{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T08:03:30Z","timestamp":1776931410264,"version":"3.51.2"},"publisher-location":"New York, NY, USA","reference-count":65,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,18]]},"DOI":"10.1145\/3725843.3756058","type":"proceedings-article","created":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T17:21:19Z","timestamp":1760721679000},"page":"94-110","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["One Flew over the Stack Engine\u2019s Nest: Practical Microarchitectural Attacks on the Stack Engine"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-2142-7728","authenticated-orcid":false,"given":"Silvan","family":"Niederer","sequence":"first","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-8004-740X","authenticated-orcid":false,"given":"Sandro","family":"R\u00fcegge","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3219-7544","authenticated-orcid":false,"given":"Ali","family":"Hajiabadi","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8588-7100","authenticated-orcid":false,"given":"Kaveh","family":"Razavi","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,17]]},"reference":[{"key":"e_1_3_3_2_2_2","volume-title":"Revision Guide for AMD Family 10h Processors (Including Errata #721)","author":"Inc. Advanced Micro Devices,","year":"2012","unstructured":"Advanced Micro Devices, Inc.2012. Revision Guide for AMD Family 10h Processors (Including Errata #721). Revision Guide (order #41322) Rev. 3.92. Advanced Micro Devices. https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/archived-tech-docs\/revision-guides\/41322_10h_Rev_Gd.pdf accessed 2025-08-01."},{"key":"e_1_3_3_2_3_2","volume-title":"AMD64 Architecture Programmer\u2019s Manual: Volume 5 - 64-Bit Media and x87 Floating-Point Instructions","author":"Inc. Advanced Micro Devices,","year":"2025","unstructured":"Advanced Micro Devices, Inc.2025. AMD64 Architecture Programmer\u2019s Manual: Volume 5 - 64-Bit Media and x87 Floating-Point Instructions. https:\/\/www.amd.com\/en\/search\/documentation\/hub.html Document Number: 58455."},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00066"},{"key":"e_1_3_3_2_5_2","volume-title":"USENIX Security","author":"Almeida Jos\u00e9\u00a0Bacelar","year":"2016","unstructured":"Jos\u00e9\u00a0Bacelar Almeida, Manuel Barbosa, Gilles Barthe, Fran\u00e7ois Dupressoir, and Michael Emmi. 2016. Verifying Constant-Time Implementations. In USENIX Security."},{"key":"e_1_3_3_2_6_2","unstructured":"AMD. 2025. AMD-SB-7045: Microarchitectural Attacks on the Stack Engine. https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7045.html accessed 2025-08-08."},{"key":"e_1_3_3_2_7_2","volume-title":"JMIR medical informatics","author":"Ayaz Muhammad","year":"2021","unstructured":"Muhammad Ayaz, Muhammad\u00a0F Pasha, Mohammed\u00a0Y Alzahrani, Rahmat Budiarto, and Deris Stiawan. 2021. The Fast Health Interoperability Resources (FHIR) standard: systematic literature review of implementations, applications, challenges and opportunities. In JMIR medical informatics."},{"key":"e_1_3_3_2_8_2","volume-title":"USENIX Security","author":"Barberis Enrico","year":"2022","unstructured":"Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano Giuffrida. 2022. Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 Attacks. In USENIX Security."},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/339647.339705"},{"key":"e_1_3_3_2_10_2","unstructured":"Dave Benson and protobuf-c contributors. 2025. protobuf-c: Protocol Buffers implementation in C. https:\/\/github.com\/protobuf-c\/protobuf-c Version 1.0+ accessed 2025-08-01."},{"key":"e_1_3_3_2_11_2","volume-title":"Speculative load hardening","author":"Carruth Chandler","year":"2018","unstructured":"Chandler Carruth. 2018. Speculative load hardening. https:\/\/llvm.org\/docs\/SpeculativeLoadHardening.html accessed 2025-08-06."},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00024"},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA57654.2024.00013"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA57654.2024.00037"},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA53966.2022.00013"},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3173204"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.5772\/intechopen.1004810"},{"key":"e_1_3_3_2_19_2","volume-title":"The microarchitecture of Intel, AMD and VIA CPUs","author":"Fog Agner","year":"2024","unstructured":"Agner Fog. 2024. The microarchitecture of Intel, AMD and VIA CPUs. https:\/\/www.agner.org\/optimize\/microarchitecture.pdf accessed 2025-06-10."