{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,30]],"date-time":"2026-08-30T03:03:47Z","timestamp":1788059027727,"version":"build-2784847793"},"reference-count":169,"publisher":"Association for Computing Machinery (ACM)","issue":"11","funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Korean government","award":["2023R1A2C2006862"],"award-info":[{"award-number":["2023R1A2C2006862"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,11,30]]},"abstract":"<jats:p>The CPU architecture landscape is constantly evolving to optimize performance. However, this has inadvertently exposed vulnerabilities such as microarchitectural traces that can be exploited in side-channel attacks. The Branch Prediction Unit (BPU) plays a critical role in improving processor performance, but also introduces vulnerabilities to microarchitectural side-channel attacks. Despite ongoing efforts to develop defensive techniques, the continued emergence of new attack methods underscores the need for comprehensive analysis. This article aims to address this research gap by conducting a thorough investigation of BPU-based side-channel attacks. This survey presents a novel taxonomy for the systematic classification of BPU-based side-channel attacks and defenses. The attacks and defenses are categorized based on three components: manipulated unit, core technique, and disclosure method. The analysis provides a structured evaluation of the effectiveness of defense techniques against each attack technique. This study not only enhances the understanding of BPU exploitation, but also provides valuable insights for software developers and CPU designers to help them protect against evolving side-channel threats.<\/jats:p>","DOI":"10.1145\/3734218","type":"journal-article","created":{"date-parts":[[2025,5,5]],"date-time":"2025-05-05T11:29:37Z","timestamp":1746444577000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["A Survey of Side-Channel Attacks on Branch Prediction Units"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4427-3997","authenticated-orcid":false,"given":"Jihoon","family":"Kim","sequence":"first","affiliation":[{"name":"Korea University, Seongbuk-gu, Korea (the Republic of)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4100-9338","authenticated-orcid":false,"given":"Hyerean","family":"Jang","sequence":"additional","affiliation":[{"name":"Korea University, Seongbuk-gu, Korea (the Republic of)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4831-7392","authenticated-orcid":false,"given":"Youngjoo","family":"Shin","sequence":"additional","affiliation":[{"name":"Korea University, Seongbuk-gu, Korea (the Republic of)"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,14]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.5555\/1782574.1782591"},{"key":"e_1_3_1_3_2","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1007\/11967668_15","volume-title":"Proceedings of the Cryptographers\u2019 Track at the RSA Conference on Topics in Cryptology\u2013CT-RSA 2007","author":"Ac\u0131i\u00e7mez Onur","year":"2006","unstructured":"Onur Ac\u0131i\u00e7mez, \u00c7etin Kaya Ko\u00e7, and Jean-Pierre Seifert. 2006. Predicting secret keys via branch prediction. In Proceedings of the Cryptographers\u2019 Track at the RSA Conference on Topics in Cryptology\u2013CT-RSA 2007. Springer, 225\u2013242."},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1266999"},{"key":"e_1_3_1_5_2","unstructured":"Mahya Morid Ahmadi Faiq Khalid and Muhammad Shafique. 2021. Side-channel attacks on RISC-V processors: Current progress challenges and opportunities. arXiv:2106.08877. Retrieved from https:\/\/arxiv.org\/abs\/2106.08877"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480074"},{"key":"e_1_3_1_7_2","first-page":"132","volume-title":"Proceedings of the 2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA\u201920)","author":"Ainsworth Sam","year":"2020","unstructured":"Sam Ainsworth and Timothy M. Jones. 2020. Muontrap: Preventing cross-domain spectre-like attacks by capturing speculative state. In Proceedings of the 2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA\u201920). IEEE, 132\u2013144."},{"key":"e_1_3_1_8_2","first-page":"53","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916)","author":"Almeida Jos\u00e9 Bacelar","year":"2016","unstructured":"Jos\u00e9 Bacelar Almeida, Manuel Barbosa, Gilles Barthe, Fran\u00e7ois Dupressoir, and Michael Emmi. 2016. Verifying \\(\\lbrace\\) Constant-Time \\(\\rbrace\\) implementations. In Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916). 53\u201370. Retrieved from https:\/\/github.com\/imdea-software\/verifying-constant-time"},{"key":"e_1_3_1_9_2","volume-title":"AMD64 Technology Indirect Branch Control Extension","year":"2018","unstructured":"AMD. 2018. AMD64 Technology Indirect Branch Control Extension. Retrieved November 2023 from https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/processor-tech-docs\/white-papers\/111006-architecture-guidelines-update-amd64-technology-indirect-branch-control-extension.pdf"},{"key":"e_1_3_1_10_2","volume-title":"Technical Guidance for Mitigating Branchtype Confusion","year":"2022","unstructured":"AMD. 2022. Technical Guidance for Mitigating Branchtype Confusion. Retrieved December 2023 from https:\/\/www.amd.com\/system\/files\/documents\/technical-guidance-for-mitigating-branch-type-confusion.pdf"},{"key":"e_1_3_1_11_2","volume-title":"Software Techniques for Managing Speculation on AMD Processors","year":"2023","unstructured":"AMD. 2023. Software Techniques for Managing Speculation on AMD Processors. Retrieved November 2023 from https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/epyc-technical-docs\/tuning-guides\/software-techniques-for-managing-speculation.pdf"},{"key":"e_1_3_1_12_2","first-page":"285","volume-title":"Proceedings of the 2019 USENIX Annual Technical Conference (USENIX ATC\u201919)","author":"Amit Nadav","year":"2019","unstructured":"Nadav Amit, Fred Jacobs, and Michael Wei. 2019. JumpSwitches: Restoring the performance of indirect branches in the era of spectre. In Proceedings of the 2019 USENIX Annual Technical Conference (USENIX ATC\u201919). 