell. 2017. AES-GCM-SIV: specification and analysis. Cryptology ePrint Archive (2017)."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2934872.2934908"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2509.01742"},{"key":"e_1_3_2_1_55_1","volume-title":"Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, 338--369","author":"Falk Brett Hemenway","year":"2021","unstructured":"Brett Hemenway Falk, Daniel Noble, and Rafail Ostrovsky. 2021. Alibi: A flaw in cuckoo-hashing based hierarchical ORAM schemes and a solution. In Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, 338--369."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-0865-5_26"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378460"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/MWSCAS.2010.5548664"},{"key":"e_1_3_2_1_59_1","volume-title":"17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20)","author":"Hunt Tyler","year":"2020","unstructured":"Tyler Hunt, Zhipeng Jia, Vance Miller, Ariel Szekely, Yige Hu, Christopher J Rossbach, and Emmett Witchel. 2020. Telekine: Secure computing with cloud {GPUs}. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20). 817--833."},{"key":"e_1_3_2_1_60_1","volume-title":"Bluethunder: A 2-level directional predictor based sidechannel attack against sgx. IACR Transactions on Cryptographic Hardware and Embedded Systems","author":"Huo Tianlin","year":"2020","unstructured":"Tianlin Huo, Xiaoni Meng, Wenhao Wang, Chunliang Hao, Pei Zhao, Jian Zhai, and Mingshu Li. 2020. Bluethunder: A 2-level directional predictor based sidechannel attack against sgx. IACR Transactions on Cryptographic Hardware and Embedded Systems (2020), 321--347."},{"key":"e_1_3_2_1_61_1","unstructured":"Apple Inc. 2025. NSUbiquitousKeyValueStore Documentation. https:\/\/develope r.apple.com\/documentation\/foundation\/nsubiquitouskeyvaluestore. Accessed: 2025-03--23."},{"key":"e_1_3_2_1_62_1","volume-title":"2023 USENIX Annual Technical Conference (USENIX ATC. 485--499","author":"Ivanov Andrei","year":"2023","unstructured":"Andrei Ivanov, Benjamin Rothenberger, Arnaud Dethise, Marco Canini, Torsten Hoefler, and Adrian Perrig. 2023. {SAGE}: Software-based Attestation for {GPU} Execution. In 2023 USENIX Annual Technical Conference (USENIX ATC. 485--499."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304021"},{"key":"e_1_3_2_1_64_1","volume-title":"CompassDB: Pioneering High- Performance Key-Value Store with Perfect Hash. arXiv preprint arXiv:2406.18099","author":"Jiang Jin","year":"2024","unstructured":"Jin Jiang, Dongsheng He, Yu Hu, Dong Liu, Chenfan Xiao, Hongxiao Bi, Yusong Zhang, Chaoqu Jiang, and Zhijun Fu. 2024. CompassDB: Pioneering High- Performance Key-Value Store with Perfect Hash. arXiv preprint arXiv:2406.18099 (2024)."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978386"},{"key":"e_1_3_2_1_66_1","volume-title":"Spectre Attacks: Exploiting Speculative Execution. In 40th IEEE Symposium on Security and Privacy (S&P'19)","author":"Kocher Paul","year":"2019","unstructured":"Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre Attacks: Exploiting Speculative Execution. In 40th IEEE Symposium on Security and Privacy (S&P'19)."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560593"},{"key":"e_1_3_2_1_68_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Lee Dayeol","year":"2020","unstructured":"Dayeol Lee, Dongha Jung, Ian T Fang, Chia-Che Tsai, and Raluca Ada Popa. 2020. An {Off-Chip} attack on hardware enclaves via the memory bus. In 29th USENIX Security Symposium (USENIX Security 20)."},{"key":"e_1_3_2_1_69_1","unstructured":"Dong Uk Lee. 2022. HBM DRAM and 3D Stacked Memory Slides. https:\/\/resourcecenter.sscs.ieee.org\/education\/short-courses\/sscstut20210215 Accessed: 2025-04-07."},{"key":"e_1_3_2_1_70_1","volume-title":"26th USENIX Security Symposium (USENIX Security. 