{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:23:01Z","timestamp":1785954181469,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":151,"publisher":"ACM","funder":[{"DOI":"10.13039\/100000028","name":"Semiconductor Research Corporation","doi-asserted-by":"publisher","award":["2025-HW-3306"],"award-info":[{"award-number":["2025-HW-3306"]}],"id":[{"id":"10.13039\/100000028","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,18]]},"DOI":"10.1145\/3725843.3756097","type":"proceedings-article","created":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T17:19:56Z","timestamp":1760721596000},"page":"308-325","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["GateBleed: Exploiting On-Core Accelerator Power Gating for High Performance and Stealthy Attacks on AI"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-3186-5069","authenticated-orcid":false,"given":"Joshua","family":"Kalyanapu","sequence":"first","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-8136-5320","authenticated-orcid":false,"given":"Farshad","family":"Dizani","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-3325-0224","authenticated-orcid":false,"given":"Darsh","family":"Asher","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4768-5663","authenticated-orcid":false,"given":"Azam","family":"Ghanbari","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2965-8987","authenticated-orcid":false,"given":"Rosario","family":"Cammarota","sequence":"additional","affiliation":[{"name":"Intel, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5530-8710","authenticated-orcid":false,"given":"Aydin","family":"Aysu","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-4997-5980","authenticated-orcid":false,"given":"Samira Mirbagher","family":"Ajorpaz","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,10,17]]},"reference":[{"key":"e_1_3_3_3_2_2","unstructured":"[n. d.]. 4th Gen Intel\u00ae Xeon\u00ae Scalable Processors. https:\/\/www.intel.com\/content\/dam\/www\/central-libraries\/us\/en\/documents\/2023-09\/4th-gen-xeon-revised-product-brief.pdf. [Accessed 01-04-2025]."},{"key":"e_1_3_3_3_3_2","unstructured":"[n. d.]. AI and compute. https:\/\/openai.com\/index\/ai-and-compute\/. [Accessed 01-04-2025]."},{"key":"e_1_3_3_3_4_2","unstructured":"[n. d.]. Getty Images (US) Inc and Others v. Stability AI Ltd [2025] EWHC 38 (Ch). https:\/\/www.judiciary.uk\/judgments\/getty-images-and-others-v-stability-ai\/ Neutral citation: [2025] EWHC 38 (Ch)."},{"key":"e_1_3_3_3_5_2","unstructured":"[n. d.]. GitHub - ggml-org\/ggml: Tensor library for machine learning \u2014 github.com. https:\/\/github.com\/ggml-org\/ggml. [Accessed 13-06-2025]."},{"key":"e_1_3_3_3_6_2","unstructured":"[n. d.]. GitHub - keras-team\/keras: Deep Learning for humans \u2014 github.com. https:\/\/github.com\/keras-team\/keras. [Accessed 12-04-2025]."},{"key":"e_1_3_3_3_7_2","unstructured":"[n. d.]. Thomson Reuters Enterprise Centre GmbH et al. v. ROSS Intelligence Inc.https:\/\/www.ded.uscourts.gov\/sites\/ded\/files\/opinions\/20-613_5.pdf Memorandum Opinion."},{"key":"e_1_3_3_3_8_2","unstructured":"2022. Feature: Align performance API timer resolution to cross-origin isolated capability. https:\/\/chromestatus.com\/feature\/6497206758539264. [Accessed 11-09-2024]."},{"key":"e_1_3_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_3_3_10_2","doi-asserted-by":"crossref","unstructured":"Hojjat Aghakhanii Dongyu Meng Yu-Xiang Wang Christopher Kruegel and Giovanni Vigna. 2021. Bullseye Polytope: A Scalable Clean-Label Poisoning Attack with Improved Transferability.","DOI":"10.1109\/EuroSP51992.2021.00021"},{"key":"e_1_3_3_3_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00085"},{"key":"e_1_3_3_3_12_2","doi-asserted-by":"crossref","unstructured":"Ayomide Akinsanya and Tegan Brennan. 2024. Timing Channels in Adaptive Neural Networks. Proceedings 2024 Network and Distributed System Security Symposium (2024). https:\/\/api.semanticscholar.org\/CorpusID:267617613","DOI":"10.14722\/ndss.2024.24125"},{"key":"e_1_3_3_3_13_2","volume-title":"Port Contention for Fun and Profit","author":"Aldaya Alejandro\u00a0Cabrera","year":"2018","unstructured":"Alejandro\u00a0Cabrera Aldaya, Billy\u00a0Bob Brumley, Sohaib ul Hassan, Cesar\u00a0Pereida Garc\u00eda, and Nicola Tuveri. 2018. Port Contention for Fun and Profit. Technical Report. Available from https:\/\/eprint.iacr.org\/2018\/1060.pdf."