285\u2013300."},{"key":"e_1_3_1_13_2","volume-title":"Cache Speculation Side Channels v2.5","year":"2020","unstructured":"ARM. 2020. Cache Speculation Side Channels v2.5. Retrieved January 2024 from https:\/\/developer.arm.com\/documentation\/102816\/latest\/"},{"key":"e_1_3_1_14_2","volume-title":"Spectre-BHB: Speculative Target Reuse Attacks","year":"2022","unstructured":"ARM. 2022. Spectre-BHB: Speculative Target Reuse Attacks. Retrieved December 2023 from https:\/\/developer.arm.com\/documentation\/102898\/0107"},{"key":"e_1_3_1_15_2","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1109\/PACT.2019.00020","volume-title":"Proceedings of the 2019 28th International Conference on Parallel Architectures and Compilation Techniques (PACT\u201919)","author":"Barber Kristin","year":"2019","unstructured":"Kristin Barber, Anys Bacha, Li Zhou, Yinqian Zhang, and Radu Teodorescu. 2019. Specshield: Shielding speculative data from microarchitectural covert channels. In Proceedings of the 2019 28th International Conference on Parallel Architectures and Compilation Techniques (PACT\u201919). IEEE, 151\u2013164."},{"key":"e_1_3_1_16_2","first-page":"971","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922)","author":"Barberis Enrico","year":"2022","unstructured":"Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano Giuffrida. 2022. Branch history injection: On the effectiveness of hardware mitigations against \\(\\lbrace\\) Cross-Privilege \\(\\rbrace\\) Spectre-v2 attacks. In Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922). 971\u2013988. Retrieved from https:\/\/www.vusec.net\/projects\/bhi-spectre-bhb"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446708"},{"key":"e_1_3_1_18_2","article-title":"Template attack on blinded scalar multiplication with asynchronous perf-ioctl calls","author":"Bhattacharya Sarani","year":"2017","unstructured":"Sarani Bhattacharya, Cl\u00e9mentine Maurice, Shivam Bhasin, and Debdeep Mukhopadhyay. 2017. Template attack on blinded scalar multiplication with asynchronous perf-ioctl calls. Cryptology ePrint Archive (2017).","journal-title":"Cryptology ePrint Archive"},{"issue":"5","key":"e_1_3_1_19_2","doi-asserted-by":"crossref","first-page":"633","DOI":"10.1109\/TC.2019.2958611","article-title":"Branch prediction attack on blinded scalar multiplication","volume":"69","author":"Bhattacharya Sarani","year":"2019","unstructured":"Sarani Bhattacharya, Cl\u00e9mentine Maurice, Shivam Bhasin, and Debdeep Mukhopadhyay. 2019. Branch prediction attack on blinded scalar multiplication. IEEE Transactions on Computers 69, 5 (2019), 633\u2013648. Retrieved from https:\/\/github.com\/SBIIT\/Branch-Attack-on-Curve-1174","journal-title":"IEEE Transactions on Computers"},{"key":"e_1_3_1_20_2","doi-asserted-by":"crossref","first-page":"248","DOI":"10.1007\/978-3-662-48324-4_13","volume-title":"Proceedings of the 17th International Workshop on Cryptographic Hardware and Embedded Systems\u2013CHES 2015","author":"Bhattacharya Sarani","year":"2015","unstructured":"Sarani Bhattacharya and Debdeep Mukhopadhyay. 2015. Who watches the watchmen?: Utilizing performance monitors for compromising keys of RSA on Intel platforms. In Proceedings of the 17th International Workshop on Cryptographic Hardware and Embedded Systems\u2013CHES 2015. Springer, 248\u2013266."},{"key":"e_1_3_1_21_2","doi-asserted-by":"crossref","first-page":"785","DOI":"10.1145\/3319535.3363194","volume-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","author":"Bhattacharyya Atri","year":"2019","unstructured":"Atri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti, Babak Falsafi, Mathias Payer, and Anil Kurmus. 2019. Smotherspectre: Exploiting speculative execution through port contention. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. 785\u2013800."},{"issue":"1","key":"e_1_3_1_22_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3023872","article-title":"A survey of timing channels and countermeasures","volume":"50","author":"Biswas Arnab Kumar","year":"2017","unstructured":"Arnab Kumar Biswas, Dipak Ghosal, and Shishir Nagaraja. 2017. A survey of timing channels and countermeasures. ACM Computing Surveys (CSUR) 50, 1 (2017), 1\u201339.","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484583"},{"key":"e_1_3_1_24_2","article-title":"Software mitigations to hedge AES against cache-based software side channel vulnerabilities","author":"Brickell Ernie","year":"2006","unstructured":"Ernie Brickell, Gary Graunke, Michael Neve, and Jean-Pierre Seifert. 2006. Software mitigations to hedge AES against cache-based software side channel vulnerabilities. Cryptology ePrint Archive (2006).","journal-title":"Cryptology ePrint Archive"},{"key":"e_1_3_1_25_2","first-page":"249","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919)","author":"Canella Claudio","year":"2019","unstructured":"Claudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp, Benjamin Von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, and Daniel Gruss. 