557--574","author":"Lee Sangho","year":"2017","unstructured":"Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring fine-grained control flowinside {SGX} enclaves with branch shadowing. In 26th USENIX Security Symposium (USENIX Security. 557--574."},{"key":"e_1_3_2_1_71_1","volume-title":"Drift analysis. Theory of evolutionary computation: Recent developments in discrete optimization","author":"Lengler Johannes","year":"2020","unstructured":"Johannes Lengler. 2020. Drift analysis. Theory of evolutionary computation: Recent developments in discrete optimization (2020), 89--131."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3491219"},{"key":"e_1_3_2_1_73_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In 27th USENIX Security Symposium (USENIX Security 18)."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2775054.2694385"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/EIECS53707.2021.9588047"},{"key":"e_1_3_2_1_77_1","volume-title":"Stealthy-Shutdown: Practical Remote Power Attacks in Multi-Tenant FPGAs. In 2020 IEEE 38th International Conference on Computer Design (ICCD). IEEE, 545--552","author":"Luo Yukui","year":"2020","unstructured":"Yukui Luo, Cheng Gongye, Shaolei Ren, Yunsi Fei, and Xiaolin Xu. 2020. Stealthy-Shutdown: Practical Remote Power Attacks in Multi-Tenant FPGAs. In 2020 IEEE 38th International Conference on Computer Design (ICCD). IEEE, 545--552."},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516692"},{"key":"e_1_3_2_1_79_1","volume-title":"17th USENIX Symposium on Operating Systems Design and Implementation (OSDI 23)","author":"Mai Haohui","year":"2023","unstructured":"Haohui Mai, Jiacheng Zhao, Hongren Zheng, Yiyang Zhao, Zibin Liu, Mingyu Gao, Cong Wang, Huimin Cui, Xiaobing Feng, and Christos Kozyrakis. 2023. Honeycomb: Secure and Efficient {GPU} Executions via Static Validation. In 17th USENIX Symposium on Operating Systems Design and Implementation (OSDI 23). 155--172."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30215-3_2"},{"key":"e_1_3_2_1_81_1","volume-title":"Accessed","author":"Developers Memcached","year":"2025","unstructured":"Memcached Developers. 2025. Memcached: High-Performance Distributed Memory Object Caching System. https:\/\/memcached.org\/. Accessed: March 13, 2025."},{"key":"e_1_3_2_1_82_1","volume-title":"Proceedings of the Nineteenth ACM Symp. on Theory of Computing, STOC. ACM New York, NY, USA, 218--229","author":"Micali Silvio","year":"1987","unstructured":"Silvio Micali, Oded Goldreich, and Avi Wigderson. 1987. How to play any mental game. In Proceedings of the Nineteenth ACM Symp. on Theory of Computing, STOC. ACM New York, NY, USA, 218--229."},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00045"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00045"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/71.963420"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-47854-7_9"},{"key":"e_1_3_2_1_87_1","volume-title":"Automation & Test in Europe Conference & Exhibition (DATE). IEEE, 1639--1644","author":"Moini Shayan","year":"2021","unstructured":"Shayan Moini, Shanquan Tian, Daniel Holcomb, Jakub Szefer, and Russell Tessier. 2021. Remote power side-channel attacks on BNN accelerators in FPGAs. In 2021 Design, Automation & Test in Europe Conference & Exhibition (DATE). IEEE, 1639--1644."},{"key":"e_1_3_2_1_88_1","unstructured":"NVIDIA. 2023. High Confidential Computing: Unlocking the Potential of Confidential Computing with NVIDIA H100. https:\/\/images.nvidia.com\/aemdam\/ en-zz\/Solutions\/data-center\/HCC-Whitepaper-v1.0.pdf"},{"key":"e_1_3_2_1_89_1","unstructured":"NVIDIA Corporation. [n.d.]. GPU Direct. https:\/\/developer.nvidia.com\/gpudirect."},{"key":"e_1_3_2_1_90_1","unstructured":"NVIDIA Developer Blog. 2023. Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI. https:\/\/developer.nvidia.com\/blog\/confidentialcomputing-on-h100-gpus-for-secure-and-trustworthy-ai\/."