},{"key":"e_1_3_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2015.7056047"},{"key":"e_1_3_3_3_15_2","first-page":"515","volume-title":"28th USENIX Security Symposium (USENIX Security \u201919)","author":"Batina Lejla","year":"2019","unstructured":"Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. CSI{NN}: Reverse engineering of neural network architectures through electromagnetic side channel. In 28th USENIX Security Symposium (USENIX Security \u201919). 515\u2013532."},{"key":"e_1_3_3_3_16_2","doi-asserted-by":"crossref","unstructured":"Atri Bhattacharyya Alexandra Sandulescu Matthias Neugschwandtner Alessandro Sorniotti Babak Falsafi Mathias Payer and Anil Kurmus. 2019. SMoTherSpectre: exploiting speculative execution through port contention. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1903.01843 (2019).","DOI":"10.1145\/3319535.3363194"},{"key":"e_1_3_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00069"},{"key":"e_1_3_3_3_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363219"},{"key":"e_1_3_3_3_19_2","volume-title":"USENIX Security Symposium","author":"Canella Claudio","year":"2019","unstructured":"Claudio Canella, Jo Van\u00a0Bulck, Michael Schwarz, Moritz Lipp, Benjamin von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, and Daniel Gruss. 2019. A Systematic Evaluation of Transient Execution Attacks and Defenses. In USENIX Security Symposium."},{"key":"e_1_3_3_3_20_2","unstructured":"Nicholas Carlini Jorge Ch\u00e1vez-Saab Anna Hambitzer Francisco Rodr\u00edguez-Henr\u00edquez and Adi Shamir. 2024. Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Hard-Label Setting. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2410.05750 (2024)."},{"key":"e_1_3_3_3_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00179"},{"key":"e_1_3_3_3_22_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-56877-1_7"},{"key":"e_1_3_3_3_23_2","first-page":"1309","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Chandrasekaran Varun","year":"2020","unstructured":"Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Songbai Yan. 2020. Exploring Connections Between Active Learning and Model Extraction. In 29th USENIX Security Symposium (USENIX Security 20). USENIX Association, 1309\u20131326. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/chandrasekaran"},{"key":"e_1_3_3_3_24_2","volume-title":"USENIX Security","author":"Chen Boru","year":"2024","unstructured":"Boru Chen et\u00a0al. 2024. GoFetch: Breaking constant-time cryptographic implementations using data memory-dependent prefetchers. In USENIX Security."},{"key":"e_1_3_3_3_25_2","first-page":"1964","volume-title":"International conference on machine learning","author":"Choquette-Choo Christopher\u00a0A","year":"2021","unstructured":"Christopher\u00a0A Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In International conference on machine learning. PMLR, 1964\u20131974."},{"key":"e_1_3_3_3_26_2","volume-title":"PyTorch: An open source machine learning framework","author":"Contributors PyTorch","year":"2024","unstructured":"PyTorch Contributors. 2024. PyTorch: An open source machine learning framework. PyTorch Foundation. https:\/\/github.com\/pytorch\/pytorch Accessed: 2025-03-28."},{"key":"e_1_3_3_3_27_2","unstructured":"DeepSpeed. 2023. Mixture of Experts (MoE). https:\/\/deepspeed.readthedocs.io\/en\/latest\/moe.html."},{"key":"e_1_3_3_3_28_2","volume-title":"PyG: PyTorch Geometric \u2013 Graph Neural Network Library","author":"Developers PyG","year":"2024","unstructured":"PyG Developers. 2024. PyG: PyTorch Geometric \u2013 Graph Neural Network Library. PyG Team. https:\/\/github.com\/pyg-team\/pytorch_geometric Accessed: 2025-03-28."},{"key":"e_1_3_3_3_29_2","doi-asserted-by":"crossref","unstructured":"Ruyi Ding Tianhong Xu Xinyi Shen Aidong\u00a0Adam Ding and Yunsi Fei. 2025. MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2508.15036 (2025).","DOI":"10.1145\/3719027.3765174"},{"key":"e_1_3_3_3_30_2","doi-asserted-by":"crossref","unstructured":"Farshad Dizani Azam Ghanbari Joshua Kalyanapu Darsh Asher and Samira\u00a0Mirbagher Ajorpaz. 2025. Thor: A Non-Speculative Value Dependent Timing Side Channel Attack Exploiting Intel AMX. IEEE Computer Architecture Letters (2025).","DOI":"10.1109\/LCA.2025.3544989"},{"key":"e_1_3_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300276"},{"key":"e_1_3_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32251-9_48"},{"key":"e_1_3_3_3_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3448891.3448939"},{"key":"e_1_3_3_3_34_2","unstructured":"Vasisht Duddu Debasis Samanta D.