{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T15:04:29Z","timestamp":1784214269491,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":253,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["No.62472374"],"award-info":[{"award-number":["No.62472374"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,18]]},"DOI":"10.1145\/3725843.3756029","type":"proceedings-article","created":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T17:19:56Z","timestamp":1760721596000},"page":"1412-1432","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2718-0297","authenticated-orcid":false,"given":"F. Nisa","family":"Bostanc\u0131","sequence":"first","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6166-0781","authenticated-orcid":false,"given":"O\u011fuzhan","family":"Canpolat","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5333-5726","authenticated-orcid":false,"given":"Ataberk","family":"Olgun","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3310-4423","authenticated-orcid":false,"given":"Ismail Emir","family":"Y\u00fcksel","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2375-7490","authenticated-orcid":false,"given":"Konstantinos","family":"Kanellopoulos","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4029-0175","authenticated-orcid":false,"given":"Mohammad","family":"Sadrosadati","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9333-6077","authenticated-orcid":false,"given":"Abdullah Giray","family":"Ya\u011fl\u0131k\u00e7\u0131","sequence":"additional","affiliation":[{"name":"ETH Zurich and CISPA, Saarbr\u00fccken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0075-2312","authenticated-orcid":false,"given":"Onur","family":"Mutlu","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,10,17]]},"reference":[{"key":"e_1_3_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2017.7951730"},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/INTMAG.2018.8508549"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00085"},{"key":"e_1_3_3_2_5_2","unstructured":"Apple Inc.[n. d.]. About the Security Content of Mac EFI Security Update 2015-001. https:\/\/support.apple.com\/en-us\/HT204934. June 2015."},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/2872362.2872390"},{"key":"e_1_3_3_2_7_2","unstructured":"K.S. Bains et\u00a0al. 2014. Method Apparatus and System for Providing a Memory Refresh. U.S. Patent 13\/625 741."},{"key":"e_1_3_3_2_8_2","unstructured":"K.S. Bains et\u00a0al. 2014. Row Hammer Refresh Command. U.S. Patent 13\/539 415."},{"key":"e_1_3_3_2_9_2","unstructured":"K. Bains et\u00a0al. 2014. Row Hammer Refresh Command. U.S. Patent 14\/068 677."},{"key":"e_1_3_3_2_10_2","unstructured":"K.S. Bains and J.B. Halbert. 2014. Distributed Row Hammer Tracking. U.S. Patent 13\/631 781."},{"key":"e_1_3_3_2_11_2","unstructured":"Kuljit Bains John Halbert Christopher Mozak Theodore Schoenborn and Zvika Greenfield. 2015. Row Hammer Refresh Command. U.S. Patent 9 117 544."},{"key":"e_1_3_3_2_12_2","unstructured":"Kuljit\u00a0S Bains and John\u00a0B Halbert. 2016. Distributed Row Hammer Tracking. U.S. Patent 9 299 400."},{"key":"e_1_3_3_2_13_2","unstructured":"Kuljit\u00a0S Bains and John\u00a0B Halbert. 2016. Row Hammer Monitoring Based on Stored Row Hammer Threshold Value. U.S. Patent 9 384 821."},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/IVSW.2018.8494868"},{"key":"e_1_3_3_2_15_2","volume-title":"Workshop on DRAM Security (DRAMSec)","author":"Bennett Tanj","year":"2021","unstructured":"Tanj Bennett, Stefan Saroiu, Alec Wolman, and Lucian Cojocar. 2021. Panopticon: A Complete In-DRAM Rowhammer Mitigation. In Workshop on DRAM Security (DRAMSec)."},{"key":"e_1_3_3_2_16_2","unstructured":"Tal Be\u2019ery and Amichai Shulman. 2013. A Perfect Crime? Only TIME Will Tell. Black Hat Europe (2013)."},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53140-2_29"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"crossref","unstructured":"Sarani Bhattacharya and Debdeep Mukhopadhyay. 2018. Advanced Fault Attacks in Software: Exploiting the Rowhammer Bug. Fault Tolerant Architectures for Cryptography and Hardware Security (2018).","DOI":"10.1007\/978-981-10-1387-4_6"},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","unstructured":"Nathan Binkert Bradford Beckmann Gabriel Black Steven\u00a0K. Reinhardt Ali Saidi Arkaprava Basu Joel Hestness Derek\u00a0R. Hower Tushar Krishna Somayeh Sardashti Rathijit Sen Korey Sewell Muhammad Shoaib Nilay Vaish Mark\u00a0D. Hill and David\u00a0A. Wood. 2011. The gem5 simulator. SIGARCH Comput. Archit. News (2011). 10.1145\/2024716.2024718","DOI":"10.1145\/2024716.2024718"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329827"},{"key":"e_1_3_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.63"},{"key":"e_1_3_3_2_22_2","doi-asserted-by":"crossref","unstructured":"F.\u00a0Nisa Bostanc\u0131 O\u011fuzhan Canpolat Ataberk Olgun \u0130smail\u00a0Emir Y\u00fcksel Konstantinos Kanellopoulos Mohammad Sadrosadati A\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131 and Onur Mutlu. 2025. Understanding and Mitigating Side and Covert Channel Vulnerabilities Introduced by RowHammer Defenses. arXiv preprint (2025).","DOI":"10.1145\/3725843.3756029"},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN64029.2025.00018"},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA57654.2024.00050"},{"key":"e_1_3_3_2_25_2","volume-title":"USENIX Security","author":"Brasser Ferdinand","year":"2017","unstructured":"Ferdinand Brasser, Lucas Davi, David Gens, Christopher Liebchen, and Ahmad-Reza Sadeghi. 2017. Can\u2019t Touch This: Software-Only Mitigation Against Rowhammer Attacks Targeting Kernel Memory. In USENIX Security."},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"crossref","unstructured":"Leo Breiman. 2001. Random Forests. Machine learning (2001).","DOI":"10.1023\/A:1010933404324"},{"key":"e_1_3_3_2_27_2","volume-title":"Classification and Regression Trees","author":"Breiman Leo","year":"1984","unstructured":"Leo Breiman, Jerome Friedman, Richard\u00a0A Olshen, and Charles\u00a0J Stone. 1984. Classification and Regression Trees. Chapman and Hall\/CRC."},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/2897937.2905022"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO61859.2024.00072"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA61900.2025.00071"},{"key":"e_1_3_3_2_31_2","unstructured":"O\u011fuzhan Canpolat A\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131 Geraldo\u00a0F Oliveira Ataberk Olgun O\u011fuz Ergin and Onur Mutlu. 