2019. A systematic evaluation of transient execution attacks and defenses. In Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919). 249\u2013266."},{"key":"e_1_3_1_26_2","volume-title":"Side-Channel Attacks in RISC-V BOOM Front-End","author":"Chavda Rutvik Jayantbhai","year":"2023","unstructured":"Rutvik Jayantbhai Chavda. 2023. Side-Channel Attacks in RISC-V BOOM Front-End. Ph. D. Dissertation. Virginia Tech."},{"key":"e_1_3_1_27_2","first-page":"25","volume-title":"Proceedings of the 2022 27th Asia and South Pacific Design Automation Conference (ASP-DAC\u201922)","author":"Chen Congcong","year":"2022","unstructured":"Congcong Chen, Chaoqun Shen, and Jiliang Zhang. 2022. Lightweight and secure branch predictors against spectre attacks. In Proceedings of the 2022 27th Asia and South Pacific Design Automation Conference (ASP-DAC\u201922). IEEE, 25\u201330."},{"key":"e_1_3_1_28_2","doi-asserted-by":"crossref","first-page":"142","DOI":"10.1109\/EuroSP.2019.00020","volume-title":"Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P\u201919)","author":"Chen Guoxing","year":"2019","unstructured":"Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten H. Lai. 2019. SgxPectre: Stealing intel secrets from SGX enclaves via speculative execution. In Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P\u201919). IEEE, 142\u2013157. Retrieved from https:\/\/github.com\/OSUSecLab\/SgxPectre"},{"issue":"3","key":"e_1_3_1_29_2","doi-asserted-by":"crossref","first-page":"224","DOI":"10.46586\/tches.v2024.i3.224-248","article-title":"Evict+ spec+ time: Exploiting out-of-order execution to improve cache-timing attacks","volume":"2024","author":"Cheng Shing Hing William","year":"2024","unstructured":"Shing Hing William Cheng, Chitchanok Chuengsatiansup, Daniel Genkin, Dallas McNeil, Toby Murray, Yuval Yarom, and Zhiyuan Zhang. 2024. Evict+ spec+ time: Exploiting out-of-order execution to improve cache-timing attacks. IACR Transactions on Cryptographic Hardware and Embedded Systems 2024, 3 (2024), 224\u2013248.","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded Systems"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2016.09.014"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.3390\/app10030984"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3560834.3563830"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480068"},{"issue":"9","key":"e_1_3_1_34_2","first-page":"2059","article-title":"Leaking secrets through modern branch predictors in the speculative world","volume":"71","author":"Chowdhuryy Md Hafizul Islam","year":"2021","unstructured":"Md Hafizul Islam Chowdhuryy and Fan Yao. 2021. Leaking secrets through modern branch predictors in the speculative world. IEEE Transactions on Computers 71, 9 (2021), 2059\u20132072. Retrieved from https:\/\/github.com\/fanyao\/branchspec","journal-title":"IEEE Transactions on Computers"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/223982.224444"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.19"},{"key":"e_1_3_1_37_2","doi-asserted-by":"crossref","first-page":"292","DOI":"10.1007\/3-540-48059-5_25","volume-title":"Proceedings of the 1st InternationalWorkshop on Cryptographic Hardware and Embedded Systems, CHES\u201999","author":"Coron Jean-S\u00e9bastien","year":"1999","unstructured":"Jean-S\u00e9bastien Coron. 1999. Resistance against differential power analysis for elliptic curve cryptosystems. In Proceedings of the 1st InternationalWorkshop on Cryptographic Hardware and Embedded Systems, CHES\u201999. Springer, 292\u2013302."},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3563037"},{"key":"e_1_3_1_39_2","article-title":"Reverse branch target buffer poisoning","author":"Oliviera Jos\u00e9 Luiz Negreira Castro de","year":"2022","unstructured":"Jos\u00e9 Luiz Negreira Castro de Oliviera and Diego Leonel Cadette Dutra. 2022. Reverse branch target buffer poisoning. Relat\u00f3rio Technico ES-783\/22, Universidade Federal do Rio de Janeiro (2022).","journal-title":"Relat\u00f3rio Technico ES-783\/22, Universidade Federal do Rio de Janeiro"},{"key":"e_1_3_1_40_2","first-page":"451","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920)","author":"Dessouky Ghada","year":"2020","unstructured":"Ghada Dessouky, Tommaso Frassetto, and Ahmad-Reza Sadeghi. 2020. \\(\\lbrace\\) HybCache \\(\\rbrace\\) : Hybrid \\(\\lbrace\\) Side-Channel-Resilient \\(\\rbrace\\) caches for trusted execution environments. In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920). 451\u2013468."},{"key":"e_1_3_1_41_2","doi-asserted-by":"crossref","unstructured":"Ghada Dessouky Alexander Gruler Pouya Mahmoody Ahmad-Reza Sadeghi and Emmanuel Stapf. 2022. Chunked-cache: On-demand and scalable cache isolation for security architectures. In Proceedings of the 29th Annual Network and Distributed System Security Symposium (NDSS\u201922).","DOI":"10.14722\/ndss.2022.23110"},{"issue":"4","key":"e_1_3_1_42_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2086696.2086714","article-title":"Non-monopolizable caches: Low-complexity mitigation of cache side channel attacks","volume":"8","author":"Domnitser Leonid","year":"2012","unstructured":"Leonid Domnitser, Aamer Jaleel, Jason Loew, Nael Abu-Ghazaleh, and Dmitry Ponomarev. 