\u00a0Vijay Rao and Valentina\u00a0E. Balas. 2018. Stealing neural networks via timing side channels. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1812.11720."},{"key":"e_1_3_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_3_3_36_2","volume-title":"Opinion 28\/2024 on certain data protection aspects related to the processing of personal data in the context of AI models","author":"Board European Data Protection","year":"2024","unstructured":"European Data Protection Board. 2024. Opinion 28\/2024 on certain data protection aspects related to the processing of personal data in the context of AI models. Opinion 28\/2024. European Data Protection Board (EDPB), Brussels, Belgium. https:\/\/www.edpb.europa.eu\/system\/files\/2024-12\/edpb_opinion_202428_ai-models_en.pdf Adopted on 17 December 2024; issued pursuant to Article 64(2) GDPR."},{"key":"e_1_3_3_3_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3173204"},{"key":"e_1_3_3_3_38_2","first-page":"83","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Garc\u00eda Cesar\u00a0Pereida","year":"2017","unstructured":"Cesar\u00a0Pereida Garc\u00eda and Billy\u00a0Bob Brumley. 2017. Constant-Time Callees with Variable-Time Callers. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, BC, 83\u201398. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/garcia"},{"key":"e_1_3_3_3_39_2","doi-asserted-by":"crossref","unstructured":"Eva Garc\u00eda-Mart\u00edn Crefeda\u00a0Faviola Rodrigues Graham Riley and H\u00e5kan Grahn. 2019. Estimation of energy consumption in machine learning. J. Parallel and Distrib. Comput. 134 (2019) 75\u201388.","DOI":"10.1016\/j.jpdc.2019.07.007"},{"key":"e_1_3_3_3_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.00027"},{"key":"e_1_3_3_3_41_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93387-0_5"},{"key":"e_1_3_3_3_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134029"},{"key":"e_1_3_3_3_43_2","volume-title":"llama.cpp: Efficient CPU inference of Meta\u2019s LLaMA model","author":"Gerganov Georgi","year":"2023","unstructured":"Georgi Gerganov and Contributors. 2023. llama.cpp: Efficient CPU inference of Meta\u2019s LLaMA model. ggerganov. https:\/\/github.com\/ggerganov\/llama.cpp Accessed: 2025-03-28."},{"key":"e_1_3_3_3_44_2","doi-asserted-by":"crossref","unstructured":"Neil\u00a0Zhenqiang Gong and Bin Liu. 2018. Attribute inference attacks in online social networks. ACM Transactions on Privacy and Security (TOPS) 21 1 (2018) 1\u201330.","DOI":"10.1145\/3154793"},{"key":"e_1_3_3_3_45_2","volume-title":"USENIX Security","author":"Gras Ben","year":"2018","unstructured":"Ben Gras, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2018. Translation leak-aside buffer: Defeating cache side-channel protections with TLB attacks. In USENIX Security."},{"key":"e_1_3_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978356"},{"key":"e_1_3_3_3_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.22"},{"key":"e_1_3_3_3_49_2","first-page":"228","volume-title":"Medical Imaging with Deep Learning","author":"Gupta Umang","year":"2021","unstructured":"Umang Gupta, Dimitris Stripelis, Pradeep\u00a0K Lam, Paul Thompson, Jose\u00a0Luis Ambite, and Greg Ver\u00a0Steeg. 2021. Membership inference attacks on deep regression models for neuroimaging. In Medical Imaging with Deep Learning. PMLR, 228\u2013251."},{"key":"e_1_3_3_3_50_2","unstructured":"Jamie Hayes Luca Melis George Danezis and Emiliano De\u00a0Cristofaro. 2017. Logan: Membership inference attacks against generative models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1705.07663 (2017)."},{"key":"e_1_3_3_3_51_2","volume-title":"USENIX Security","author":"He Yu","year":"2025","unstructured":"Yu He, Boheng Li, Liu Liu, Zhongjie Ba, Wei Dong, Yiming Li, Zhan Qin, Kui Ren, and Chun Chen. 2025. Towards label-only membership inference attack against pre-trained large language models. In USENIX Security."},{"key":"e_1_3_3_3_52_2","doi-asserted-by":"crossref","unstructured":"Benjamin Hilprecht Martin H\u00e4rterich and Daniel Bernau. 2019. Monte carlo and reconstruction membership inference attacks against generative models. Proceedings on Privacy Enhancing Technologies (2019).","DOI":"10.2478\/popets-2019-0067"},{"key":"e_1_3_3_3_53_2","unstructured":"Jann Horn. 2018. speculative execution variant 4: speculative store bypass. https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1528. Accessed: 2023-04-22."