2024. Understanding the Security Benefits and Overheads of Emerging Industry Solutions to DRAM Read Disturbance. DRAMSec (2024)."},{"key":"e_1_3_3_2_32_2","volume-title":"DSD","author":"Carre Sebastien","year":"2018","unstructured":"Sebastien Carre, Matthieu Desjardins, Adrien Facon, and Sylvain Guilley. 2018. OpenSSL Bellcore\u2019s Protection Helps Fault Attack. In DSD."},{"key":"e_1_3_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/2896377.2901453"},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2014.6835946"},{"key":"e_1_3_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3078505.3078590"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3676641.3716017"},{"key":"e_1_3_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.3115\/1072064.1072067"},{"key":"e_1_3_3_2_38_2","volume-title":"CCS","author":"Cohen Yaakov","year":"2022","unstructured":"Yaakov Cohen, Kevin\u00a0Sam Tharayil, Arie Haenel, Daniel Genkin, Angelos\u00a0D Keromytis, Yossi Oren, and Yuval Yarom. 2022. HammerScope: Observing DRAM Power Consumption Using Rowhammer. In CCS."},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00085"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00089"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"crossref","unstructured":"Corinna Cortes and Vladimir Vapnik. 1995. Support-Vector Networks. Machine Learning (1995).","DOI":"10.1023\/A:1022627411411"},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"crossref","unstructured":"Thomas Cover and Peter Hart. 1967. Nearest neighbor Pattern Classification. IEEE Transactions on Information Theory (1967).","DOI":"10.1109\/TIT.1967.1053964"},{"key":"e_1_3_3_2_43_2","unstructured":"David\u00a0R Cox. 1958. The Regression Analysis of Binary Sequences. Journal of the Royal Statistical Society Series B: Statistical Methodology (1958)."},{"key":"e_1_3_3_2_44_2","volume-title":"DATE","author":"Dagli Ismet","year":"2025","unstructured":"Ismet Dagli, James Crea, Soner Seckiner, Yuanchao Xu, Sel\u00e7uk K\u00f6se, and Mehmet\u00a0E Belviranli. 2025. MC3: Memory Contention-Based Covert Channel Communication on Shared DRAM System-on-Chips. In DATE."},{"key":"e_1_3_3_2_45_2","volume-title":"USENIX Security","author":"Ridder Finn de","year":"2021","unstructured":"Finn de Ridder, Pietro Frigo, Emanuele Vannacci, Herbert Bos, Cristiano Giuffrida, and Kaveh Razavi. 2021. SMASH: Synchronized Many-Sided Rowhammer Attacks from JavaScript. In USENIX Security."},{"key":"e_1_3_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3503222.3507747"},{"key":"e_1_3_3_2_47_2","unstructured":"Fabrice Devaux and Renaud Ayrignac. 2021. Method and Circuit for Protecting a DRAM Memory Device from the Row Hammer Effect."},{"key":"e_1_3_3_2_48_2","doi-asserted-by":"crossref","unstructured":"Shuhei Enomoto Hiroki Kuzuno and Hiroshi Yamada. 2022. Efficient Protection Mechanism for CPU Cache Flush Instruction Based Attacks. TOIS (2022).","DOI":"10.1587\/transinf.2022NGP0008"},{"key":"e_1_3_3_2_49_2","doi-asserted-by":"crossref","unstructured":"Michael Fahr\u00a0Jr Hunter Kippen Andrew Kwong Thinh Dang Jacob Lichtinger Dana Dachman-Soled Daniel Genkin Alexander Nelson Ray Perlner Arkady Yerukhimovich et\u00a0al. 2022. When Frodo Flips: End-to-End Key Recovery on FrodoKEM via Rowhammer. CCS (2022).","DOI":"10.1145\/3548606.3560673"},{"key":"e_1_3_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA53966.2022.00035"},{"key":"e_1_3_3_2_51_2","doi-asserted-by":"crossref","unstructured":"Apostolos\u00a0P Fournaris Lidia Pocero\u00a0Fraile and Odysseas Koufopavlou. 2017. Exploiting Hardware Vulnerabilities to Attack Embedded System Devices: A Survey of Potent Microarchitectural Attacks. Electronics (2017).","DOI":"10.3390\/electronics6030052"},{"key":"e_1_3_3_2_52_2","doi-asserted-by":"crossref","unstructured":"Yoav Freund and Robert\u00a0E Schapire. 1997. A Decision-Theoretic Generalization of On-Line Learning and An Application to Bosting. J. Comput. System Sci. (1997).","DOI":"10.1006\/jcss.1997.1504"},{"key":"e_1_3_3_2_53_2","doi-asserted-by":"crossref","unstructured":"Jerome\u00a0H Friedman. 2001. Greedy Function Approximation: a Gradient Boosting Machine. Annals of statistics (2001).","DOI":"10.1214\/aos\/1013203451"},{"key":"e_1_3_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00022"},{"key":"e_1_3_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00090"},{"key":"e_1_3_3_2_56_2","doi-asserted-by":"crossref","unstructured":"SK Gautam SK Manhas Arvind Kumar Mahendra Pakala and Ellie Yieh. 2019. Row Hammering Mitigation Using Metal Nanowire in Saddle Fin DRAM. IEEE TED (2019).","DOI":"10.1109\/TED.2019.2931347"},{"key":"e_1_3_3_2_57_2","doi-asserted-by":"crossref","unstructured":"Paul\u00a0R. Genssler Victor\u00a0M. van Santen J\u00f6rg Henkel and Hussam Amrouch. 2022. On the Reliability of FeFET On-Chip Memory. TC (2022).","DOI":"10.1109\/TC.2021.3066899"},{"key":"e_1_3_3_2_58_2","volume-title":"SIGMETRICS","author":"Ghose Saugata","year":"2019","unstructured":"Saugata Ghose, Tianshi Li, Nastaran Hajinazar, Damla\u00a0Senol Cali, and Onur Mutlu. 2019. Demystifying Complex Workload\u2013DRAM Interactions: An Experimental Study. In SIGMETRICS."},{"key":"e_1_3_3_2_59_2","unstructured":"Yoel Gluck Neal Harris and Angelo Prado. 2013. BREACH: Reviving the CRIME Attack. Unpublished manuscript (2013)."},{"key":"e_1_3_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23271"},{"key":"e_1_3_3_2_61_2","unstructured":"Zvika Greenfield and Tomer Levy. 2016. Throttling Support for Row-Hammer Counters. U.S. Patent 9 251 885."},{"key":"e_1_3_3_2_62_2","unstructured":"SAFARI\u00a0Research Group. [n. d.]. Ramulator V2.0. https:\/\/github.com\/CMU-SAFARI\/ramulator2."},{"key":"e_1_3_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00031"},{"key":"e_1_3_3_2_64_2","doi-asserted-by":"crossref","unstructured":"Daniel Gruss Cl\u00e9mentine Maurice and Stefan Mangard. 2016. Rowhammer.js: A Remote Software-Induced Fault Attack in Javascript. DIMVA.","DOI":"10.1007\/978-3-319-40667-1_15"},{"key":"e_1_3_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_3_2_66_2","doi-asserted-by":"crossref","unstructured":"Jin Han Jungsik Kim Dafna Beery K\u00a0Deniz Bozdag Peter Cuevas Amitay Levi Irwin Tain Khai Tran Andrew\u00a0J Walker Senthil\u00a0Vadakupudhu Palayam et\u00a0al. 2021. Surround Gate Transistor With Epitaxially Grown Si Pillar and Simulation Study on Soft Error and Rowhammer Tolerance for DRAM. TED (2021).","DOI":"10.1109\/TED.2020.3045966"},{"key":"e_1_3_3_2_67_2","unstructured":"Hasan Hassan Ataberk Olgun A\u00a0Giray Yaglikci Haocong Luo and Onur Mutlu. 