{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:44:52Z","timestamp":1780634692206,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":97,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,3,30]],"date-time":"2025-03-30T00:00:00Z","timestamp":1743292800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,3,30]]},"DOI":"10.1145\/3722041.3723099","type":"proceedings-article","created":{"date-parts":[[2025,4,2]],"date-time":"2025-04-02T07:16:25Z","timestamp":1743578185000},"page":"40-48","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["CUDA, Woulda, Shoulda: Returning Exploits in a SASS-y World"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-6510-4273","authenticated-orcid":false,"given":"Jonas","family":"Roels","sequence":"first","affiliation":[{"name":"DistriNet, KU Leuven, Ghent, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9958-0273","authenticated-orcid":false,"given":"Adriaan","family":"Jacobs","sequence":"additional","affiliation":[{"name":"DistriNet, KU Leuven, Ghent, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5594-7742","authenticated-orcid":false,"given":"Stijn","family":"Volckaert","sequence":"additional","affiliation":[{"name":"DistriNet, KU Leuven, Ghent, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,2]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Nvidia a100 tensor core gpu. https:\/\/www.nvidia.com\/en-us\/data-center\/a100\/","author":"NVIDIA Corporation","year":"2020","unstructured":"NVIDIA Corporation. Nvidia a100 tensor core gpu. https:\/\/www.nvidia.com\/en-us\/data-center\/a100\/, 2020."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/HCS59251.2023.10254716"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1553374.1553486"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/IPDPS.2008.4536351"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128571"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3038228.3038233"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-018-0039-0"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23194"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-45472-5_9"},{"key":"e_1_3_2_1_10_1","first-page":"115","volume-title":"Proceedings - Series of the Gesellschaft fur Informatik (GI)","author":"Bre\u00df S.","year":"2013","unstructured":"S. Bre\u00df, S. Kiltz, and Martin Sch\u00e4ler. Forensics on gpu coprocessing in databases -research challenges, first experiments, and countermeasures. Lecture Notes in Informatics (LNI), Proceedings - Series of the Gesellschaft fur Informatik (GI), pages 115--129, 01 2013."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2015.7140493"},{"key":"e_1_3_2_1_12_1","volume-title":"Cuda leaks: a detailed hack for cuda and a (partial) fix. ACM Transactions on Embedded Computing Systems (TECS), 15(1):1--25","author":"Pietro Roberto Di","year":"2016","unstructured":"Roberto Di Pietro, Flavio Lombardi, and Antonio Villani. Cuda leaks: a detailed hack for cuda and a (partial) fix. ACM Transactions on Embedded Computing Systems (TECS), 15(1):1--25, 2016."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC47756.2020.9045745"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2016.7446081"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243831"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 6th European Workshop on System Security (EuroSec). Citeseer","author":"Ladakis Evangelos","year":"2013","unstructured":"Evangelos Ladakis, Lazaros Koromilas, Giorgos Vasiliadis, Michalis Polychronakis, and Sotiris Ioannidis. You can type, but you can't hide: A stealthy gpu-based keylogger. In Proceedings of the 6th European Workshop on System Security (EuroSec). Citeseer, 2013."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP60621.2024.00026"},{"key":"e_1_3_2_1_18_1","volume-title":"Vulnerable gpu memory management: Towards recovering raw data from gpu","author":"Zhou Zhe","year":"2016","unstructured":"Zhe Zhou, Wenrui Diao, Xiangyu Liu, Zhou Li, Kehuan Zhang, and Rui Liu. Vulnerable gpu memory management: Towards recovering raw data from gpu, 2016. URL https:\/\/arxiv.org\/abs\/1605.06610."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00084"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.9"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00031"},{"key":"e_1_3_2_1_22_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Zhu Yuankun","year":"2021","unstructured":"Yuankun Zhu, Yueqiang Cheng, Husheng Zhou, and Yantao Lu. Hermes attack: Steal {DNN} models with lossless inference accuracy. In 30th USENIX Security Symposium (USENIX Security 21), 2021."