},{"key":"e_1_3_3_2_20_2","unstructured":"Dave Gamble and contributors. 2025. cJSON - Ultralightweight JSON parser in C. https:\/\/github.com\/DaveGamble\/cJSON. accessed 2025-04-10."},{"key":"e_1_3_3_2_21_2","unstructured":"GNU Project. 2022. glibc 2.35 Source Code: string\/strtok_r.c. https:\/\/elixir.bootlin.com\/glibc\/glibc-2.35\/source\/string\/strtok_r.c#L28 accessed 2025-04-08."},{"key":"e_1_3_3_2_22_2","unstructured":"Simcha Gochman Ronny Ronen Ittai Anati Ariel Berkovits Tsvika Kurts Alon Naveh Ali Saeed Zeev Sperber and Robert\u00a0C Valentine. 2003. The Intel\u00ae Pentium\u00ae M Processor: Microarchitecture and Performance.Intel technology journal (2003)."},{"key":"e_1_3_3_2_23_2","unstructured":"Google. 2025. Protocol Buffers. https:\/\/github.com\/protocolbuffers\/protobuf Version 3.0+ accessed 2025-08-01."},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23018"},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3649329.3655895"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.46586\/uasc.2025.004"},{"key":"e_1_3_3_2_27_2","unstructured":"Intel. 2022. Guidelines for Mitigating Timing Side Channels Against Cryptographic Implementations. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/secure-coding\/mitigate-timing-side-channel-crypto- implementation.htmlaccessed 2025-09-03."},{"key":"e_1_3_3_2_28_2","volume-title":"Intel\u00ae 64 and IA-32 Architectures Optimization Reference Manual","author":"Corporation Intel","year":"2025","unstructured":"Intel Corporation. 2025. Intel\u00ae 64 and IA-32 Architectures Optimization Reference Manual. https:\/\/cdrdv2-public.intel.com\/814198\/248966-046A-software-optimization-manual.pdf Document Number: 248966-046A."},{"key":"e_1_3_3_2_29_2","volume-title":"USENIX Security","author":"Kim Jason","year":"2025","unstructured":"Jason Kim, Jalen Chuang, Daniel Genkin, and Yuval Yarom. 2025. FLOP: Breaking the Apple M3 CPU via False Load Output Predictions. In USENIX Security."},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00098"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480079"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00027"},{"key":"e_1_3_3_2_34_2","volume-title":"USENIX ATC","author":"Kotni Swaroop","year":"2021","unstructured":"Swaroop Kotni, Ajay Nayak, Vinod Ganapathy, and Arkaprava Basu. 2021. Faastlane: Accelerating Function-as-a-Service Workflows. In USENIX ATC."},{"key":"e_1_3_3_2_35_2","volume-title":"USENIX Security","author":"Lee Sangho","year":"2017","unstructured":"Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring fine-grained control flow inside SGX enclaves with branch shadowing. In USENIX Security."},{"key":"e_1_3_3_2_36_2","volume-title":"USENIX Security","author":"Li Luyi","year":"2024","unstructured":"Luyi Li, Hosein Yavarzadeh, and Dean Tullsen. 2024. Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch Predictor. In USENIX Security."},{"key":"e_1_3_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3581784.3613211"},{"key":"e_1_3_3_2_38_2","volume-title":"USENIX Security","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading kernel memory from user space. In USENIX Security."},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694385"},{"key":"e_1_3_3_2_40_2","volume-title":"System V Application Binary Interface AMD64 Architecture Processor Supplement","author":"Lu H.J.","year":"2025","unstructured":"H.J. Lu, Michael Matz, Milind Girkar, Jan Hubi\u010dka, Andreas Jaeger, and Mark Mitchell. 2025. System V Application Binary Interface AMD64 Architecture Processor Supplement."},{"key":"e_1_3_3_2_41_2","volume-title":"WOOT","author":"Mambretti Andrea","year":"2019","unstructured":"Andrea Mambretti, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti, and Anil Kurmus. 2019. Two methods for exploiting speculative control flow hijacks. In WOOT."},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00046"},{"key":"e_1_3_3_2_43_2","volume-title":"Zen 5: AMD\u2019s most innovative core since the original Zen \u2013 analysis","author":"Ol\u0161an Jan","year":"2024","unstructured":"Jan Ol\u0161an. 2024. Zen 5: AMD\u2019s most innovative core since the original Zen \u2013 analysis. https:\/\/www.hwcooling.net\/en\/zen-5-amds-most-innovative-core-since-the-original-zen-analysis\/ Accessed: 2025-04-12."},{"key":"e_1_3_3_2_44_2","volume-title":"USENIX Security","author":"Puddu Ivan","year":"2021","unstructured":"Ivan Puddu, Moritz Schneider, Miro Haller, and Srdjan \u010capkun. 2021. Frontal attack: Leaking Control-Flow in SGX via the CPU frontend. In USENIX Security."