2022. A Case for Self-Managing DRAM Chips: Improving Performance Efficiency Reliability and Security via Autonomous in-DRAM Maintenance Operations. arXiv:2207.13358."},{"key":"e_1_3_3_2_68_2","volume-title":"MICRO","author":"Hassan Hasan","year":"2021","unstructured":"Hasan Hassan, Yahya\u00a0Can Tugrul, Jeremie\u00a0S. Kim, Victor van\u00a0der Veen, Kaveh Razavi, and Onur Mutlu. 2021. Uncovering In-DRAM RowHammer Protection Mechanisms: A New Methodology, Custom RowHammer Patterns, and Implications. In MICRO."},{"key":"e_1_3_3_2_69_2","volume-title":"DRAMSec","author":"Heckel Martin","year":"2023","unstructured":"Martin Heckel and Florian Adamsky. 2023. Reverse-Engineering Bank Addressing Functions on AMD CPUs. In DRAMSec."},{"key":"e_1_3_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/MASCOTS50786.2020.9285962"},{"key":"e_1_3_3_2_71_2","unstructured":"Hewlett-Packard Enterprise. 2015. HP Moonshot Component Pack Version 2015.05.0."},{"key":"e_1_3_3_2_72_2","volume-title":"International Workshop on Privacy Enhancing Technologies","author":"Hintz Andrew","year":"2002","unstructured":"Andrew Hintz. 2002. Fingerprinting Websites Using Traffic Analysis. In International Workshop on Privacy Enhancing Technologies."},{"key":"e_1_3_3_2_73_2","volume-title":"USENIX Security","author":"Hong Sanghyun","year":"2019","unstructured":"Sanghyun Hong, Pietro Frigo, Yi\u011fitcan Kaya, Cristiano Giuffrida, and Tudor Dumitra\u015f. 2019. Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault Attacks. In USENIX Security."},{"key":"e_1_3_3_2_74_2","unstructured":"Seungki Hong Dongha Kim Jaehyung Lee Reum Oh Changsik Yoo Sangjoon Hwang and Jooyoung Lee. 2023. DSAC: Low-Cost Rowhammer Mitigation Using In-DRAM Stochastic and Approximate Counting Algorithm. arXiv:https:\/\/arXiv.org\/abs\/2302.03591 (2023)."},{"key":"e_1_3_3_2_75_2","volume-title":"Intel\u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual, Vol. 1: Basic Architecture","author":"Corp. Intel","year":"2016","unstructured":"Intel Corp.2016. Intel\u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual, Vol. 1: Basic Architecture."},{"key":"e_1_3_3_2_76_2","unstructured":"Gorka Irazoqui Thomas Eisenbarth and Berk Sunar. 2016. MASCAT: Stopping Microarchitectural Attacks Before Execution. IACR Cryptology (2016)."},{"key":"e_1_3_3_2_77_2","first-page":"1157","volume-title":"ISCA","author":"Jaleel Aamer","year":"2024","unstructured":"Aamer Jaleel, Gururaj Saileshwar, Stephen\u00a0W Keckler, and Moinuddin Qureshi. 2024. PrIDE: Achieving Secure Rowhammer Mitigation with Low-Cost In-DRAM Trackers. In ISCA. IEEE, 1157\u20131172."},{"key":"e_1_3_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1145\/3152701.3152709"},{"key":"e_1_3_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833772"},{"key":"e_1_3_3_2_80_2","volume-title":"USENIX Security","author":"Jattke Patrick","year":"2024","unstructured":"Patrick Jattke, Max Wipfli, Flavien Solt, Michele Marazzi, Matej B\u00f6lcskei, and Kaveh Razavi. 2024. Zenhammer: Rowhammer Attacks on AMD Zen-Based Platforms. In USENIX Security."},{"key":"e_1_3_3_2_81_2","volume-title":"JESD79-4C: DDR4 SDRAM Standard","year":"2020","unstructured":"JEDEC. 2020. JESD79-4C: DDR4 SDRAM Standard."},{"key":"e_1_3_3_2_82_2","volume-title":"JESD79-5: DDR5 SDRAM Standard","year":"2020","unstructured":"JEDEC. 2020. JESD79-5: DDR5 SDRAM Standard."},{"key":"e_1_3_3_2_83_2","volume-title":"JESD79-5c: DDR5 SDRAM Standard","year":"2024","unstructured":"JEDEC. 2024. JESD79-5c: DDR5 SDRAM Standard."},{"key":"e_1_3_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2012.6168944"},{"key":"e_1_3_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329811"},{"key":"e_1_3_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586119"},{"key":"e_1_3_3_2_87_2","volume-title":"DATE","author":"Joardar Biresh\u00a0Kumar","year":"2022","unstructured":"Biresh\u00a0Kumar Joardar, Tyler\u00a0K Bletsch, and Krishnendu Chakrabarty. 2022. Learning to Mitigate RowHammer Attacks. In DATE."},{"key":"e_1_3_3_2_88_2","doi-asserted-by":"crossref","unstructured":"Biresh\u00a0Kumar Joardar Tyler\u00a0K. Bletsch and Krishnendu Chakrabarty. 2022. Machine Learning-based Rowhammer Mitigation. TCAD (2022).","DOI":"10.7924\/r4hh6p604"},{"key":"e_1_3_3_2_89_2","volume-title":"SP","author":"Juffinger Jonas","year":"2023","unstructured":"Jonas Juffinger, Lukas Lamster, Andreas Kogler, Maria Eichlseder, Moritz Lipp, and Daniel Gruss. 2023. CSI: Rowhammer-Cryptographic Security and Integrity against Rowhammer. In SP."},{"key":"e_1_3_3_2_90_2","volume-title":"USENIX Security","author":"Kamadan Nureddin","year":"2025","unstructured":"Nureddin Kamadan, Walter Wang, Stephan van Schaik, Christina Garman, Daniel Genkin, and Yuval Yarom. 2025. ECC. fail: Mounting Rowhammer Attacks on DDR4 Servers with ECC Memory. In USENIX Security."},{"key":"e_1_3_3_2_91_2","doi-asserted-by":"crossref","unstructured":"Ingab Kang Eojin Lee and Jung\u00a0Ho Ahn. 2020. CAT-TWO: Counter-Based Adaptive Tree Time Window Optimized for DRAM Row-Hammer Prevention. IEEE Access (2020).","DOI":"10.1109\/ACCESS.2020.2967217"},{"key":"e_1_3_3_2_92_2","volume-title":"USENIX Security 24","author":"Kang Ingab","year":"2024","unstructured":"Ingab Kang, Walter Wang, Jason Kim, Stephan van Schaik, Youssef Tobah, Daniel Genkin, Andrew Kwong, and Yuval Yarom. 2024. SledgeHammer: Amplifying Rowhammer via Bank-level Parallelism. In USENIX Security 24."},{"key":"e_1_3_3_2_93_2","unstructured":"Dimitris Karakostas and Dionysis Zindros. 2016. Practical New Developments on BREACH. Black Hat Asia (2016)."},{"key":"e_1_3_3_2_94_2","volume-title":"DRAM Circuit Design: A Tutorial","author":"Keeth B.","year":"2001","unstructured":"B. Keeth and R.J. Baker. 2001. DRAM Circuit Design: A Tutorial. Wiley."},{"key":"e_1_3_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45661-9_21"},{"key":"e_1_3_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2018.00021"},{"key":"e_1_3_3_2_97_2","unstructured":"Dae-Hyun Kim Prashant\u00a0J Nair and Moinuddin\u00a0K Qureshi. 2014. Architectural Support for Mitigating Row Hammering in DRAM Memories. CAL (2014)."},{"key":"e_1_3_3_2_98_2","unstructured":"Dae-Hyun Kim Prashant\u00a0J Nair and Moinuddin\u00a0K Qureshi. 2015. Architectural Support for Mitigating Row Hammering in DRAM Memories. CAL (2015)."