2012. Non-monopolizable caches: Low-complexity mitigation of cache side channel attacks. ACM Transactions on Architecture and Code Optimization (TACO) 8, 4 (2012), 1\u201321.","journal-title":"ACM Transactions on Architecture and Code Optimization (TACO)"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446729"},{"key":"e_1_3_1_44_2","first-page":"1","volume-title":"Proceedings of the 4th Workshop on Hardware and Architectural Support for Security and Privacy","author":"Evtyushkin Dmitry","year":"2015","unstructured":"Dmitry Evtyushkin, Dmitry Ponomarev, and Nael Abu-Ghazaleh. 2015. Covert channels through branch predictors: A feasibility study. In Proceedings of the 4th Workshop on Hardware and Architectural Support for Security and Privacy. 1\u20138."},{"key":"e_1_3_1_45_2","first-page":"1","volume-title":"Proceedings of the 2016 49th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201916)","author":"Evtyushkin Dmitry","year":"2016","unstructured":"Dmitry Evtyushkin, Dmitry Ponomarev, and Nael Abu-Ghazaleh. 2016. Jump over ASLR: Attacking branch predictors to bypass ASLR. In Proceedings of the 2016 49th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201916). IEEE, 1\u201313."},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/2870636"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3296957.3173204"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3456631"},{"key":"e_1_3_1_49_2","doi-asserted-by":"crossref","unstructured":"Luis Fiolhais and Leonel Sousa. 2023. Transient-execution attacks: A computer architect perspective. ACM Computing Surveys (CSUR) 56 3 (2023) 1\u201338.","DOI":"10.1145\/3603619"},{"key":"e_1_3_1_50_2","first-page":"1","volume-title":"Proceedings of the 56th Annual Design Automation Conference 2019","author":"Fustos Jacob","year":"2019","unstructured":"Jacob Fustos, Farzad Farshchi, and Heechul Yun. 2019. Spectreguard: An efficient data-centric defense mechanism against spectre attacks. In Proceedings of the 56th Annual Design Automation Conference 2019. 1\u20136. Retrieved from https:\/\/github.com\/CSL-KU\/SpectreGuard"},{"key":"e_1_3_1_51_2","doi-asserted-by":"crossref","unstructured":"Qian Ge Yuval Yarom David Cock and Gernot Heiser. 2018. A survey of microarchitectural timing attacks and countermeasures on contemporary hardware. Journal of Cryptographic Engineering 8 1 (2018) 1\u201327.","DOI":"10.1007\/s13389-016-0141-6"},{"key":"e_1_3_1_52_2","unstructured":"Qian Ge Yuval Yarom Frank Li and Gernot Heiser. 2016. Your processor leaks information-and there\u2019s nothing you can do about it. arXiv:1612.04474. Retrieved from https:\/\/arxiv.org\/abs\/1612.04474"},{"key":"e_1_3_1_53_2","doi-asserted-by":"crossref","first-page":"1871","DOI":"10.1145\/3372297.3417289","volume-title":"Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security","author":"G\u00f6ktas Enes","year":"2020","unstructured":"Enes G\u00f6ktas, Kaveh Razavi, Georgios Portokalidis, Herbert Bos, and Cristiano Giuffrida. 2020. Speculative probing: Hacking blind in the Spectre era. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security. 1871\u20131885."},{"key":"e_1_3_1_54_2","volume-title":"Proceedings of the 3rd Workshop on Computer Architecture Research with RISC-V (CARRV\u201919)","author":"Gonzalez Abraham","year":"2019","unstructured":"Abraham Gonzalez, Ben Korpan, Jerry Zhao, Ed Younis, and Krste Asanovic. 2019. Replicating and mitigating spectre attacks on an open source RISC-V microarchitecture. In Proceedings of the 3rd Workshop on Computer Architecture Research with RISC-V (CARRV\u201919). Retrieved from https:\/\/github.com\/riscv-boom\/boom-attacks"},{"key":"e_1_3_1_55_2","first-page":"955","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918)","author":"Gras Ben","year":"2018","unstructured":"Ben Gras, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2018. Translation leak-aside buffer: Defeating cache side-channel protections with \\(\\lbrace\\) TLB \\(\\rbrace\\) attacks. In Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918). 955\u2013972."},{"key":"e_1_3_1_56_2","volume-title":"Respectre: The State of the Art in Spectre Defenses","year":"2018","unstructured":"grsecurity. 2018. Respectre: The State of the Art in Spectre Defenses. Retrieved September 2023 from https:\/\/grsecurity.net\/respectre_announce"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417246"},{"key":"e_1_3_1_58_2","first-page":"1","volume-title":"Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP\u201920)","author":"Guarnieri Marco","year":"2020","unstructured":"Marco Guarnieri, Boris K\u00f6pf, Jos\u00e9 F. Morales, Jan Reineke, and Andr\u00e9s S\u00e1nchez. 2020. Spectector: Principled detection of speculative information flows. In Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP\u201920). IEEE, 1\u201319. Retrieved from https:\/\/github.com\/spectector\/spectector"},{"key":"e_1_3_1_59_2","first-page":"116","volume-title":"Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Hetterich Lorenz","year":"2022","unstructured":"Lorenz Hetterich and Michael Schwarz. 2022. Branch different-spectre attacks on apple silicon. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 116\u2013135. Retrieved from https:\/\/github.com\/cispa\/BranchDifferent"},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/3268935.3268940"},{"key":"e_1_3_1_61_2","first-page":"639","volume-title":"Proceedings of the 2015 IEEE 21st International Symposium on High Performance Computer Architecture (HPCA\u201915)","author":"Hunger Casen","year":"2015","unstructured":"Casen Hunger, Mikhail Kazdagli, Ankit Rawat, Alex Dimakis, Sriram Vishwanath, and Mohit Tiwari. 