},{"key":"e_1_3_2_1_23_1","volume-title":"Blog","author":"Sorenson Tyler","year":"2024","unstructured":"Tyler Sorenson and Heidy Khlaaf. LeftoverLocals: Listening to LLM responses through leaked GPU local memory. Blog, January 2024. URL https:\/\/blog.trailofbits.com\/2024\/01\/16\/leftoverlocals-listening-to-llm-responses-through-leaked-gpu-local-memory\/."},{"key":"e_1_3_2_1_24_1","volume-title":"Mohammed Ben-Idris, and Shamik Sengupta. Vulnerabilities of machine learning algorithms to adversarial attacks for cyberphysical power systems","author":"Das Tapadhir","year":"2024","unstructured":"Tapadhir Das, Raj Mani Shukla, Mohammed Ben-Idris, and Shamik Sengupta. Vulnerabilities of machine learning algorithms to adversarial attacks for cyberphysical power systems. In Ali Parizad, Hamid Reza Baghaee, and Saifur Rahman, editors, Smart Cyber-Physical Power Systems: Challenges and Solutions. Wiley-IEEE Press, 2024."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102115"},{"key":"e_1_3_2_1_26_1","volume-title":"Bitcoin fiasco. https:\/\/play.esea.net\/news\/12692","author":"Levine Craig","year":"2013","unstructured":"Craig \"Torbull\" Levine. Bitcoin fiasco. https:\/\/play.esea.net\/news\/12692, 2013."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/PIERE62470.2024.10804931"},{"key":"e_1_3_2_1_28_1","volume-title":"Lara Magdalena Lazier, and Lukas Cavigelli. Ascend-cc: Confidential computing on heterogeneous npu for emerging generative ai workloads. arXiv preprint arXiv:2407.11888","author":"Dhar Aritra","year":"2024","unstructured":"Aritra Dhar, Cl\u00e9ment Thorens, Lara Magdalena Lazier, and Lukas Cavigelli. Ascend-cc: Confidential computing on heterogeneous npu for emerging generative ai workloads. arXiv preprint arXiv:2407.11888, 2024."},{"key":"e_1_3_2_1_29_1","volume-title":"Nvidia multi-instance gpu. https:\/\/www.nvidia.com\/en-us\/technologies\/multi-instance-gpu\/","author":"NVIDIA Corporation","year":"2024","unstructured":"NVIDIA Corporation. Nvidia multi-instance gpu. https:\/\/www.nvidia.com\/en-us\/technologies\/multi-instance-gpu\/, 2024."},{"key":"e_1_3_2_1_30_1","volume-title":"Nvidia confidential computing. https:\/\/www.nvidia.com\/en-us\/data-center\/solutions\/confidential-computing\/","author":"NVIDIA Corporation","year":"2024","unstructured":"NVIDIA Corporation. Nvidia confidential computing. https:\/\/www.nvidia.com\/en-us\/data-center\/solutions\/confidential-computing\/, 2024."},{"key":"e_1_3_2_1_31_1","volume-title":"https:\/\/www.phoronix.com\/news\/AMD-Trusted-Memory-Zone","author":"Larabel Michael","year":"2019","unstructured":"Michael Larabel. Amd \"trusted memory zone\" encrypted vram support coming to their linux gpu driver. https:\/\/www.phoronix.com\/news\/AMD-Trusted-Memory-Zone, 2019."},{"key":"e_1_3_2_1_32_1","volume-title":"G-safe: Safe gpu sharing in multi-tenant environments. arXiv preprint arXiv:2401.09290","author":"Pavlidakis Manos","year":"2024","unstructured":"Manos Pavlidakis, Giorgos Vasiliadis, Stelios Mavridis, Anargyros Argyros, Antony Chazapis, and Angelos Bilas. G-safe: Safe gpu sharing in multi-tenant environments. arXiv preprint arXiv:2401.09290, 2024."},{"key":"e_1_3_2_1_33_1","volume-title":"Cuda c++ programming interface. https:\/\/docs.nvidia.com\/cuda\/cuda-c-programming-guide\/index.html#programming-interface","author":"NVIDIA Corporation","year":"2024","unstructured":"NVIDIA Corporation. Cuda c++ programming interface. https:\/\/docs.nvidia.com\/cuda\/cuda-c-programming-guide\/index.html#programming-interface, 2024."},{"key":"e_1_3_2_1_34_1","volume-title":"https:\/\/www.amd.com\/en\/products\/software\/rocm.html","author":"Advanced Micro Devices Inc. C++ language extenstions - hip documentation.","year":"2024","unstructured":"Advanced Micro Devices Inc. C++ language extenstions - hip documentation. https:\/\/www.amd.com\/en\/products\/software\/rocm.html, 2024."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_3_2_1_36_1","first-page":"103","volume-title":"NPC 2016, Xi'an, China, October 28-29, 2016, Proceedings 13","author":"Di Bang","year":"2016","unstructured":"Bang Di, Jianhua Sun, and Hao Chen. A study of overflow vulnerabilities on gpus. In Network and Parallel Computing: 13th IFIP WG 10.3 International Conference, NPC 2016, Xi'an, China, October 28-29, 2016, Proceedings 13, pages 103--115. Springer, 2016."