},{"key":"e_1_3_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2019.00011"},{"key":"e_1_3_3_2_100_2","volume-title":"ISCA","author":"Kim Jeremie\u00a0S.","year":"2020","unstructured":"Jeremie\u00a0S. Kim, Minesh Patel, Abdullah\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131, Hasan Hassan, Roknoddin Azizi, Lois Orosa, and Onur Mutlu. 2020. Revisiting RowHammer: An Experimental Analysis of Modern Devices and Mitigation Techniques. In ISCA."},{"key":"e_1_3_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA53966.2022.00088"},{"key":"e_1_3_3_2_102_2","volume-title":"ISCA","author":"Kim Y.","year":"2014","unstructured":"Y. Kim, R. Daly, J. Kim, C. Fallin, J.\u00a0H. Lee, D. Lee, C. Wilkerson, K. Lai, and O. Mutlu. 2014. Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors. In ISCA."},{"key":"e_1_3_3_2_103_2","volume-title":"ISCA","author":"Kim Yoongu","year":"2012","unstructured":"Yoongu Kim, Vivek Seshadri, Donghyuk Lee, Jamie Liu, Onur Mutlu, Yoongu Kim, Vivek Seshadri, Donghyuk Lee, Jamie Liu, and Onur Mutlu. 2012. A Case for Exploiting Subarray-Level Parallelism (SALP) in DRAM. In ISCA."},{"key":"e_1_3_3_2_104_2","doi-asserted-by":"crossref","unstructured":"Yoongu Kim Weikun Yang and Onur Mutlu. 2016. Ramulator: A Fast and Extensible DRAM Simulator. CAL (2016).","DOI":"10.1109\/LCA.2015.2414456"},{"key":"e_1_3_3_2_105_2","volume-title":"USENIX Security","author":"Kogler Andreas","year":"2022","unstructured":"Andreas Kogler, Jonas Juffinger, Salman Qazi, Yoongu Kim, Moritz Lipp, Nicolas Boichat, Eric Shiu, Mattias Nissler, and Daniel Gruss. 2022. Half-Double: Hammering From the Next Row Over. In USENIX Security."},{"key":"e_1_3_3_2_106_2","volume-title":"IJCAI","author":"Kohavi Ron","year":"1995","unstructured":"Ron Kohavi. 1995. A Study of Cross-Validation and Bootstrap for Accuracy Estimation and Model Selection. In IJCAI."},{"key":"e_1_3_3_2_107_2","volume-title":"OSDI","author":"Konoth Radhesh\u00a0Krishnan","year":"2018","unstructured":"Radhesh\u00a0Krishnan Konoth, Marco Oliverio, Andrei Tatar, Dennis Andriesse, Herbert Bos, Cristiano Giuffrida, and Kaveh Razavi. 2018. ZebRAM: Comprehensive and Compatible Software Protection Against Rowhammer Attacks. In OSDI."},{"key":"e_1_3_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00020"},{"key":"e_1_3_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2013.6522354"},{"key":"e_1_3_3_2_110_2","volume-title":"ISCA","author":"Lee Eojin","year":"2019","unstructured":"Eojin Lee, Ingab Kang, Sukhan Lee, G Edward Suh, and Jung Ho Ahn. 2019. TWiCe: Preventing Row-Hammering by Exploiting Time Window Counters. In ISCA."},{"key":"e_1_3_3_2_111_2","volume-title":"ISCA","author":"Lee Gyu-Hyeon","year":"2021","unstructured":"Gyu-Hyeon Lee, Seongmin Na, Ilkwon Byun, Dongmoon Min, and Jangwoo Kim. 2021. CryoGuard: A Near Refresh-Free Robust DRAM Design for Cryogenic Computing. In ISCA."},{"key":"e_1_3_3_2_112_2","unstructured":"Lenovo Group Ltd.2015. Row Hammer Privilege Escalation. https:\/\/support.lenovo.com\/us\/en\/product_security\/row_hammer."},{"key":"e_1_3_3_2_113_2","volume-title":"USENIX Security)","author":"Lin Chris\u00a0S","year":"2025","unstructured":"Chris\u00a0S Lin, Joyce Qu, and Gururaj Saileshwar. 2025. GPUHammer: Rowhammer Attacks on GPU Memories are Practical. In USENIX Security)."},{"key":"e_1_3_3_2_114_2","unstructured":"Chris\u00a0S Lin Jeonghyun Woo Prashant\u00a0J Nair and Gururaj Saileshwar. 2025. CnC-PRAC: Coalesce not Cache Per Row Activation Counts for an Efficient in-DRAM Rowhammer Mitigation. DRAMSec (2025)."},{"key":"e_1_3_3_2_115_2","doi-asserted-by":"publisher","DOI":"10.1145\/3167132.3167151"},{"key":"e_1_3_3_2_116_2","unstructured":"Moritz Lipp Misiker\u00a0Tadesse Aga Michael Schwarz Daniel Gruss Cl\u00e9mentine Maurice Lukas Raab and Lukas Lamster. 2018. Nethammer: Inducing Rowhammer Faults Through Network Requests. EuroS&PW."},{"key":"e_1_3_3_2_117_2","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384746"},{"key":"e_1_3_3_2_118_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_3_2_119_2","volume-title":"ISCA","author":"Liu Jamie","year":"2013","unstructured":"Jamie Liu, Ben Jaiyen, Yoongu Kim, Chris Wilkerson, Onur Mutlu, J Liu, B Jaiyen, Y Kim, C Wilkerson, and O Mutlu. 2013. An Experimental Study of Data Retention Behavior in Modern DRAM Devices. In ISCA."},{"key":"e_1_3_3_2_120_2","volume-title":"ISCA","author":"Liu Jamie","year":"2012","unstructured":"Jamie Liu, Ben Jaiyen, Richard Veras, and Onur Mutlu. 2012. RAIDR: Retention-Aware Intelligent DRAM Refresh. In ISCA."},{"key":"e_1_3_3_2_121_2","doi-asserted-by":"crossref","unstructured":"Lei Liu Zehan Cui Yong Li Yungang Bao Mingyu Chen and Chengyong Wu. 2014. BPM\/BPM+ Software-Based Dynamic Memory Partitioning Mechanisms for Mitigating DRAM Bank-\/Channel-Level Interferences in Multicore Systems. TACO (2014).","DOI":"10.1145\/2579672"},{"key":"e_1_3_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1145\/2370816.2370869"},{"key":"e_1_3_3_2_123_2","unstructured":"Liang Liu Yanan Guo Yueqiang Cheng Youtao Zhang and Jun Yang. 2022. Generating Robust DNN with Resistance to Bit-Flip based Adversarial Weight Attack. TC (2022)."},{"key":"e_1_3_3_2_124_2","volume-title":"USENIX Security","author":"Liu Sihang","year":"2023","unstructured":"Sihang Liu, Suraaj Kanniwadi, Martin Schwarzl, Andreas Kogler, Daniel Gruss, and Samira Khan. 2023. Side-Channel Attacks on Optane Persistent Memory. In USENIX Security."},{"key":"e_1_3_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1145\/3458336.3465295"},{"key":"e_1_3_3_2_126_2","volume-title":"ISCA","author":"Loughlin Kevin","year":"2022","unstructured":"Kevin Loughlin, Stefan Saroiu, Alec Wolman, Yatin\u00a0A. Manerkar, and Baris Kasikci. 2022. MOESI-Prime: Preventing Coherence-Induced Hammering in Commodity Workloads. In ISCA."},{"key":"e_1_3_3_2_127_2","unstructured":"Shih-Lien Lu Jeonghyun Woo and Prashant\u00a0J Nair. 2025. Counterpoint: One-Hot Counting for PRAC-Based RowHammer Mitigation. DRAMSec (2025)."},{"key":"e_1_3_3_2_128_2","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065034"},{"key":"e_1_3_3_2_129_2","volume-title":"ISCA","author":"Luo Haocong","year":"2023","unstructured":"Haocong Luo, Ataberk Olgun, Abdullah\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131, Yahya\u00a0Can Tu\u011frul, Steve Rhyner, Meryem\u00a0Banu Cavlak, Jo\u00ebl Lindegger, Mohammad Sadrosadati, and Onur Mutlu. 2023. RowPress: Amplifying Read Disturbance in Modern DRAM Chips. In ISCA."