2015. Understanding contention-based channels and using them for defense. In Proceedings of the 2015 IEEE 21st International Symposium on High Performance Computer Architecture (HPCA\u201915). IEEE, 639\u2013650."},{"key":"e_1_3_1_62_2","doi-asserted-by":"crossref","unstructured":"Tianlin Huo Xiaoni Meng Wenhao Wang Chunliang Hao Pei Zhao Jian Zhai and Mingshu Li. 2020. Bluethunder: A 2-level directional predictor based side-channel attack against SGX. IACR Transactions on Cryptographic Hardware and Embedded Systems 2020 1 (2020) 321\u2013347.","DOI":"10.46586\/tches.v2020.i1.321-347"},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560578"},{"key":"e_1_3_1_64_2","volume-title":"Usage Models for Cache Allocation Technology in the Intel\u00ae Xeon\u00ae Processor E5 v4 Family","year":"2016","unstructured":"Intel. 2016. Usage Models for Cache Allocation Technology in the Intel\u00ae Xeon\u00ae Processor E5 v4 Family. Retrieved September 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/cache-allocation-technology-usage-models.html"},{"key":"e_1_3_1_65_2","volume-title":"Indirect Branch Restricted Speculation","year":"2018","unstructured":"Intel. 2018. Indirect Branch Restricted Speculation. Retrieved November 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/indirect-branch-restricted-speculation.html"},{"key":"e_1_3_1_66_2","volume-title":"Intel Analysis of Speculative Execution Side Channels","year":"2018","unstructured":"Intel. 2018. Intel Analysis of Speculative Execution Side Channels. Retrieved November 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/analysis-speculative-execution-side-channels.html"},{"key":"e_1_3_1_67_2","volume-title":"Retpoline: A Branch Target Injection Mitigation","year":"2018","unstructured":"Intel. 2018. Retpoline: A Branch Target Injection Mitigation. Retrieved November 2023 from https:\/\/www.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/retpoline-a-branch-target-injection-mitigation.pdf"},{"key":"e_1_3_1_68_2","volume-title":"Rogue Data Cache Load","year":"2018","unstructured":"Intel. 2018. Rogue Data Cache Load. Retrieved November 2023 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/advisory-guidance\/rogue-data-cache-load.html"},{"key":"e_1_3_1_69_2","volume-title":"Speculative Store Bypass","year":"2018","unstructured":"Intel. 2018. Speculative Store Bypass. Retrieved January 2024 from https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/advisory-guidance\/speculative-store-bypass.html"},{"key":"e_1_3_1_70_2","volume-title":"Intel\u00ae 64 and IA-32 Architectures Optimization Reference Manual Volume 1","year":"2024","unstructured":"Intel. 2024. Intel\u00ae 64 and IA-32 Architectures Optimization Reference Manual Volume 1. Retrieved February 2024 from https:\/\/www.intel.com\/content\/www\/us\/en\/content-details\/671488\/intel-64-and-ia-32-architectures-optimization-reference-manual-volume-1.html"},{"key":"e_1_3_1_71_2","first-page":"64","volume-title":"Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security","author":"Jang Hyerean","year":"2024","unstructured":"Hyerean Jang, Teahun Kim, and Youngjoo Shin. 2024. SysBumps: Exploiting speculative execution in system calls for breaking KASLR in macOS for apple silicon. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security. 64\u201378."},{"key":"e_1_3_1_72_2","doi-asserted-by":"crossref","unstructured":"Hyerean Jang and Youngjoo Shin. 2023. MicroCFI: Microarchitecture-level control-flow restrictions for spectre mitigation. IEEE Access 11 (2023) 138699\u2013138711.","DOI":"10.1109\/ACCESS.2023.3340680"},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3566053"},{"key":"e_1_3_1_74_2","first-page":"291","volume-title":"Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems","author":"Joye Marc","year":"2002","unstructured":"Marc Joye and Sung-Ming Yen. 2002. The Montgomery powering ladder. In Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems. Springer, 291\u2013302."},{"key":"e_1_3_1_75_2","first-page":"1","volume-title":"Proceedings of the 2019 56th ACM\/IEEE Design Automation Conference (DAC\u201919)","author":"Khasawneh Khaled N.","year":"2019","unstructured":"Khaled N. Khasawneh, Esmaeil Mohammadian Koruyeh, Chengyu Song, Dmitry Evtyushkin, Dmitry Ponomarev, and Nael Abu-Ghazaleh. 2019. Safespec: Banishing the spectre of a meltdown with leakage-free speculation. In Proceedings of the 2019 56th ACM\/IEEE Design Automation Conference (DAC\u201919). IEEE, 1\u20136."},{"key":"e_1_3_1_76_2","doi-asserted-by":"crossref","unstructured":"Hodong Kim Changhee Hahn Hyunwoo J. Kim Youngjoo Shin and Junbeom Hur. 2023. Deep learning based detection for multiple cache side-channel attacks. IEEE Transactions on Information Forensics and Security 19 (2024) 1672\u20131686.","DOI":"10.1109\/TIFS.2023.3340088"},{"key":"e_1_3_1_77_2","unstructured":"Juhee Kim Jinbum Park Sihyeon Roh Jaeyoung Chung Youngjoo Lee Taesoo Kim and Byoungyoung Lee. 2025. TikTag: Breaking ARM\u2019s memory tagging extension with speculative execution. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP\u201925). IEEE 3731\u20133749."