},{"key":"e_1_3_3_3_54_2","doi-asserted-by":"crossref","unstructured":"Hongsheng Hu Zoran Salcic Lichao Sun Gillian Dobbie Philip\u00a0S Yu and Xuyun Zhang. 2022. Membership inference attacks on machine learning: A survey. ACM Computing Surveys (CSUR) 54 11s (2022) 1\u201337.","DOI":"10.1145\/3523273"},{"key":"e_1_3_3_3_55_2","unstructured":"Gao Huang Danlu Chen Tianhong Li Felix Wu Laurens van\u00a0der Maaten and Kilian\u00a0Q. Weinberger. 2017. Multi-Scale Dense Networks for Resource Efficient Image Classification. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1703.09844 (2017). https:\/\/arxiv.org\/abs\/1703.09844"},{"key":"e_1_3_3_3_56_2","unstructured":"Quzhe Huang Zhenwei An Nan Zhuang Mingxu Tao Chen Zhang Yang Jin Kun Xu Liwei Chen Songfang Huang and Yansong Feng. 2024. Harder tasks need more experts: Dynamic routing in moe models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2403.07652 (2024)."},{"key":"e_1_3_3_3_57_2","volume-title":"Transformers: State-of-the-art Natural Language Processing for PyTorch and TensorFlow","author":"Inc. Hugging\u00a0Face","year":"2024","unstructured":"Hugging\u00a0Face Inc.2024. Transformers: State-of-the-art Natural Language Processing for PyTorch and TensorFlow. Hugging Face. https:\/\/github.com\/huggingface\/transformers Accessed: 2025-03-28."},{"key":"e_1_3_3_3_58_2","volume-title":"Guidance on AI and Data Protection (version 2.0.38)","author":"(ICO) Information Commissioner\u2019s Office","year":"2023","unstructured":"Information Commissioner\u2019s Office (ICO). 2023. Guidance on AI and Data Protection (version 2.0.38). Guidance. Information Commissioner\u2019s Office (UK). https:\/\/ico.org.uk\/media2\/ga4lfb5d\/guidance-on-ai-and-data-protection-all-2-0-38.pdf Updated on 15 March 2023; version 2.0.38."},{"key":"e_1_3_3_3_59_2","volume-title":"Intel Architecture Instruction Set Extensions and Future Features Programming Reference","year":"2021","unstructured":"Intel. 2021. Intel Architecture Instruction Set Extensions and Future Features Programming Reference. Available: https:\/\/www.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/architecture-instruction-set-extensions-programming-reference.pdf."},{"key":"e_1_3_3_3_60_2","unstructured":"Intel. 2023. Advanced Matrix Extensions (AMX) for AI Acceleration. Intel Corporation. https:\/\/www.intel.com\/content\/www\/us\/en\/products\/docs\/accelerator-engines\/advanced-matrix-extensions\/ai-solution-brief.html Accessed: 2023-04-12."},{"key":"e_1_3_3_3_61_2","unstructured":"Intel. 2024. Intel\u00ae 64 and IA-32 Architectures Optimization Reference Manual. https:\/\/www.intel.com\/content\/www\/us\/en\/content-details\/814198\/intel-64-and-ia-32-architectures-optimization-reference-manual-volume-1.html."},{"key":"e_1_3_3_3_62_2","unstructured":"Matthew Jagielski Nicholas Carlini David Berthelot Alex Kurakin and Nicolas Papernot. 2020. High Accuracy and High Fidelity Extraction of Neural Networks. arxiv:https:\/\/arXiv.org\/abs\/1909.01838\u00a0[cs.LG] https:\/\/arxiv.org\/abs\/1909.01838"},{"key":"e_1_3_3_3_63_2","first-page":"1895","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Jayaraman Bargav","year":"2019","unstructured":"Bargav Jayaraman and David Evans. 2019. Evaluating Differentially Private Machine Learning in Practice. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 1895\u20131912. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/jayaraman"},{"key":"e_1_3_3_3_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560663"},{"key":"e_1_3_3_3_65_2","unstructured":"Andrew Jeong. [n. d.]. Federal court says copyrighted books are fair use for AI training. https:\/\/www.washingtonpost.com\/technology\/2025\/06\/25\/ai-copyright-anthropic-books\/?utm_source=chatgpt.com. The Washington Post ([n. d.]). Accessed: 2025-09-17."},{"key":"e_1_3_3_3_66_2","unstructured":"Dhiraj Kalamkar Dheevatsa Mudigere Naveen Mellempudi Dipankar Das Kunal Banerjee Sasikanth Avancha Dharma\u00a0Teja Vooturi Nataraj Jammalamadaka Jianyu Huang Hector Yuen et\u00a0al. 2019. A study of BFLOAT16 for deep learning training. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1905.12322 (2019)."},{"key":"e_1_3_3_3_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480063"},{"key":"e_1_3_3_3_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460231.3474606"},{"key":"e_1_3_3_3_69_2","doi-asserted-by":"publisher","DOI":"10.1145\/3123939.3123972"},{"key":"e_1_3_3_3_70_2","unstructured":"Vladimir Kiriansky and Carl Waldspurger. 