},{"key":"e_1_3_3_2_130_2","unstructured":"Haocong Luo Ataberk Olgun A\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131 Yahya\u00a0Can Tu\u011frul Steve Rhyner Meryem\u00a0Banu Cavlak Jo\u00ebl Lindegger Mohammad Sadrosadati and Onur Mutlu. 2024. RowPress Vulnerability in Modern DRAM Chips. IEEE Micro (2024)."},{"key":"e_1_3_3_2_131_2","unstructured":"Haocong Luo Yahya\u00a0Can Tu\u011frul F.\u00a0Nisa Bostanc\u0131 Ataberk Olgun A.\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131 and Onur Mutlu. 2023. Ramulator 2.0: A Modern Modular and Extensible DRAM Simulator. IEEE CAL (2023)."},{"key":"e_1_3_3_2_132_2","doi-asserted-by":"crossref","unstructured":"Jack\u00a0A Mandelman Robert\u00a0H Dennard Gary\u00a0B Bronner John\u00a0K DeBrosse Rama Divakaruni Yujun Li and Carl\u00a0J Radens. 2002. Challenges and Future Directions for the Scaling of Dynamic Random-Access Memory (DRAM). IBM JRD (2002).","DOI":"10.1147\/rd.462.0187"},{"key":"e_1_3_3_2_133_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00020"},{"key":"e_1_3_3_2_134_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833664"},{"key":"e_1_3_3_2_135_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23294"},{"key":"e_1_3_3_2_136_2","volume-title":"S&P","author":"Meyer Diego","year":"2026","unstructured":"Diego Meyer, Patrick Jattke, Michele Marazzi, Salman Qazi, Daniel Moghimi, and Kaveh Razavi. 2026. Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization. In S&P."},{"key":"e_1_3_3_2_137_2","volume-title":"WEED","author":"Meza Justin","year":"2013","unstructured":"Justin Meza, Yixin Luo, Samira Khan, Jishen Zhao, Yuan Xie, and Onur Mutlu. 2013. A Case for Efficient Hardware\/Software Cooperative Management of Storage and Memory. In WEED."},{"key":"e_1_3_3_2_138_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2016.7446087"},{"key":"e_1_3_3_2_139_2","unstructured":"Micron. 2020. 8Gb: x4 x8 x16 DDR4 SDRAM Features - Excessive Row Activation."},{"key":"e_1_3_3_2_140_2","volume-title":"USENIX Security","author":"Moscibroda Thomas","year":"2007","unstructured":"Thomas Moscibroda and Onur Mutlu. 2007. Memory Performance Attacks: Denial of Memory Service in Multi-Core Systems. In USENIX Security."},{"key":"e_1_3_3_2_141_2","doi-asserted-by":"publisher","DOI":"10.1145\/2155620.2155664"},{"key":"e_1_3_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/IMW.2013.6582088"},{"key":"e_1_3_3_2_143_2","volume-title":"DATE","author":"Mutlu Onur","year":"2017","unstructured":"Onur Mutlu. 2017. The RowHammer Problem and Other Issues We May Face as Memory Becomes Denser. In DATE."},{"key":"e_1_3_3_2_144_2","unstructured":"Onur Mutlu. 2018. RowHammer. Top Picks in Hardware and Embedded Security."},{"key":"e_1_3_3_2_145_2","unstructured":"Onur Mutlu. 2023. Retrospective: Flipping Bits in Memory without Accessing Them: An Experimental Study of DRAM Disturbance Errors. arXiv (2023)."},{"key":"e_1_3_3_2_146_2","unstructured":"Onur Mutlu and Jeremie\u00a0S Kim. 2019. RowHammer: A Retrospective. TCAD (2019)."},{"key":"e_1_3_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2007.40"},{"key":"e_1_3_3_2_148_2","volume-title":"ISCA","author":"Mutlu Onur","year":"2008","unstructured":"Onur Mutlu and Thomas Moscibroda. 2008. Parallelism-Aware Batch Scheduling: Enhancing Both Performance and Fairness of Shared DRAM Systems. In ISCA."},{"key":"e_1_3_3_2_149_2","doi-asserted-by":"publisher","DOI":"10.1145\/3566097.3568350"},{"key":"e_1_3_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.1109\/IMW61990.2025.11026935"},{"key":"e_1_3_3_2_151_2","doi-asserted-by":"crossref","unstructured":"Amir Naseredini Martin Berger Matteo Sammartino and Shale Xiong. 2022. ALARM: Active LeArning of Rowhammer Mitigations. https:\/\/users.sussex.ac.uk\/\u00a0mfb21\/rh-draft.pdf.","DOI":"10.1145\/3569562.3569563"},{"key":"e_1_3_3_2_152_2","volume-title":"USENIX Security","author":"Nazaraliyev Ravan","year":"2025","unstructured":"Ravan Nazaraliyev, Yicheng Zhang, Sankha\u00a0Baran Dutta, Andres Marquez, Kevin Barker, and Nael Abu-Ghazaleh. 2025. Not so Refreshing: Attacking GPUs using RFM Rowhammer Mitigation. In USENIX Security."},{"key":"e_1_3_3_2_153_2","doi-asserted-by":"crossref","unstructured":"Kai Ni Xueqing Li Jeffrey\u00a0A. Smith Matthew Jerry and Suman Datta. 2018. Write Disturb in Ferroelectric FETs and Its Implication for 1T-FeFET AND Memory Arrays. IEEE EDL (2018).","DOI":"10.1109\/LED.2018.2872347"},{"key":"e_1_3_3_2_154_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA61900.2025.00069"},{"key":"e_1_3_3_2_155_2","volume-title":"ISCA","author":"Olgun Ataberk","year":"2021","unstructured":"Ataberk Olgun, Minesh Patel, A\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131, Haocong Luo, Jeremie\u00a0S Kim, Nisa Bostanc\u0131, Nandita Vijaykumar, O\u011fuz Ergin, and Onur Mutlu. 2021. QUAC-TRNG: High-Throughput True Random Number Generation Using Quadruple Row Activation in Commodity DRAM Chips. In ISCA."},{"key":"e_1_3_3_2_156_2","volume-title":"USENIX Security","author":"Olgun Ataberk","year":"2024","unstructured":"Ataberk Olgun, Yahya\u00a0Can Tugrul, Nisa Bostanci, Ismail\u00a0Emir Yuksel, Haocong Luo, Steve Rhyner, Abdullah\u00a0Giray Yaglikci, Geraldo\u00a0F. Oliveira, and Onur Mutlu. 2024. ABACuS: All-Bank Activation Counters for Scalable and Low Overhead RowHammer Mitigation. In USENIX Security."},{"key":"e_1_3_3_2_157_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813708"},{"key":"e_1_3_3_2_158_2","unstructured":"Lois Orosa Ulrich R\u00fchrmair A\u00a0Giray Yaglikci Haocong Luo Ataberk Olgun Patrick Jattke Minesh Patel Jeremie Kim Kaveh Razavi and Onur Mutlu. 2022. SpyHammer: Using RowHammer to Remotely Spy on Temperature. arXiv:2210.04084."},{"key":"e_1_3_3_2_159_2","volume-title":"MICRO","author":"Orosa Lois","year":"2021","unstructured":"Lois Orosa, A\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131, Haocong Luo, Ataberk Olgun, Jisung Park, Hasan Hassan, Minesh Patel, Jeremie\u00a0S. Kim, and Onur Mutlu. 2021. A Deeper Look into RowHammer\u2019s Sensitivities: Experimental Analysis of Real DRAM Chips and Implications on Future Attacks and Defenses. In MICRO."