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-015-0251-1"},{"key":"e_1_3_2_1_38_1","first-page":"4033","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Guo Yanan","year":"2024","unstructured":"Yanan Guo, Zhenkai Zhang, and Jun Yang. GPU memory exploitation for fun and profit. In 33rd USENIX Security Symposium (USENIX Security 24), pages 4033--4050, Philadelphia, PA, August 2024. USENIX Association. ISBN 978-1-939133-44-1. URL https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/guo-yanan."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.152"},{"key":"e_1_3_2_1_40_1","volume-title":"6th USENIX Workshop on Offensive Technologies (WOOT 12)","author":"Homescu Andrei","year":"2012","unstructured":"Andrei Homescu, Michael Stewart, Per Larsen, Stefan Brunthaler, and Michael Franz. Microgadgets: Size does matter in Turing-Complete Return-Oriented programming. In 6th USENIX Workshop on Offensive Technologies (WOOT 12), Bellevue, WA, August 2012. USENIX Association. URL https:\/\/www.usenix.org\/conference\/woot12\/workshop-program\/presentation\/Homescu."},{"key":"e_1_3_2_1_41_1","volume-title":"Return-oriented programming: Systems, languages, and applications. ACM Transactions on Information and System Security (TISSEC), 15(1):1--34","author":"Roemer Ryan","year":"2012","unstructured":"Ryan Roemer, Erik Buchanan, Hovav Shacham, and Stefan Savage. Return-oriented programming: Systems, languages, and applications. ACM Transactions on Information and System Security (TISSEC), 15(1):1--34, 2012."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966919"},{"key":"e_1_3_2_1_44_1","volume-title":"ROP chains on ARM64","author":"Deepak Ajin","year":"2023","unstructured":"Ajin Deepak. ROP chains on ARM64, 2023. URL https:\/\/infosecwriteups.com\/rop-chains-on-arm64-6ff10368798f."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455776"},{"key":"e_1_3_2_1_46_1","volume-title":"Dissecting the nvidia turing T4 GPU via microbenchmarking. CoRR, abs\/1903.07486","author":"Jia Zhe","year":"2019","unstructured":"Zhe Jia, Marco Maggioni, Jeffrey Smith, and Daniele Paolo Scarpazza. Dissecting the nvidia turing T4 GPU via microbenchmarking. CoRR, abs\/1903.07486, 2019. URL http:\/\/arxiv.org\/abs\/1903.07486."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2019.8661186"},{"key":"e_1_3_2_1_48_1","volume-title":"Address space layout randomization (aslr). https:\/\/pax.grsecurity.net\/docs\/aslr.txt","author":"Team X","year":"2001","unstructured":"PaX Team. Address space layout randomization (aslr). https:\/\/pax.grsecurity.net\/docs\/aslr.txt, 2001."},{"key":"e_1_3_2_1_49_1","volume-title":"NVIDIA CUDA Compiler Driver","author":"NVIDIA Corporation","year":"2024","unstructured":"NVIDIA Corporation. NVIDIA CUDA Compiler Driver, 2024. URL https:\/\/docs.nvidia.com\/cuda\/cuda-compiler-driver-nvcc\/."},{"key":"e_1_3_2_1_50_1","volume-title":"Data execution prevention. https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/memory\/data-execution-prevention","author":"Microsoft Corporation","year":"2003","unstructured":"Microsoft Corporation. Data execution prevention. https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/memory\/data-execution-prevention, 2003."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243176.3243194"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2020.3042965"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2019.00035"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3470496.3527420"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD56317.2022.00108"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589102"},{"key":"e_1_3_2_1_57_1","volume-title":"Compute Sanitizer --- compute-sanitizer 12.6 documentation","author":"NVIDIA Corporation","year":"2022","unstructured":"NVIDIA Corporation. Compute Sanitizer --- compute-sanitizer 12.6 documentation, 2022. URL https:\/\/docs.nvidia.com\/compute-sanitizer\/ComputeSanitizer\/index.html."},{"key":"e_1_3_2_1_58_1","unstructured":"NVIDIA Corporation. CUDA-MEMCHECK 2013. URL https:\/\/developer.nvidia.com\/cuda-memcheck."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2791321.2791333"},{"key":"e_1_3_2_1_60_1","first-page":"67","volume-title":"Tools for High Performance Computing","author":"Thomas","year":"2013","unstructured":"Thomas M. Baumann and Jos\u00e9 Gracia. Cudagrind: Memory-usage checking for cuda. In Andreas Kn\u00fcpfer, Jos\u00e9 Gracia, Wolfgang E. Nagel, and Michael M. Resch, editors, Tools for High Performance Computing 2013, pages 67--78, Cham, 2014. Springer International Publishing. ISBN 978-3-319-08144-1."