2018. Speculative buffer overflows: Attacks and defenses. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1807.03757 (2018)."},{"key":"e_1_3_3_3_71_2","volume-title":"ISCA","author":"Kiriansky Vladimir","year":"2018","unstructured":"Vladimir Kiriansky, Carl Waldspurger, and Joel Emer. 2018. DAWG: Defense against wayward gossip. In ISCA."},{"key":"e_1_3_3_3_72_2","doi-asserted-by":"crossref","unstructured":"Paul Kocher Jann Horn Anders Fogh Daniel Genkin Daniel Gruss Werner Haas Mike Hamburg Moritz Lipp Stefan Mangard Thomas Prescher et\u00a0al. 2020. Spectre attacks: Exploiting speculative execution. Commun. ACM 63 7 (2020) 93\u2013101.","DOI":"10.1145\/3399742"},{"key":"e_1_3_3_3_73_2","first-page":"7285","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Kogler Andreas","year":"2023","unstructured":"Andreas Kogler, Jonas Juffinger, Lukas Giner, Lukas Gerlach, Martin Schwarzl, Michael Schwarz, Daniel Gruss, and Stefan Mangard. 2023. { Collide+ Power} : Leaking Inaccessible Data with Software-based Power Side Channels. In 32nd USENIX Security Symposium (USENIX Security 23). 7285\u20137302."},{"key":"e_1_3_3_3_74_2","volume-title":"12th USENIX Workshop on Offensive Technologies (WOOT 18)","author":"Koruyeh Esmaeil\u00a0Mohammadian","year":"2018","unstructured":"Esmaeil\u00a0Mohammadian Koruyeh, Khaled\u00a0N Khasawneh, Chengyu Song, and Nael Abu-Ghazaleh. 2018. Spectre returns! speculation attacks using the return stack buffer. In 12th USENIX Workshop on Offensive Technologies (WOOT 18)."},{"key":"e_1_3_3_3_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00027"},{"key":"e_1_3_3_3_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/HOTCHIPS.2011.7477480"},{"key":"e_1_3_3_3_77_2","doi-asserted-by":"crossref","unstructured":"Rakesh Kumar Alejandro Mart\u00ednez and Antonio Gonz\u00e1lez. 2014. Efficient power gating of simd accelerators through dynamic selective devectorization in an hw\/sw codesigned environment. ACM Transactions on Architecture and Code Optimization (TACO) 11 3 (2014) 1\u201323.","DOI":"10.1145\/2629681"},{"key":"e_1_3_3_3_78_2","unstructured":"LangChain. 2023. LangChain: Build context-aware reasoning applications. https:\/\/www.langchain.com\/."},{"key":"e_1_3_3_3_79_2","first-page":"19274","volume-title":"International Conference on Machine Learning","author":"Leviathan Yaniv","year":"2023","unstructured":"Yaniv Leviathan, Matan Kalman, and Yossi Matias. 2023. Fast inference from transformers via speculative decoding. In International Conference on Machine Learning. PMLR, 19274\u201319286."},{"key":"e_1_3_3_3_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559359"},{"key":"e_1_3_3_3_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"e_1_3_3_3_82_2","first-page":"643","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Lipp Moritz","year":"2022","unstructured":"Moritz Lipp, Daniel Gruss, and Michael Schwarz. 2022. { AMD} prefetch attacks through power and time. In 31st USENIX Security Symposium (USENIX Security 22). 643\u2013660."},{"key":"e_1_3_3_3_83_2","doi-asserted-by":"publisher","unstructured":"Moritz Lipp Andreas Kogler David Oswald Michael Schwarz Catherine Easdon Claudio Canella and Daniel Gruss. 2021. PLATYPUS: Software-based Power Side-Channel Attacks on x86. 355\u2013371. 10.1109\/SP40001.2021.00063","DOI":"10.1109\/SP40001.2021.00063"},{"key":"e_1_3_3_3_84_2","doi-asserted-by":"crossref","unstructured":"Moritz Lipp Michael Schwarz Daniel Gruss Thomas Prescher Werner Haas Jann Horn Stefan Mangard Paul Kocher Daniel Genkin Yuval Yarom et\u00a0al. 2020. Meltdown: Reading kernel memory from user space. Commun. ACM 63 6 (2020) 46\u201356.","DOI":"10.1145\/3357033"},{"key":"e_1_3_3_3_85_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560682"},{"key":"e_1_3_3_3_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_3_3_87_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484749"},{"key":"e_1_3_3_3_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2019.00056"},{"key":"e_1_3_3_3_89_2","doi-asserted-by":"publisher","DOI":"10.1145\/3097983.3098011"},{"key":"e_1_3_3_3_90_2","doi-asserted-by":"publisher","DOI":"10.1145\/1594233.1594331"},{"key":"e_1_3_3_3_91_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243761"},{"key":"e_1_3_3_3_92_2","unstructured":"Ross Mcilroy Jaroslav Sevcik Tobias Tebbi Ben\u00a0L. Titzer and Toon Verwaest. 