},{"key":"e_1_3_3_2_160_2","doi-asserted-by":"crossref","unstructured":"Kyungbae Park Chulseung Lim Donghyuk Yun and Sanghyeon Baeg. 2016. Experiments and Root Cause Analysis for Active-Precharge Hammering Fault in DDR3 SDRAM under 3xnm Technology. Microelectronics Reliability (2016).","DOI":"10.1016\/j.microrel.2015.12.027"},{"key":"e_1_3_3_2_161_2","doi-asserted-by":"crossref","unstructured":"Kyungbae Park Donghyuk Yun and Sanghyeon Baeg. 2016. Statistical Distributions of Row-Hammering Induced Failures in DDR3 Components. Microelectronics Reliability (2016).","DOI":"10.1016\/j.microrel.2016.10.014"},{"key":"e_1_3_3_2_162_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00014"},{"key":"e_1_3_3_2_163_2","volume-title":"USENIX Security","author":"Pessl Peter","year":"2016","unstructured":"Peter Pessl, Daniel Gruss, Cl\u00e9mentine Maurice, Michael Schwarz, and Stefan Mangard. 2016. DRAMA: Exploiting DRAM Addressing for Cross-CPU Attacks. In USENIX Security."},{"key":"e_1_3_3_2_164_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00031"},{"key":"e_1_3_3_2_165_2","unstructured":"Salman Qazi and Moinuddin Qureshi. 2025. DRFM and the Art of Rowhammer Sampling. DRAMSec (2025)."},{"key":"e_1_3_3_2_166_2","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2016.7495576"},{"key":"e_1_3_3_2_167_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA61900.2025.00078"},{"key":"e_1_3_3_2_168_2","doi-asserted-by":"crossref","unstructured":"Moinuddin Qureshi Salman Qazi and Aamer Jaleel. 2024. MINT: Securely Mitigating Rowhammer with a Minimalist In-DRAM Tracker. MICRO (2024).","DOI":"10.1109\/MICRO61859.2024.00071"},{"key":"e_1_3_3_2_169_2","volume-title":"ISCA","author":"Qureshi Moinuddin","year":"2022","unstructured":"Moinuddin Qureshi, Aditya Rohan, Gururaj Saileshwar, and Prashant\u00a0J Nair. 2022. Hydra: Enabling Low-Overhead Mitigation of Row-Hammer at Ultra-Low Thresholds via Hybrid Tracking. In ISCA."},{"key":"e_1_3_3_2_170_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"e_1_3_3_2_171_2","volume-title":"ISCA","author":"Ravichandran Joseph","year":"2022","unstructured":"Joseph Ravichandran, Weon\u00a0Taek Na, Jay Lang, and Mengjia Yan. 2022. PACMAN: Attacking ARM Pointer Authentication with Speculative Execution. In ISCA."},{"key":"e_1_3_3_2_172_2","volume-title":"USENIX Security","author":"Razavi Kaveh","year":"2016","unstructured":"Kaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel, Cristiano Giuffrida, and Herbert Bos. 2016. Flip Feng Shui: Hammering a Needle in the Software Stack. In USENIX Security."},{"key":"e_1_3_3_2_173_2","doi-asserted-by":"publisher","DOI":"10.5555\/582628.825134"},{"key":"e_1_3_3_2_174_2","doi-asserted-by":"crossref","unstructured":"Vera Rimmer Davy Preuveneers Marc Juarez Tom van Goethem and Wouter Joosen. 2018. Automated Website Fingerprinting through Deep Learning. NDSS (2018).","DOI":"10.14722\/ndss.2018.23105"},{"key":"e_1_3_3_2_175_2","volume-title":"ISCA","author":"Rixner Scott","year":"2000","unstructured":"Scott Rixner, William\u00a0J. Dally, Ujval\u00a0J. Kapasi, Peter Mattson, and John\u00a0D. Owens. 2000. Memory Access Scheduling. In ISCA."},{"key":"e_1_3_3_2_176_2","volume-title":"Ekoparty Security Conference","author":"Rizzo Juliano","year":"2012","unstructured":"Juliano Rizzo and Thai Duong. 2012. Crime: Compression Ratio Info-leak Made Easy. In Ekoparty Security Conference."},{"key":"e_1_3_3_2_177_2","doi-asserted-by":"crossref","unstructured":"Frank Rosenblatt. 1958. The Perceptron: A Probabilistic Model for Information Storage and Organization in the Brain. Psychological Review (1958).","DOI":"10.1037\/h0042519"},{"key":"e_1_3_3_2_178_2","doi-asserted-by":"publisher","DOI":"10.1109\/IEDM.2017.8268437"},{"key":"e_1_3_3_2_179_2","unstructured":"SAFARI Research Group. [n. d.]. BlockHammer \u2014 GitHub Repository. https:\/\/github.com\/CMU-SAFARI\/blockhammer."},{"key":"e_1_3_3_2_180_2","unstructured":"SAFARI Research Group. [n. d.]. RowHammer \u2014 GitHub Repository. https:\/\/github.com\/CMU-SAFARI\/rowhammer."},{"key":"e_1_3_3_2_181_2","doi-asserted-by":"publisher","DOI":"10.1145\/3503222.3507716"},{"key":"e_1_3_3_2_182_2","doi-asserted-by":"publisher","DOI":"10.1109\/IRPS48227.2022.9764591"},{"key":"e_1_3_3_2_183_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO61859.2024.00073"},{"key":"e_1_3_3_2_184_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00022"},{"key":"e_1_3_3_2_185_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70972-7_13"},{"key":"e_1_3_3_2_186_2","unstructured":"Martin Schwarzl Pietro Borrello Gururaj Saileshwar Hanna M\u00fcller Michael Schwarz and Daniel Gruss. 2021. Practical Timing Side Channel Attacks on Memory Compression. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2111.08404 (2021)."},{"key":"e_1_3_3_2_187_2","unstructured":"Mark Seaborn and Thomas Dullien. 2015. Exploiting the DRAM Rowhammer Bug to Gain Kernel Privileges. http:\/\/googleprojectzero.blogspot.com.tr\/2015\/03\/exploiting-dram-rowhammer-bug-to-gain.html."},{"key":"e_1_3_3_2_188_2","unstructured":"Mark Seaborn and Thomas Dullien. 2015. Exploiting the DRAM Rowhammer Bug to Gain Kernel Privileges. Black Hat (2015)."},{"key":"e_1_3_3_2_189_2","doi-asserted-by":"crossref","unstructured":"Seyed\u00a0Mohammad Seyedzadeh Alex\u00a0K. Jones and Rami Melhem. 2017. Counter-Based Tree Structure for Row Hammering Mitigation in DRAM. CAL (2017).","DOI":"10.1109\/LCA.2016.2614497"},{"key":"e_1_3_3_2_190_2","volume-title":"ISCA","author":"Seyedzadeh S.\u00a0M.","year":"2018","unstructured":"S.\u00a0M. Seyedzadeh, A.\u00a0K. Jones, and R. Melhem. 2018. Mitigating Wordline Crosstalk Using Adaptive Trees of Counters. In ISCA."},{"key":"e_1_3_3_2_191_2","volume-title":"USENIX Security 19","author":"Shusterman Anatoly","year":"2019","unstructured":"Anatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser, Prateek Mittal, Yossi Oren, and Yuval Yarom. 2019. Robust Website Fingerprinting Through the Cache Occupancy Channel. In USENIX Security 19. USENIX Association."},{"key":"e_1_3_3_2_192_2","doi-asserted-by":"publisher","DOI":"10.1145\/3061639.3062281"},{"key":"e_1_3_3_2_193_2","unstructured":"Standard Performance Evaluation Corp.2006. SPEC CPU 2006. http:\/\/www.spec.org\/cpu2006\/."},{"key":"e_1_3_3_2_194_2","unstructured":"Standard Performance Evaluation Corp.2017. SPEC CPU 2017. http:\/\/www.spec.org\/cpu2017."},{"key":"e_1_3_3_2_195_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2014.6974655"},{"key":"e_1_3_3_2_196_2","doi-asserted-by":"crossref","unstructured":"Lavanya Subramanian Donghyuk Lee Vivek Seshadri Harsha Rastogi and Onur Mutlu. 2016. BLISS: Balancing Performance Fairness and Complexity in Memory Access Scheduling. TPDS (2016).","DOI":"10.1109\/TPDS.2016.2526003"},{"key":"e_1_3_3_2_197_2","volume-title":"S&P","author":"Sun Qixiang","year":"2002","unstructured":"Qixiang Sun, Daniel\u00a0R Simon, Yi-Min Wang, Wilf Russell, Venkata\u00a0N Padmanabhan, and Lili Qiu. 2002. Statistical Identification of Encrypted Web Browsing Traffic. In S&P."