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2017.7863729"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3591225"},{"key":"e_1_3_2_1_63_1","volume-title":"https:\/\/github.com\/KhronosGroup\/webcl-validator","author":"Khronos Group","year":"2014","unstructured":"Khronos Group. Webcl-validator. https:\/\/github.com\/KhronosGroup\/webcl-validator, 2014."},{"key":"e_1_3_2_1_64_1","volume-title":"Cuda binary utilities. https:\/\/docs.nvidia.com\/cuda\/cuda-binary- utilities\/index.html","author":"NVIDIA Corporation","year":"2024","unstructured":"NVIDIA Corporation. Cuda binary utilities. https:\/\/docs.nvidia.com\/cuda\/cuda-binary- utilities\/index.html, 2024."},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS '23","author":"Zhang Zhenkai","year":"2023","unstructured":"Zhenkai Zhang, Tyler Allen, Fan Yao, Xing Gao, and Rong Ge. TunneLs for Bootlegging: Fully Reverse-Engineering GPU TLBs for Challenging Isolation Guarantees of NVIDIA MIG. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS '23, 2023."},{"key":"e_1_3_2_1_66_1","volume-title":"Pascal mmu format changes. https:\/\/nvidia.github.io\/open-gpu-doc\/pascal\/gp100-mmu-format.pdf","author":"NVIDIA Corporation","year":"2016","unstructured":"NVIDIA Corporation. Pascal mmu format changes. https:\/\/nvidia.github.io\/open-gpu-doc\/pascal\/gp100-mmu-format.pdf, 2016."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-70896-1_7"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.62"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00018"},{"key":"e_1_3_2_1_70_1","volume-title":"Nvidia cublas. https:\/\/docs.nvidia.com\/cuda\/cublas\/index.html","author":"NVIDIA Corporation","year":"2024","unstructured":"NVIDIA Corporation. Nvidia cublas. https:\/\/docs.nvidia.com\/cuda\/cublas\/index.html, 2024."},{"key":"e_1_3_2_1_71_1","volume-title":"Nvidia cudnn. https:\/\/developer.nvidia.com\/cudnn","author":"NVIDIA Corporation","year":"2024","unstructured":"NVIDIA Corporation. Nvidia cudnn. https:\/\/developer.nvidia.com\/cudnn, 2024."},{"key":"e_1_3_2_1_72_1","first-page":"8024","volume-title":"Advances in Neural Information Processing Systems 32","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Kopf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala. Pytorch: An imperative style, high-performance deep learning library. In Advances in Neural Information Processing Systems 32, pages 8024--8035. Curran Associates, Inc., 2019. URL http:\/\/papers.neurips.cc\/paper\/9015-pytorch-an-imperative-style-high-performance-deep-learning-library.pdf."},{"key":"e_1_3_2_1_73_1","volume-title":"TensorFlow: Large-scale machine learning on heterogeneous systems","author":"Abadi Mart\u00edn","year":"2015","unstructured":"Mart\u00edn Abadi, Ashish Agarwal, Paul Barham, Eugene Brevdo, Zhifeng Chen, Craig Citro, Greg S. Corrado, Andy Davis, Jeffrey Dean, Matthieu Devin, Sanjay Ghemawat, Ian Goodfellow, Andrew Harp, Geoffrey Irving, Michael Isard, Yangqing Jia, Rafal Jozefowicz, Lukasz Kaiser, Manjunath Kudlur, Josh Levenberg, Dandelion Man\u00e9, Rajat Monga, Sherry Moore, Derek Murray, Chris Olah, Mike Schuster, Jonathon Shlens, Benoit Steiner, Ilya Sutskever, Kunal Talwar, Paul Tucker, Vincent Vanhoucke, Vijay Vasudevan, Fernanda Vi\u00e9gas, Oriol Vinyals, Pete Warden, Martin Wattenberg, Martin Wicke, Yuan Yu, and Xiaoqiang Zheng. TensorFlow: Large-scale machine learning on heterogeneous systems, 2015. URL https:\/\/www.tensorflow.org\/. Software available from tensorflow.org."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818023"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.22"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/RoEduNet60162.2023.10274918"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920269"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.25"},{"key":"e_1_3_2_1_79_1","volume-title":"Safellvm: Llvm without the rop gadgets!","author":"Cassano Federico","year":"2023","unstructured":"Federico Cassano, Charles Bershatsky, Jacob Ginesin, and Sasha Bashenko. Safellvm: Llvm without the rop gadgets!, 2023. URL https:\/\/arxiv.org\/abs\/2305.06092."