},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417265"},{"key":"e_1_3_2_1_92_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Oya Simon","year":"2021","unstructured":"Simon Oya and Florian Kerschbaum. 2021. Hiding the access pattern is not enough: Exploiting search pattern leakage in searchable encryption. In 30th USENIX Security Symposium (USENIX Security 21). 127--142."},{"key":"e_1_3_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2018.00087"},{"volume-title":"25th USENIX security symposium (USENIX security 16). 565--581.","author":"Pessl Peter","key":"e_1_3_2_1_94_1","unstructured":"Peter Pessl, Daniel Gruss, Cl\u00e9mentine Maurice, Michael Schwarz, and Stefan Mangard. 2016. {DRAMA}: Exploiting {DRAM} addressing for {Cross-CPU} attacks. In 25th USENIX security symposium (USENIX security 16). 565--581."},{"key":"e_1_3_2_1_95_1","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Ren Ling","year":"2015","unstructured":"Ling Ren, Christopher Fletcher, Albert Kwon, Emil Stefanov, Elaine Shi, Marten Van Dijk, and Srinivas Devadas. 2015. Constants count: Practical improvements to oblivious {RAM}. In 24th USENIX Security Symposium (USENIX Security 15). 415--430."},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.19"},{"key":"e_1_3_2_1_97_1","volume-title":"ZeroTrace: Oblivious memory primitives from Intel SGX. Cryptology ePrint Archive","author":"Sasy Sajin","year":"2017","unstructured":"Sajin Sasy, Sergey Gorbunov, and Christopher W Fletcher. 2017. ZeroTrace: Oblivious memory primitives from Intel SGX. Cryptology ePrint Archive (2017)."},{"key":"e_1_3_2_1_98_1","first-page":"1450","article-title":"Strengthening VM isolation with integrity protection and more","volume":"53","author":"Sev-Snp AMD","year":"2020","unstructured":"AMD Sev-Snp. 2020. Strengthening VM isolation with integrity protection and more. White Paper, January 53 (2020), 1450--1465.","journal-title":"White Paper"},{"key":"e_1_3_2_1_99_1","unstructured":"Ramesh Sitaraman. 2001. The power of two random choices: A survey of techniques and results. (2001)."},{"key":"e_1_3_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1145\/3177872"},{"key":"e_1_3_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1145\/3177872"},{"key":"e_1_3_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1145\/3177872"},{"key":"e_1_3_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.25"},{"key":"e_1_3_2_1_104_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Tatar Andrei","year":"2022","unstructured":"Andrei Tatar, Dani\u00ebl Trujillo, Cristiano Giuffrida, and Herbert Bos. 2022. {TLB; DR}: Enhancing {TLB-based} attacks with {TLB} desynchronized reverse engineering. In 31st USENIX Security Symposium (USENIX Security 22). 989--1007."},{"key":"e_1_3_2_1_105_1","unstructured":"Apify Technologies. 2025. Key-Value Store Documentation. https:\/\/docs.apify.com\/platform\/storage\/key-value-store. Accessed: 2025-03--23."},{"key":"e_1_3_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1145\/3289602.3293920"},{"key":"e_1_3_2_1_107_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Tinoco Afonso","year":"2023","unstructured":"Afonso Tinoco, Sixiang Gao, and Elaine Shi. 2023. {EnigMap}:{External-Memory} Oblivious Map for Secure Enclaves. In 32nd USENIX Security Symposium (USENIX Security 23). 4033--4050."},{"key":"e_1_3_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660316"},{"key":"e_1_3_2_1_109_1","volume-title":"Ken Gordon, Balaji Vembu, Sam Webster, David Chisnall, Saurabh Kulkarni, Graham Cunningham, Richard Osborne, and Dan Wilkinson.","author":"Vaswani Kapil","year":"2022","unstructured":"Kapil Vaswani, Stavros Volos, C\u00e9dric Fournet, Antonio Nino Diaz, Ken Gordon, Balaji Vembu, Sam Webster, David Chisnall, Saurabh Kulkarni, Graham Cunningham, Richard Osborne, and Dan Wilkinson. 2022. Confidential machine learning within graphcore ipus. arXiv preprint arXiv:2205.09005 (2022)."