},{"key":"e_1_3_3_2_198_2","volume-title":"CSE","author":"Suzuki Noriaki","year":"2013","unstructured":"Noriaki Suzuki, Hyoseung Kim, Dionisio De\u00a0Niz, Bjorn Andersson, Lutz Wrage, Mark Klein, and Ragunathan Rajkumar. 2013. Coordinated Bank and Cache Coloring for Temporal Protection of Memory Accesses. In CSE. IEEE."},{"key":"e_1_3_3_2_199_2","volume-title":"ISCA","author":"Taneja Hritvik","year":"2025","unstructured":"Hritvik Taneja and Moin Qureshi. 2025. DREAM: Enabling Low-Overhead Rowhammer Mitigation via Directed Refresh Management. In ISCA."},{"key":"e_1_3_3_2_200_2","unstructured":"Hritvik Taneja and Moinuddin Qureshi. 2025. RogueRFM: Attacking Refresh Management for Covert-Channel and Denial-of-Service. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2501.06646 (2025)."},{"key":"e_1_3_3_2_201_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_3"},{"key":"e_1_3_3_2_202_2","volume-title":"USENIX ATC","author":"Tatar Andrei","year":"2018","unstructured":"Andrei Tatar, Radhesh\u00a0Krishnan Konoth, Elias Athanasopoulos, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. 2018. Throwhammer: Rowhammer Attacks Over the Network and Defenses. In USENIX ATC."},{"key":"e_1_3_3_2_203_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833802"},{"key":"e_1_3_3_2_204_2","unstructured":"M\u00a0Caner Tol Saad Islam Berk Sunar and Ziming Zhang. 2022. Toward Realistic Backdoor Injection Attacks on DNNs using RowHammer. arXiv:2110.07683v2 [cs.LG]."},{"key":"e_1_3_3_2_205_2","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378453"},{"key":"e_1_3_3_2_206_2","volume-title":"HPCA","author":"Tu\u011frul Yahya\u00a0Can","year":"2025","unstructured":"Yahya\u00a0Can Tu\u011frul, A\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131, \u0130smail\u00a0Emir Y\u00fcksel, Ataberk Olgun, O\u011fuzhan Canpolat, Nisa Bostanc\u0131, Mohammad Sadrosadati, O\u011fuz Ergin, and Onur Mutlu. 2025. Understanding RowHammer Under Reduced Refresh Latency: Experimental Analysis of Real DRAM Chips and Implications on Future Solutions. In HPCA."},{"key":"e_1_3_3_2_207_2","volume-title":"CCS","author":"Veen Victor van\u00a0der","year":"2016","unstructured":"Victor van\u00a0der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss, Clementine Maurice, Giovanni Vigna, Herbert Bos, Kaveh Razavi, and Cristiano Giuffrida. 2016. Drammer: Deterministic Rowhammer Attacks on Mobile Platforms. In CCS."},{"key":"e_1_3_3_2_208_2","unstructured":"Victor van\u00a0der Veen and Ben Gras. 2023. DramaQueen: Revisiting Side Channels in DRAM."},{"key":"e_1_3_3_2_209_2","volume-title":"DIMVA","author":"Veen Victor van der","year":"2018","unstructured":"Victor van der Veen, Martina Lindorfer, Yanick Fratantonio, Harikrishnan\u00a0Padmanabha Pillai, Giovanni Vigna, Christopher Kruegel, Herbert Bos, and Kaveh Razavi. 2018. GuardION: Practical Mitigation of DMA-Based Rowhammer Attacks on ARM. In DIMVA."},{"key":"e_1_3_3_2_210_2","volume-title":"USENIX Security","author":"Van\u00a0Goethem Tom","year":"2016","unstructured":"Tom Van\u00a0Goethem, Mathy Vanhoef, Frank Piessens, and Wouter Joosen. 2016. Request and conquer: Exposing Cross-Origin Resource Size. In USENIX Security."},{"key":"e_1_3_3_2_211_2","doi-asserted-by":"publisher","DOI":"10.5555\/539927"},{"key":"e_1_3_3_2_212_2","volume-title":"Black Hat US Briefings, Location: Las Vegas, USA","author":"Vanhoef Mathy","year":"2016","unstructured":"Mathy Vanhoef and Tom Van\u00a0Goethem. 2016. HEIST: HTTP Encrypted Information can be Stolen through TCP-windows. In Black Hat US Briefings, Location: Las Vegas, USA."},{"key":"e_1_3_3_2_213_2","unstructured":"A Vaswani. 2017. Attention is All You Need. Advances in Neural Information Processing Systems (2017)."},{"key":"e_1_3_3_2_214_2","volume-title":"HASP","author":"Vig Saru","year":"2018","unstructured":"Saru Vig, Sarani Bhattacharya, Debdeep Mukhopadhyay, and Siew-Kei Lam. 2018. Rapid Detection of Rowhammer Attacks Using Dynamic Skewed Hash Tree. In HASP."},{"key":"e_1_3_3_2_215_2","volume-title":"ISCA","author":"Vittal Suhas","year":"2025","unstructured":"Suhas Vittal, Salman Qazi, Poulami Das, and Moinuddin Qureshi. 2025. MoPAC: Efficiently Mitigating Rowhammer with Probabilistic Activation Counting. In ISCA."},{"key":"e_1_3_3_2_216_2","volume-title":"CCS","author":"Volos Stavros","year":"2024","unstructured":"Stavros Volos, C\u00e9dric Fournet, Jana Hofmann, Boris K\u00f6pf, and Oleksii Oleksenko. 2024. Principled Microarchitectural Isolation on Cloud CPUs. In CCS."},{"key":"e_1_3_3_2_217_2","doi-asserted-by":"crossref","unstructured":"Andrew\u00a0J. Walker Sungkwon Lee and Dafna Beery. 2021. On DRAM RowHammer and the Physics on Insecurity. IEEE TED (2021).","DOI":"10.1109\/TED.2021.3060362"},{"key":"e_1_3_3_2_218_2","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218599"},{"key":"e_1_3_3_2_219_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD53106.2021.00074"},{"key":"e_1_3_3_2_220_2","doi-asserted-by":"crossref","unstructured":"Zane Weissman Thore Tiemann Daniel Moghimi Evan Custodio Thomas Eisenbarth and Berk Sunar. 2020. JackHammer: Efficient Rowhammer on Heterogeneous FPGA\u2013CPU Platforms. TCHES.","DOI":"10.46586\/tches.v2020.i3.169-195"},{"key":"e_1_3_3_2_221_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA56546.2023.10070966"},{"key":"e_1_3_3_2_222_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA61900.2025.00080"},{"key":"e_1_3_3_2_223_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA61900.2025.00079"},{"key":"e_1_3_3_2_224_2","volume-title":"ISCA","author":"Woo Jeonghyun","year":"2025","unstructured":"Jeonghyun Woo, Joyce Qu, Gururaj Saileshwar, and Prashant\u00a0Jayaprakash Nair. 2025. When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer Mitigations. In ISCA."},{"key":"e_1_3_3_2_225_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA56546.2023.10070999"},{"key":"e_1_3_3_2_226_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2013.6575349"},{"key":"e_1_3_3_2_227_2","volume-title":"USENIX Security","author":"Xiao Yuan","year":"2016","unstructured":"Yuan Xiao, Xiaokuan Zhang, Yinqian Zhang, and Radu Teodorescu. 2016. One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege Escalation. In USENIX Security."},{"key":"e_1_3_3_2_228_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2014.6835945"},{"key":"e_1_3_3_2_229_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA47549.2020.00021"},{"key":"e_1_3_3_2_230_2","unstructured":"A.