},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616611"},{"key":"e_1_3_1_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665726"},{"key":"e_1_3_1_80_2","doi-asserted-by":"crossref","first-page":"974","DOI":"10.1109\/MICRO.2018.00083","volume-title":"Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918)","author":"Kiriansky Vladimir","year":"2018","unstructured":"Vladimir Kiriansky, Ilia Lebedev, Saman Amarasinghe, Srinivas Devadas, and Joel Emer. 2018. DAWG: A defense against cache timing attacks in speculative execution processors. In Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918). IEEE, 974\u2013987."},{"key":"e_1_3_1_81_2","unstructured":"Vladimir Kiriansky and Carl Waldspurger. 2018. Speculative buffer overflows: Attacks and defenses. arXiv:1807.03757. Retrieved from https:\/\/arxiv.org\/abs\/1807.03757"},{"key":"e_1_3_1_82_2","first-page":"2399","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921)","author":"Kirzner Ofek","year":"2021","unstructured":"Ofek Kirzner and Adam Morrison. 2021. An analysis of speculative type confusion vulnerabilities in the wild. In Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921). 2399\u20132416."},{"key":"e_1_3_1_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/3399742"},{"key":"e_1_3_1_84_2","first-page":"393","volume-title":"Proceedings of the 2009 IEEE 15th International Symposium on High Performance Computer Architecture","author":"Kong Jingfei","year":"2009","unstructured":"Jingfei Kong, Onur Acii\u00e7mez, Jean-Pierre Seifert, and Huiyang Zhou. 2009. Hardware-software integrated approaches to defend against software cache-based side channel attacks. In Proceedings of the 2009 IEEE 15th International Symposium on High Performance Computer Architecture. IEEE, 393\u2013404."},{"key":"e_1_3_1_85_2","volume-title":"Proceedings of the 12th USENIX Workshop on Offensive Technologies (WOOT\u201918)","author":"Koruyeh Esmaeil Mohammadian","year":"2018","unstructured":"Esmaeil Mohammadian Koruyeh, Khaled N. Khasawneh, Chengyu Song, and Nael Abu-Ghazaleh. 2018. Spectre returns! Speculation attacks using the return stack buffer. In Proceedings of the 12th USENIX Workshop on Offensive Technologies (WOOT\u201918)."},{"key":"e_1_3_1_86_2","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1109\/SP40000.2020.00033","volume-title":"Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP\u201920)","author":"Koruyeh Esmaeil Mohammadian","year":"2020","unstructured":"Esmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song, and Nael Abu-Ghazaleh. 2020. SpecCFI: Mitigating spectre attacks using CFI informed speculation. In Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP\u201920). IEEE, 39\u201353."},{"key":"e_1_3_1_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586226"},{"key":"e_1_3_1_88_2","first-page":"493","volume-title":"Proceedings of the 2017 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201917)","author":"Kumar Rakesh","year":"2017","unstructured":"Rakesh Kumar, Cheng-Chieh Huang, Boris Grot, and Vijay Nagarajan. 2017. Boomerang: A metadata-free architecture for control flow delivery. In Proceedings of the 2017 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201917). IEEE, 493\u2013504."},{"key":"e_1_3_1_89_2","first-page":"2467","volume-title":"Proceedings of the 2022 IEEE International Symposium on Circuits and Systems (ISCAS\u201922)","author":"Le Anh-Tien","year":"2022","unstructured":"Anh-Tien Le, Trong-Thuc Hoang, Ba-Anh Dao, Akira Tsukamoto, Kuniyasu Suzaki, and Cong-Kha Pham. 2022. Spectre attack detection with neutral network on RISC-V processor. In Proceedings of the 2022 IEEE International Symposium on Circuits and Systems (ISCAS\u201922). IEEE, 2467\u20132471."},{"key":"e_1_3_1_90_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2022.108546"},{"key":"e_1_3_1_91_2","first-page":"557","volume-title":"Proceedings of the 26th USENIX Security Symposium (USENIX Security\u201917)","author":"Lee Sangho","year":"2017","unstructured":"Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. 2017. Inferring fine-grained control flow inside \\(\\lbrace\\) SGX \\(\\rbrace\\) enclaves with branch shadowing. In Proceedings of the 26th USENIX Security Symposium (USENIX Security\u201917). 557\u2013574."},{"key":"e_1_3_1_92_2","first-page":"98","volume-title":"Proceedings of the 2022 IEEE International Symposium on High-Performance Computer Architecture (HPCA\u201922)","author":"Li Mengming","year":"2022","unstructured":"Mengming Li, Chenlu Miao, Yilong Yang, and Kai Bu. 2022. Unxpec: Breaking undo-based safe speculation. In Proceedings of the 2022 IEEE International Symposium on High-Performance Computer Architecture (HPCA\u201922). IEEE, 98\u2013112. Retrieved from https:\/\/github.com\/RISEGp\/unXpec"},{"key":"e_1_3_1_93_2","first-page":"264","volume-title":"Proceedings of the 2019 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201919)","author":"Li Peinan","year":"2019","unstructured":"Peinan Li, Lutan Zhao, Rui Hou, Lixin Zhang, and Dan Meng. 2019. Conditional speculation: An effective approach to safeguard out-of-order execution against spectre attacks. In Proceedings of the 2019 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201919). IEEE, 264\u2013276."},{"key":"e_1_3_1_94_2","unstructured":"Moritz Lipp Michael Schwarz Daniel Gruss Thomas Prescher Werner Haas Stefan Mangard Paul Kocher Daniel Genkin Yuval Yarom and Mike Hamburg. 2018. Meltdown. arXiv:1801.01207. Retrieved from https:\/\/arxiv.org\/abs\/1801.01207"},{"key":"e_1_3_1_95_2","first-page":"406","volume-title":"Proceedings of the 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201916)","author":"Liu Fangfei","year":"2016","unstructured":"Fangfei Liu, Qian Ge, Yuval Yarom, Frank McKeen, Carlos Rozas, Gernot Heiser, and Ruby B. Lee. 2016. Catalyst: Defeating last-level cache side channel attacks in cloud computing. In Proceedings of the 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201916). IEEE, 406\u2013418."