2019. Spectre is here to stay: An analysis of side-channels and speculative execution. https:\/\/arxiv.org\/abs\/1902.05178"},{"key":"e_1_3_3_3_93_2","first-page":"4579","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Mehnaz Shagufta","year":"2022","unstructured":"Shagufta Mehnaz, Sayanton\u00a0V Dibbo, Ehsanul Kabir, Ninghui Li, and Elisa Bertino. 2022. Are your sensitive attributes private? novel model inversion attribute inference attacks on classification models. In 31st USENIX Security Symposium (USENIX Security 22). 4579\u20134596."},{"key":"e_1_3_3_3_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00093"},{"key":"e_1_3_3_3_95_2","first-page":"7179","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Moghimi Daniel","year":"2023","unstructured":"Daniel Moghimi. 2023. Downfall: Exploiting speculative data gathering. In 32nd USENIX Security Symposium (USENIX Security 23). 7179\u20137193."},{"key":"e_1_3_3_3_96_2","volume-title":"USENIX Security Symposium","author":"Moghimi Daniel","year":"2020","unstructured":"Daniel Moghimi, Moritz Lipp, Berk Sunar, and Michael Schwarz. 2020. Medusa: Microarchitectural Data Leakage via Automated Attack Synthesis. In USENIX Security Symposium."},{"key":"e_1_3_3_3_97_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSCC49657.2024.10454434"},{"key":"e_1_3_3_3_98_2","unstructured":"Sasi\u00a0Kumar Murakonda and Reza Shokri. 2020. Ml privacy meter: Aiding regulatory compliance by quantifying the privacy risks of machine learning. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2007.09339 (2020)."},{"key":"e_1_3_3_3_99_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSCC42614.2022.9731107"},{"key":"e_1_3_3_3_100_2","unstructured":"OpenAI. 2023. Function calling - OpenAI API. https:\/\/platform.openai.com\/docs\/guides\/gpt\/function-calling."},{"key":"e_1_3_3_3_101_2","unstructured":"Tribhuvanesh Orekondy Bernt Schiele and Mario Fritz. 2018. Knockoff Nets: Stealing Functionality of Black-Box Models. CoRR abs\/1812.02766 (2018). arXiv:https:\/\/arXiv.org\/abs\/1812.02766http:\/\/arxiv.org\/abs\/1812.02766"},{"key":"e_1_3_3_3_102_2","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_3_3_103_2","unstructured":"Nicolas Papernot Patrick Mcdaniel and Ian\u00a0J. Goodfellow. 2016. Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples. ArXiv abs\/1605.07277 (2016). https:\/\/api.semanticscholar.org\/CorpusID:17362994"},{"key":"e_1_3_3_3_104_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00020"},{"key":"e_1_3_3_3_105_2","unstructured":"Shadi Rahimian Tribhuvanesh Orekondy and Mario Fritz. 2020. Sampling attacks: Amplification of membership inference attacks by repeated queries. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2009.00395 (2020)."},{"key":"e_1_3_3_3_106_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24078"},{"key":"e_1_3_3_3_107_2","doi-asserted-by":"publisher","DOI":"10.1145\/3470496.3527429"},{"key":"e_1_3_3_3_108_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA52012.2021.00036"},{"key":"e_1_3_3_3_109_2","unstructured":"Reuters. [n. d.]. Apple sued by authors over use of books in AI training. https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/apple-sued-by-authors-over-use-books-ai-training-2025-09-05\/. Reuters ([n. d.]). Accessed: 2025-09-17."},{"key":"e_1_3_3_3_110_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00062"},{"key":"e_1_3_3_3_111_2","unstructured":"ONNX Runtime. 2023. Generate API (Preview). https:\/\/onnxruntime.ai\/docs\/genai\/."},{"key":"e_1_3_3_3_112_2","unstructured":"ONNX Runtime. 2023. Mixture of Experts (MoE) \u2014 DeepSpeed 0.16.6 documentation. https:\/\/deepspeed.readthedocs.io\/en\/latest\/moe.html."},{"key":"e_1_3_3_3_113_2","doi-asserted-by":"crossref","unstructured":"Ahmed Salem Yang Zhang Mathias Humbert Pascal Berrang Mario Fritz and Michael Backes. 2018. ML-Leaks: Model and data independent membership inference attacks and defenses on machine learning models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1806.01246.","DOI":"10.14722\/ndss.2019.23119"},{"key":"e_1_3_3_3_114_2","doi-asserted-by":"publisher","DOI":"10.1145\/2995306.2995307"},{"key":"e_1_3_3_3_115_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354252"},{"key":"e_1_3_3_3_116_2","unstructured":"Michael Schwarz Martin Schwarzl Moritz Lipp and Daniel Gruss. 2018. Netspectre: Read arbitrary memory over network. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1807.10535 (2018)."},{"key":"e_1_3_3_3_117_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_3_3_118_2","doi-asserted-by":"crossref","unstructured":"Dimitrios Skarlatos Mengjia Yan Bhargava Gopireddy Read Sprabery Josep Torrellas and Christopher\u00a0W. Fletcher. 