},{"key":"e_1_3_2_1_110_1","volume-title":"13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18)","author":"Volos Stavros","year":"2018","unstructured":"Stavros Volos, Kapil Vaswani, and Rodrigo Bruno. 2018. Graviton: Trusted execution environments on {GPUs}. In 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18). 681--696."},{"key":"e_1_3_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660314"},{"key":"e_1_3_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2024.3355772"},{"key":"e_1_3_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1016\/0021-9045(74)90012-4"},{"key":"e_1_3_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSII.2020.2973007"},{"volume-title":"Host Memory Access (HM). Xilinx. https:\/\/xilinx.github.io\/XRT\/master\/html\/hm.html Accessed","year":"2025","key":"e_1_3_2_1_115_1","unstructured":"Xilinx. 2024. Host Memory Access (HM). Xilinx. https:\/\/xilinx.github.io\/XRT\/master\/html\/hm.html Accessed: March 2025."},{"volume-title":"XRT Host Memory (HM) Documentation. https:\/\/xilinx.github.io\/XRT\/master\/html\/hm.html Accessed","year":"2025","key":"e_1_3_2_1_116_1","unstructured":"Xilinx. 2025. XRT Host Memory (HM) Documentation. https:\/\/xilinx.github.io\/XRT\/master\/html\/hm.html Accessed: March 11, 2025."},{"key":"e_1_3_2_1_117_1","volume-title":"Hermetic: Privacy-preserving distributed analytics without (most) side channels. External Links: Link Cited by","author":"Xu Min","year":"2019","unstructured":"Min Xu, Antonis Papadimitriou, Andreas Haeberlen, and Ariel Feldman. 2019. Hermetic: Privacy-preserving distributed analytics without (most) side channels. External Links: Link Cited by (2019)."},{"key":"e_1_3_2_1_118_1","volume-title":"27th annual symposium on foundations of computer science (Sfcs","author":"Chi-Chih Yao Andrew","year":"1986","unstructured":"Andrew Chi-Chih Yao. 1986. How to generate and exchange secrets. In 27th annual symposium on foundations of computer science (Sfcs 1986). IEEE, 162--167."},{"volume-title":"23rd USENIX security symposium (USENIX security 14). 719--732.","author":"Yarom Yuval","key":"e_1_3_2_1_119_1","unstructured":"Yuval Yarom and Katrina Falkner. 2014. {FLUSH RELOAD}: A high resolution, low noise, l3 cache {Side-Channel} attack. In 23rd USENIX security symposium (USENIX security 14). 719--732."},{"key":"e_1_3_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA61900.2025.00038"},{"key":"e_1_3_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1587\/transfun.2020CIP0024"},{"key":"e_1_3_2_1_122_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503222.3507733"},{"key":"e_1_3_2_1_123_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00049"},{"key":"e_1_3_2_1_124_1","volume-title":"A High-Performance Hierarchical Doubly Oblivious RAM. arXiv preprint arXiv:2409.07167","author":"Zheng Leqian","year":"2024","unstructured":"Leqian Zheng, Zheng Zhang, Wentao Dong, Yao Zhang, Ye Wu, and Cong Wang. 2024. H _2 O _2 RAM: A High-Performance Hierarchical Doubly Oblivious RAM. arXiv preprint arXiv:2409.07167 (2024)."},{"key":"e_1_3_2_1_125_1","volume-title":"Sealing neural network models in secure deep learning accelerators. arXiv preprint arXiv:2008.03752","author":"Zuo Pengfei","year":"2020","unstructured":"Pengfei Zuo, Yu Hua, Ling Liang, Xinfeng Xie, Xing Hu, and Yuan Xie. 2020. Sealing neural network models in secure deep learning accelerators. arXiv preprint arXiv:2008.03752 (2020)."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Taipei Taiwan","acronym":"CCS '25"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765069","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:23:57Z","timestamp":1766442237000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765069"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":125,"alternative-id":["10.1145\/3719027.3765069","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765069","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}