},{"key":"e_1_3_1_96_2","first-page":"203","volume-title":"Proceedings of the 2014 47th Annual IEEE\/ACM International Symposium on Microarchitecture","author":"Liu Fangfei","year":"2014","unstructured":"Fangfei Liu and Ruby B. Lee. 2014. Random fill cache architecture. In Proceedings of the 2014 47th Annual IEEE\/ACM International Symposium on Microarchitecture. IEEE, 203\u2013215."},{"key":"e_1_3_1_97_2","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2016.85"},{"key":"e_1_3_1_98_2","doi-asserted-by":"publisher","DOI":"10.1145\/3456629"},{"key":"e_1_3_1_99_2","doi-asserted-by":"crossref","unstructured":"Yangdi Lyu and Prabhat Mishra. 2018. A survey of side-channel attacks on caches and countermeasures. Journal of Hardware and Systems Security 2 1 (2018) 33\u201350.","DOI":"10.1007\/s41635-017-0025-y"},{"key":"e_1_3_1_100_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243761"},{"key":"e_1_3_1_101_2","unstructured":"Giorgi Maisuradze and Christian Rossow. 2018. Speculose: Analyzing the security implications of speculative execution in CPUs. arXiv:1801.04084. Retrieved from https:\/\/arxiv.org\/abs\/1801.04084"},{"key":"e_1_3_1_102_2","doi-asserted-by":"publisher","DOI":"10.5555\/3359043.3359046"},{"key":"e_1_3_1_103_2","doi-asserted-by":"crossref","first-page":"633","DOI":"10.1109\/EuroSP51992.2021.00048","volume-title":"Proceedings of the 2021 IEEE European Symposium on Security and Privacy (EuroS&P\u201921)","author":"Mambretti Andrea","year":"2021","unstructured":"Andrea Mambretti, Alexandra Sandulescu, Alessandro Sorniotti, William Robertson, Engin Kirda, and Anil Kurmus. 2021. Bypassing memory safety mechanisms through speculative control flow hijacks. In Proceedings of the 2021 IEEE European Symposium on Security and Privacy (EuroS&P\u201921). IEEE, 633\u2013649."},{"key":"e_1_3_1_104_2","unstructured":"Ross McIlroy Jaroslav Sevcik Tobias Tebbi Ben L. Titzer and Toon Verwaest. 2019. Spectre is here to stay: An analysis of side-channels and speculative execution. arXiv:1902.05178. Retrieved from https:\/\/arxiv.org\/abs\/1902.05178"},{"key":"e_1_3_1_105_2","volume-title":"Spectre Mitigations in MSVC","year":"2018","unstructured":"Microsoft. 2018. Spectre Mitigations in MSVC. Retrieved December 2023 from https:\/\/devblogs.microsoft.com\/cppblog\/spectre-mitigations-in-msvc\/"},{"key":"e_1_3_1_106_2","unstructured":"Alyssa Milburn Ke Sun and Henrique Kawakami. 2022. You cannot always win the race: Analyzing the LFENCE\/JMP mitigation for branch target injection. arXiv:2203.04277. Retrieved from https:\/\/arxiv.org\/abs\/2203.04277"},{"key":"e_1_3_1_107_2","unstructured":"Marina Minkin Daniel Moghimi Moritz Lipp Michael Schwarz Jo Van Bulck Daniel Genkin Daniel Gruss Frank Piessens Berk Sunar and Yuval Yarom. 2019. Fallout: Reading kernel writes from user space. arXiv:1905.12701. Retrieved from https:\/\/arxiv.org\/abs\/1905.12701"},{"key":"e_1_3_1_108_2","doi-asserted-by":"publisher","DOI":"10.1145\/3296979.3192413"},{"key":"e_1_3_1_109_2","unstructured":"Alexander Nilsson Pegah Nikbakht Bideh and Joakim Brorsson. 2020. A survey of published attacks on Intel SGX. arXiv:2006.13598. Retrieved from https:\/\/arxiv.org\/abs\/2006.13598"},{"key":"e_1_3_1_110_2","first-page":"1481","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920)","author":"Oleksenko Oleksii","year":"2020","unstructured":"Oleksii Oleksenko, Bohdan Trach, Mark Silberstein, and Christof Fetzer. 2020. \\(\\lbrace\\) SpecFuzz \\(\\rbrace\\) : Bringing spectre-type vulnerabilities to the surface. In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920). 1481\u20131498. Retrieved from https:\/\/github.com\/OleksiiOleksenko\/SpecFuzz"},{"key":"e_1_3_1_111_2","doi-asserted-by":"crossref","first-page":"775","DOI":"10.1109\/MICRO.2018.00068","volume-title":"Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918)","author":"Qureshi Moinuddin K.","year":"2018","unstructured":"Moinuddin K. Qureshi. 2018. CEASER: Mitigating conflict-based cache attacks via encrypted-address and remapping. In Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918). IEEE, 775\u2013787."},{"key":"e_1_3_1_112_2","doi-asserted-by":"publisher","DOI":"10.1145\/3307650.3322246"},{"key":"e_1_3_1_113_2","volume-title":"Proceedings of the USENIX Security Symposium","author":"Ragab Hany","year":"2024","unstructured":"Hany Ragab, Andrea Mambretti, Anil Kurmus, and Cristiano Giuffrida. 2024. GhostRace: Exploiting and mitigating speculative race conditions. In Proceedings of the USENIX Security Symposium. Retrieved from https:\/\/www.vusec.net\/projects\/ghostrace"},{"key":"e_1_3_1_114_2","first-page":"431","volume-title":"Proceedings of the 24th USENIX Security Symposium (USENIX Security\u201915)","author":"Rane Ashay","year":"2015","unstructured":"Ashay Rane, Calvin Lin, and Mohit Tiwari. 2015. Raccoon: Closing digital \\(\\lbrace\\) Side-Channels \\(\\rbrace\\) through obfuscated execution. In Proceedings of the 24th USENIX Security Symposium (USENIX Security\u201915). 431\u2013446."},{"key":"e_1_3_1_115_2","doi-asserted-by":"publisher","DOI":"10.1145\/3470496.3527429"},{"key":"e_1_3_1_116_2","doi-asserted-by":"crossref","first-page":"435","DOI":"10.1109\/SP.2019.00062","volume-title":"Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP\u201919)","author":"Ronen Eyal","year":"2019","unstructured":"Eyal Ronen, Robert Gillham, Daniel Genkin, Adi Shamir, David Wong, and Yuval Yarom. 