},{"key":"e_1_3_3_2_45_2","volume-title":"USENIX Security","author":"Ragab Hany","year":"2021","unstructured":"Hany Ragab, Enrico Barberis, Herbert Bos, and Cristiano Giuffrida. 2021. Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution Attacks. In USENIX Security."},{"key":"e_1_3_3_2_46_2","unstructured":"Red Hat Inc.2024. Potential Dragonfly Issue with some older AMD processors. https:\/\/access.redhat.com\/solutions\/188273 Solution Verified; last updated August 6 2024 accessed 2025-08-01."},{"key":"e_1_3_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA52012.2021.00036"},{"key":"e_1_3_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358296"},{"key":"e_1_3_3_2_49_2","unstructured":"SPEC2017 2017. SPEC CPU2017. https:\/\/www.spec.org\/cpu2017\/."},{"key":"e_1_3_3_2_50_2","volume-title":"USENIX Security","author":"Taram Mohammadkazem","year":"2022","unstructured":"Mohammadkazem Taram, Xida Ren, Ashish Venkat, and Dean Tullsen. 2022. SecSMT: Securing SMT processors against Contention-Based covert channels. In USENIX Security."},{"key":"e_1_3_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/PACT.2019.00012"},{"key":"e_1_3_3_2_52_2","volume-title":"USENIX Security","author":"Trujillo Dani\u00ebl","year":"2023","unstructured":"Dani\u00ebl Trujillo, Johannes Wikner, and Kaveh Razavi. 2023. Inception: Exposing New Attack Surfaces with Training in Transient Execution. In USENIX Security."},{"key":"e_1_3_3_2_53_2","volume-title":"USENIX Security","author":"Vahldiek-Oberwagner Anjo","year":"2019","unstructured":"Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno\u00a0O. Duarte, Michael Sammler, Peter Druschel, and Deepak Garg. 2019. ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK). In USENIX Security."},{"key":"e_1_3_3_2_54_2","volume-title":"USENIX Security","author":"Wiebing Sander","year":"2024","unstructured":"Sander Wiebing, Alvise de Faveri\u00a0Tron, Herbert Bos, and Cristiano Giuffrida. 2024. InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2. In USENIX Security."},{"key":"e_1_3_3_2_55_2","volume-title":"USENIX Security","author":"Wikner Johannes","year":"2022","unstructured":"Johannes Wikner and Kaveh Razavi. 2022. RETBLEED: Arbitrary Speculative Code Execution with Return Instructions. In USENIX Security."},{"key":"e_1_3_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00089"},{"key":"e_1_3_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3613424.3614275"},{"key":"e_1_3_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690319"},{"key":"e_1_3_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2014.6853201"},{"key":"e_1_3_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00080"},{"key":"e_1_3_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1145\/3620666.3651382"},{"key":"e_1_3_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179415"},{"key":"e_1_3_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/3689031.3717490"},{"key":"e_1_3_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589100"},{"key":"e_1_3_3_2_65_2","volume-title":"USENIX Security","author":"Zhang Zhiyuan","year":"2023","unstructured":"Zhiyuan Zhang, Gilles Barthe, Chitchanok Chuengsatiansup, Peter Schwabe, and Yuval Yarom. 2023. Ultimate SLH: Taking Speculative Load Hardening to the Next Level. In USENIX Security."},{"key":"e_1_3_3_2_66_2","volume-title":"Fourth Workshop on Computer Architecture Research with RISC-V","author":"Zhao Jerry","year":"2020","unstructured":"Jerry Zhao, Ben Korpan, Abraham Gonzalez, and Krste Asanovic. 2020. SonicBOOM: The 3rd Generation Berkeley Out-of-Order Machine. In Fourth Workshop on Computer Architecture Research with RISC-V."}],"event":{"name":"MICRO 2025: 58th IEEE\/ACM International Symposium on Microarchitecture","location":"Seoul Korea","acronym":"MICRO 2025","sponsor":["SIGMICRO ACM Special Interest Group on Microarchitectural Research and Processing"]},"container-title":["Proceedings of the 58th IEEE\/ACM International Symposium on Microarchitecture"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3725843.3756058","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,26]],"date-time":"2026-01-26T21:48:44Z","timestamp":1769464124000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3725843.3756058"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,17]]},"references-count":65,"alternative-id":["10.1145\/3725843.3756058","10.1145\/3725843"],"URL":"https:\/\/doi.org\/10.1145\/3725843.3756058","relation":{},"subject":[],"published":{"date-parts":[[2025,10,17]]},"assertion":[{"value":"2025-10-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}