},{"key":"e_1_3_2_1_80_1","volume-title":"October","author":"Devillard Nicolas","year":"2023","unstructured":"Nicolas Devillard. Better Security at the Flick of a (Compiler) Switch: Enabling Pointer Authentication and Branch Target Identification. https:\/\/newsroom.arm.com\/blog\/pac-bti, October 2023."},{"key":"e_1_3_2_1_81_1","volume-title":"https:\/\/clang.llvm.org\/docs\/SafeStack.html","author":"Developers LLVM","year":"2021","unstructured":"LLVM Developers. Safestack. https:\/\/clang.llvm.org\/docs\/SafeStack.html, 2021."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00076"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966920"},{"key":"e_1_3_2_1_84_1","first-page":"02","article-title":"Architecture support for defending against buffer overflow attacks. Coordinated Science Laboratory Report no","volume":"02","author":"Xu Jun","year":"2002","unstructured":"Jun Xu, Zbigniew Kalbarczyk, Sanjay Patel, and Ravishankar K Iyer. Architecture support for defending against buffer overflow attacks. Coordinated Science Laboratory Report no. UILU-ENG-02-2205, CRHC-02-05, 2002.","journal-title":"UILU-ENG-"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/2714576.2714635"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDSC.2001.918971"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.5555\/2685048.2685061"},{"key":"e_1_3_2_1_88_1","first-page":"357","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Liljestrand Hans","year":"2021","unstructured":"Hans Liljestrand, Thomas Nyman, Lachlan J. Gunn, Jan-Erik Ekberg, and N. Asokan. PACStack: an authenticated call stack. In 30th USENIX Security Symposium (USENIX Security 21), pages 357--374. USENIX Association, August 2021. ISBN 978-1-939133-24-3. URL https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/liljestrand."},{"key":"e_1_3_2_1_89_1","first-page":"177","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Liljestrand Hans","year":"2019","unstructured":"Hans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez, Jan-Erik Ekberg, and N. Asokan. PAC it up: Towards pointer integrity using ARM pointer authentication. In 28th USENIX Security Symposium (USENIX Security 19), pages 177--194, Santa Clara, CA, August 2019. USENIX Association. ISBN 978-1-939133-06-9. URL https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/liljestrand."},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.44"},{"key":"e_1_3_2_1_92_1","volume-title":"A technical look at intel's control-flow enforcement technology. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/technical-look-control-flow-enforcement-technology.html","author":"Intel Corporation","year":"2020","unstructured":"Intel Corporation. A technical look at intel's control-flow enforcement technology. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/technical-look-control-flow-enforcement-technology.html, 2020."},{"key":"e_1_3_2_1_93_1","volume-title":"https:\/\/community.arm.com\/arm-community-blogs\/b\/architectures-and-processors-blog\/posts\/armv8-1-m-pointer-authentication-and-branch-target-identification-extension","author":"Mujumdar Alan","year":"2021","unstructured":"Alan Mujumdar. Armv8.1-m pointer authentication and branch target identification extension. https:\/\/community.arm.com\/arm-community-blogs\/b\/architectures-and-processors-blog\/posts\/armv8-1-m-pointer-authentication-and-branch-target-identification-extension, 2021."},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1145\/3054924"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88418-5_11"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417234"},{"key":"e_1_3_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545997"}],"event":{"name":"EuroSys '25: Twentieth European Conference on Computer Systems","location":"Rotterdam Netherlands","acronym":"EuroSys '25","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 18th European Workshop on Systems Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3722041.3723099","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3722041.3723099","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T18:14:53Z","timestamp":1755972893000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3722041.3723099"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,30]]},"references-count":97,"alternative-id":["10.1145\/3722041.3723099","10.1145\/3722041"],"URL":"https:\/\/doi.org\/10.1145\/3722041.3723099","relation":{},"subject":[],"published":{"date-parts":[[2025,3,30]]},"assertion":[{"value":"2025-04-02","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}