2020. MicroScope: Enabling Microarchitectural Replay Attacks. IEEE Micro (2020).","DOI":"10.1109\/MM.2020.2986204"},{"key":"e_1_3_3_3_119_2","volume-title":"USENIX Security Symposium","author":"Tatar Andrei","year":"2022","unstructured":"Andrei Tatar, Dani\u00ebl Trujillo, Cristiano Giuffrida, and Herbert Bos. 2022. TLB;DR: Enhancing TLB-based Attacks with TLB Desynchronized Reverse Engineering. In USENIX Security Symposium."},{"key":"e_1_3_3_3_120_2","volume-title":"TensorFlow: An end-to-end open source machine learning platform","author":"Team Google\u00a0Brain","year":"2024","unstructured":"Google\u00a0Brain Team and TensorFlow Contributors. 2024. TensorFlow: An end-to-end open source machine learning platform. Google. https:\/\/github.com\/tensorflow\/tensorflow Accessed: 2025-03-28."},{"key":"e_1_3_3_3_121_2","volume-title":"AutoGen: Enabling Next-Gen LLM Applications with Multi-Agent Collaboration","author":"Team Microsoft\u00a0AutoGen","year":"2024","unstructured":"Microsoft\u00a0AutoGen Team. 2024. AutoGen: Enabling Next-Gen LLM Applications with Multi-Agent Collaboration. Microsoft. https:\/\/github.com\/microsoft\/autogen Accessed: 2025-03-28."},{"key":"e_1_3_3_3_122_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.2016.7900006"},{"key":"e_1_3_3_3_123_2","unstructured":"Florian Tram\u00e8r Fan Zhang Ari Juels Michael\u00a0K. Reiter and Thomas Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. CoRR abs\/1609.02943 (2016). arXiv:https:\/\/arXiv.org\/abs\/1609.02943http:\/\/arxiv.org\/abs\/1609.02943"},{"key":"e_1_3_3_3_124_2","doi-asserted-by":"crossref","unstructured":"Ekaterina Trimbach Badr Abdallaoui and Paul Missault. 2025. Cost-efficiency trade-offs for neural cascade rankers in web search. (2025). https:\/\/www.amazon.science\/publications\/cost-efficiency-trade-offs-for-neural-cascade-rankers-in-web-search","DOI":"10.1145\/3701716.3717577"},{"key":"e_1_3_3_3_125_2","unstructured":"P. Turner. 2018. Retpoline: a software construct for preventing branch-target-injection. https:\/\/support.google.com\/faqs\/answer\/7625886."},{"key":"e_1_3_3_3_126_2","first-page":"991","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Van\u00a0Bulck Jo","year":"2018","unstructured":"Jo Van\u00a0Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas\u00a0F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. In 27th USENIX Security Symposium (USENIX Security 18). 991\u20131008."},{"key":"e_1_3_3_3_127_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00089"},{"key":"e_1_3_3_3_128_2","volume-title":"S&P","author":"Schaik Stephan van","year":"2019","unstructured":"Stephan van Schaik, Alyssa Milburn, Sebastian \u00d6sterlund, Pietro Frigo, Giorgi Maisuradze, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2019. RIDL: Rogue In-flight Data Load. In S&P."},{"key":"e_1_3_3_3_129_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSCC49661.2025.10904676"},{"key":"e_1_3_3_3_130_2","doi-asserted-by":"crossref","unstructured":"Michael Veale Reuben Binns and Lilian Edwards. 2018. Algorithms that remember: model inversion attacks and data protection law. Philosophical Transactions of the Royal Society A: Mathematical Physical and Engineering Sciences 376 2133 (2018) 20180083.","DOI":"10.1098\/rsta.2018.0083"},{"key":"e_1_3_3_3_131_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833570"},{"key":"e_1_3_3_3_132_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA52012.2021.00035"},{"key":"e_1_3_3_3_133_2","unstructured":"An Wang Xingwu Sun Ruobing Xie Shuaipeng Li Jiaqi Zhu Zhen Yang Pinxue Zhao JN Han Zhanhui Kang Di Wang et\u00a0al. 2024. Hmoe: Heterogeneous mixture of experts for language modeling. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2408.10681 (2024)."},{"key":"e_1_3_3_3_134_2","unstructured":"Binghui Wang and Neil\u00a0Zhenqiang Gong. 2018. Stealing Hyperparameters in Machine Learning. CoRR abs\/1802.05351 (2018). arXiv:https:\/\/arXiv.org\/abs\/1802.05351http:\/\/arxiv.org\/abs\/1802.05351"},{"key":"e_1_3_3_3_135_2","doi-asserted-by":"crossref","unstructured":"Po-Han Wang Chia-Lin Yang Yen-Ming Chen and Yu-Jung Cheng. 2011. Power gating strategies on GPUs. ACM Transactions on Architecture and Code Optimization (TACO) 8 3 (2011) 1\u201325.","DOI":"10.1145\/2019608.2019612"},{"key":"e_1_3_3_3_136_2","volume-title":"USENIX Security","author":"Wang Yu","year":"2022","unstructured":"Yu Wang et\u00a0al. 2022. Hertzbleed: Turning power side-channel attacks into remote timing attacks on x86. In USENIX Security."