\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131 Jeremie\u00a0S. Kim Fabrice Devaux and Onur Mutlu. 2021. Security Analysis of the Silver Bullet Technique for RowHammer Prevention. arXiv:2106.07084 [cs.CR]."},{"key":"e_1_3_3_2_231_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN53405.2022.00054"},{"key":"e_1_3_3_2_232_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00062"},{"key":"e_1_3_3_2_233_2","volume-title":"HPCA","author":"Ya\u011fl\u0131k\u00e7\u0131 A.\u00a0Giray","year":"2024","unstructured":"A.\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131, Geraldo\u00a0Francisco Oliveira, Yahya\u00a0Can Tu\u011frul, Ismail\u00a0Emir Yuksel, Ataberk Olgun, Haocong Luo, and Onur Mutlu. 2024. Spatial Variation-Aware Read Disturbance Defenses: Experimental Analysis of Real DRAM Chips and Implications on Future Solutions. In HPCA."},{"key":"e_1_3_3_2_234_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA51647.2021.00037"},{"key":"e_1_3_3_2_235_2","volume-title":"HPCA","author":"Ya\u011fl\u0131k\u00e7\u0131 Abdullah\u00a0Giray","year":"2024","unstructured":"Abdullah\u00a0Giray Ya\u011fl\u0131k\u00e7\u0131, Yahya\u00a0Can Tu\u011frul, Geraldo\u00a0F Oliveira, \u0130smail\u00a0Emir Y\u00fcksel, Ataberk Olgun, Haocong Luo, and Onur Mutlu. 2024. Spatial Variation-Aware Read Disturbance Defenses: Experimental Analysis of Real DRAM Chips and Implications on Future Solutions. In HPCA."},{"key":"e_1_3_3_2_236_2","doi-asserted-by":"crossref","unstructured":"Chia Yang Chen\u00a0Kang Wei Yu\u00a0Jing Chang Tieh\u00a0Chiang Wu Hsiu\u00a0Pin Chen and Chao\u00a0Sung Lai. 2016. Suppression of RowHammer Effect by Doping Profile Modification in Saddle-Fin Array Devices for Sub-30-nm DRAM Technology. TDMR (2016).","DOI":"10.1109\/TDMR.2016.2607174"},{"key":"e_1_3_3_2_237_2","unstructured":"Chia-Ming Yang Chen-Kang Wei Hsiu-Pin Chen Jian-Shing Luo Yu\u00a0Jing Chang Tieh-Chiang Wu and Chao-Sung Lai. 2017. Scanning Spreading Resistance Microscopy for Doping Profile in Saddle-Fin Devices. IEEE Transactions on Nanotechnology (2017)."},{"key":"e_1_3_3_2_238_2","doi-asserted-by":"crossref","unstructured":"Thomas Yang and Xi-Wei Lin. 2019. Trap-Assisted DRAM Row Hammer Effect. EDL (2019).","DOI":"10.1109\/LED.2019.2891260"},{"key":"e_1_3_3_2_239_2","volume-title":"USENIX Security","author":"Yao Fan","year":"2020","unstructured":"Fan Yao, Adnan\u00a0Siraj Rakin, and Deliang Fan. 2020. Deephammer: Depleting the Intelligence of Deep Neural Networks Through Targeted Chain of Bit Flips. In USENIX Security."},{"key":"e_1_3_3_2_240_2","volume-title":"USENIX Security Symposium","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner. 2014. FLUSH+ RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. In USENIX Security Symposium."},{"key":"e_1_3_3_2_241_2","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317866"},{"key":"e_1_3_3_2_242_2","doi-asserted-by":"publisher","DOI":"10.1145\/3725843.3756022"},{"key":"e_1_3_3_2_243_2","volume-title":"ISCA","author":"Yuksel Ismail\u00a0Emir","year":"2025","unstructured":"Ismail\u00a0Emir Yuksel, Akash Sood, Ataberk Olgun, O\u011fuzhan Canpolat, Haocong Luo, Nisa Bostanci, Mohammad Sadrosadati, Giray Yaglikci, and Onur Mutlu. 2025. PuDHammer: Experimental Analysis of Read Disturbance Effects of Processing-using-DRAM in Real DRAM Chips. In ISCA."},{"key":"e_1_3_3_2_244_2","doi-asserted-by":"publisher","DOI":"10.1109\/RTAS.2014.6925999"},{"key":"e_1_3_3_2_245_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00016"},{"key":"e_1_3_3_2_246_2","volume-title":"USENIX ATC","author":"Zhang Zhi","year":"2022","unstructured":"Zhi Zhang, Yueqiang Cheng, Minghua Wang, Wei He, Wenhao Wang, Surya Nepal, Yansong Gao, Kang Li, Zhe Wang, and Chenggang Wu. 2022. SoftTRR: Protect Page Tables against Rowhammer Attacks using Software-only Target Row Refresh. In USENIX ATC."},{"key":"e_1_3_3_2_247_2","doi-asserted-by":"crossref","unstructured":"Zhi Zhang Wei He Yueqiang Cheng Wenhao Wang Yansong Gao Dongxi Liu Kang Li Surya Nepal Anmin Fu and Yi Zou. 2022. Implicit Hammer: Cross-Privilege-Boundary Rowhammer through Implicit Accesses. TDSC (2022).","DOI":"10.1109\/TDSC.2022.3214666"},{"key":"e_1_3_3_2_248_2","doi-asserted-by":"publisher","DOI":"10.1145\/3266444.3266454"},{"key":"e_1_3_3_2_249_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00060"},{"key":"e_1_3_3_2_250_2","volume-title":"USENIX Security 22","author":"Zhao Zirui\u00a0Neil","year":"2022","unstructured":"Zirui\u00a0Neil Zhao, Adam Morrison, Christopher\u00a0W Fletcher, and Josep Torrellas. 2022. Binoculars: Contention-Based Side-Channel Attacks Exploiting the Page Walker. In USENIX Security 22."},{"key":"e_1_3_3_2_251_2","doi-asserted-by":"crossref","unstructured":"Mengxin Zheng Qian Lou and Lei Jiang. 2022. TrojViT: Trojan Insertion in Vision Transformers. arXiv:2208.13049.","DOI":"10.1109\/CVPR52729.2023.00392"},{"key":"e_1_3_3_2_252_2","volume-title":"USENIX Security Symposium","author":"Zhenyu Wu","year":"2012","unstructured":"Wu Zhenyu, Xu Zhang, and H Wang. 2012. Whispers in the Hyper-space: High-speed Covert Channel Attacks in the Cloud. In USENIX Security Symposium."},{"key":"e_1_3_3_2_253_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2017.36"},{"key":"e_1_3_3_2_254_2","unstructured":"William\u00a0K Zuravleff and Timothy Robinson. 1997. Controller for a Synchronous DRAM That Maximizes Throughput by Allowing Memory Requests and Commands to Be Issued Out of Order. U.S. Patent 5 630 096."}],"event":{"name":"MICRO 2025: 58th IEEE\/ACM International Symposium on Microarchitecture","location":"Seoul Korea","acronym":"MICRO 2025","sponsor":["SIGMICRO ACM Special Interest Group on Microarchitectural Research and Processing"]},"container-title":["Proceedings of the 58th IEEE\/ACM International Symposium on Microarchitecture"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3725843.3756029","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,26]],"date-time":"2026-01-26T21:48:02Z","timestamp":1769464082000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3725843.3756029"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,17]]},"references-count":253,"alternative-id":["10.1145\/3725843.3756029","10.1145\/3725843"],"URL":"https:\/\/doi.org\/10.1145\/3725843.3756029","relation":{},"subject":[],"published":{"date-parts":[[2025,10,17]]},"assertion":[{"value":"2025-10-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}