},{"key":"e_1_3_3_3_137_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179326"},{"key":"e_1_3_3_3_138_2","unstructured":"Yiding Wang Fisher Yu Zi-Yi Dou Trevor Darrell and Joseph\u00a0E. Gonzalez. 2017. SkipNet: Learning Dynamic Routing in Convolutional Networks. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1711.09485 (2017). https:\/\/arxiv.org\/abs\/1711.09485"},{"key":"e_1_3_3_3_139_2","volume-title":"USENIX Security Symposium","author":"Weber Daniel","year":"2021","unstructured":"Daniel Weber, Ahmad Ibrahim, Hamed Nemati, Michael Schwarz, and Christian Rossow. 2021. Osiris: Automated Discovery of Microarchitectural Side Channels. In USENIX Security Symposium."},{"key":"e_1_3_3_3_140_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274696"},{"key":"e_1_3_3_3_141_2","volume-title":"High Resolution Time (Working Draft)","author":"Weiss Yoav","year":"2024","unstructured":"Yoav Weiss and W3C Web Performance\u00a0Working Group. 2024. High Resolution Time (Working Draft). Working Draft. World Wide Web Consortium (W3C). https:\/\/www.w3.org\/TR\/hr-time-3\/ Accessed: 2025-09-22."},{"key":"e_1_3_3_3_142_2","volume-title":"Workshop On Offensive Technologies (WOOT)","author":"Wikner Johannes","year":"2022","unstructured":"Johannes Wikner, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. 2022. Spring: Spectre returning in the browser with speculative load queuing and deep stacks. In Workshop On Offensive Technologies (WOOT)."},{"key":"e_1_3_3_3_143_2","doi-asserted-by":"publisher","DOI":"10.1145\/3613424.3614275"},{"key":"e_1_3_3_3_144_2","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575700"},{"key":"e_1_3_3_3_145_2","first-page":"2003","volume-title":"29th USENIX Security Symposium (USENIX Security \u201920)","author":"Yan Mengjia","year":"2020","unstructured":"Mengjia Yan, Christopher\u00a0W. Fletcher, and Josep Torrellas. 2020. Cache telepathy: Leveraging shared resource attacks to learn DNN architectures. In 29th USENIX Security Symposium (USENIX Security \u201920). 2003\u20132020."},{"key":"e_1_3_3_3_146_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00004"},{"key":"e_1_3_3_3_147_2","series-title":"(SEC\u201914)","first-page":"719","volume-title":"Proceedings of the 23rd USENIX Conference on Security Symposium","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner. 2014. FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. In Proceedings of the 23rd USENIX Conference on Security Symposium (San Diego, CA) (SEC\u201914). USENIX Association, USA, 719\u2013732."},{"key":"e_1_3_3_3_148_2","doi-asserted-by":"crossref","unstructured":"Yuval Yarom Daniel Genkin and Nadia Heninger. 2016. CacheBleed: a timing attack on OpenSSL constant-time RSA. Journal of Cryptographic Engineering 7 (2016) 99 \u2013 112. https:\/\/api.semanticscholar.org\/CorpusID:7895014","DOI":"10.1007\/s13389-017-0152-y"},{"key":"e_1_3_3_3_149_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"e_1_3_3_3_150_2","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382230"},{"key":"e_1_3_3_3_151_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00025"},{"key":"e_1_3_3_3_152_2","volume-title":"USENIX Security","author":"Zhao Zirui\u00a0Neil","year":"2022","unstructured":"Zirui\u00a0Neil Zhao, Adam Morrison, Christopher\u00a0W Fletcher, and Josep Torrellas. 2022. Binoculars: Contention-based side-channel attacks exploiting the page walker. In USENIX Security."}],"event":{"name":"MICRO 2025: 58th IEEE\/ACM International Symposium on Microarchitecture","location":"Seoul Korea","acronym":"MICRO 2025","sponsor":["SIGMICRO ACM Special Interest Group on Microarchitectural Research and Processing"]},"container-title":["Proceedings of the 58th IEEE\/ACM International Symposium on Microarchitecture"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3725843.3756097","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,26]],"date-time":"2026-01-26T21:45:18Z","timestamp":1769463918000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3725843.3756097"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,17]]},"references-count":151,"alternative-id":["10.1145\/3725843.3756097","10.1145\/3725843"],"URL":"https:\/\/doi.org\/10.1145\/3725843.3756097","relation":{},"subject":[],"published":{"date-parts":[[2025,10,17]]},"assertion":[{"value":"2025-10-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}