2019. The 9 lives of Bleichenbacher\u2019s CAT: New cache attacks on TLS implementations. In Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP\u201919). IEEE, 435\u2013452. Retrieved from https:\/\/github.com\/mimoo\/RSA_PKCS1v1_5_attacks"},{"key":"e_1_3_1_117_2","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358314"},{"key":"e_1_3_1_118_2","doi-asserted-by":"publisher","DOI":"10.1145\/3307650.3322216"},{"key":"e_1_3_1_119_2","doi-asserted-by":"publisher","DOI":"10.1145\/3307650.3322216"},{"key":"e_1_3_1_120_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2020.2993896"},{"key":"e_1_3_1_121_2","doi-asserted-by":"crossref","first-page":"753","DOI":"10.1145\/3319535.3354252","volume-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","author":"Schwarz Michael","year":"2019","unstructured":"Michael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck, Julian Stecklina, Thomas Prescher, and Daniel Gruss. 2019. ZombieLoad: Cross-privilege-boundary data sampling. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. 753\u2013768."},{"key":"e_1_3_1_122_2","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1007\/978-3-030-29959-0_14","volume-title":"Computer Security\u2013ESORICS 2019: Proceedings of the 24th European Symposium on Research in Computer Security, Part I","author":"Schwarz Michael","year":"2019","unstructured":"Michael Schwarz, Martin Schwarzl, Moritz Lipp, Jon Masters, and Daniel Gruss. 2019. Netspectre: Read arbitrary memory over network. In Computer Security\u2013ESORICS 2019: Proceedings of the 24th European Symposium on Research in Computer Security, Part I. Springer, 279\u2013299."},{"key":"e_1_3_1_123_2","first-page":"293","volume-title":"Proceedings of the 25th International Conference on Financial Cryptography and Data Security, FC 2021, Revised Selected Papers, Part I","author":"Schwarzl Martin","year":"2021","unstructured":"Martin Schwarzl, Claudio Canella, Daniel Gruss, and Michael Schwarz. 2021. Specfuscator: Evaluating branch removal as a Spectre mitigation. In Proceedings of the 25th International Conference on Financial Cryptography and Data Security, FC 2021, Revised Selected Papers, Part I. Springer, 293\u2013310."},{"key":"e_1_3_1_124_2","first-page":"1","article-title":"A 256 kbits L-TAGE branch predictor","volume":"9","author":"Seznec Andr\u00e9","year":"2007","unstructured":"Andr\u00e9 Seznec. 2007. A 256 kbits L-TAGE branch predictor. Journal of Instruction-Level Parallelism (JILP) Special Issue: The Second Championship Branch Prediction Competition (CBP-2) 9 (2007), 1\u20136.","journal-title":"Journal of Instruction-Level Parallelism (JILP) Special Issue: The Second Championship Branch Prediction Competition (CBP-2)"},{"key":"e_1_3_1_125_2","volume-title":"Proceedings of the 5th JILP Workshop on Computer Architecture Competitions (JWAC-5): Championship Branch Prediction (CBP-5)","author":"Seznec Andr\u00e9","year":"2016","unstructured":"Andr\u00e9 Seznec. 2016. TAGE-SC-L branch predictors again. In Proceedings of the 5th JILP Workshop on Computer Architecture Competitions (JWAC-5): Championship Branch Prediction (CBP-5)."},{"key":"e_1_3_1_126_2","doi-asserted-by":"publisher","DOI":"10.1145\/3337167.3337175"},{"key":"e_1_3_1_127_2","doi-asserted-by":"publisher","DOI":"10.1145\/3394885.3431638"},{"key":"e_1_3_1_128_2","doi-asserted-by":"crossref","unstructured":"Zhuojia Shen Jie Zhou Divya Ojha and John Criswell. 2019. Restricting control flow during speculative execution. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. 2297\u20132299.","DOI":"10.1145\/3243734.3278522"},{"key":"e_1_3_1_129_2","doi-asserted-by":"crossref","unstructured":"Luigi Soares Michael Canesche and Fernando Magno Quintao Pereira. 2023. Side-channel elimination via partial control-flow linearization. ACM Transactions on Programming Languages and Systems 45 2 (2023) 1\u201343. Retrieved from https:\/\/github.com\/lac-dcc\/lif\/","DOI":"10.1145\/3594736"},{"key":"e_1_3_1_130_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO51591.2021.9370305"},{"key":"e_1_3_1_131_2","doi-asserted-by":"crossref","first-page":"291","DOI":"10.1109\/HPCA.2001.903271","volume-title":"Proceedings HPCA 7th International Symposium on High-Performance Computer Architecture","author":"Srinivasan Viji","year":"2001","unstructured":"Viji Srinivasan, Edward S. Davidson, Gary S. Tyson, Mark J. Charney, and Thomas R. Puzak. 2001. Branch history guided instruction prefetching. In Proceedings HPCA 7th International Symposium on High-Performance Computer Architecture. IEEE, 291\u2013300."},{"key":"e_1_3_1_132_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-018-0046-1"},{"key":"e_1_3_1_133_2","unstructured":"Farhad Taheri Siavash Bayat-Sarmadi Alireza Sadeghpour and Seyed Parsa Tayefeh Morsal. 2023. Comprehensive evaluation of RSB and spectre vulnerability on modern processors. arXiv:2302.09544. Retrieved from https:\/\/arxiv.org\/abs\/2302.09544"},{"key":"e_1_3_1_134_2","volume-title":"Proceedings of the NDSS","author":"Tan Qinhan","year":"2020","unstructured":"Qinhan Tan, Zhihua Zeng, Kai Bu, and Kui Ren. 2020. PhantomCache: Obfuscating cache conflicts with localized randomization.. In Proceedings of the NDSS."},{"key":"e_1_3_1_135_2","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304060"},{"key":"e_1_3_1_136_2","doi-asserted-by":"crossref","first-page":"681","DOI":"10.1109\/SP46214.2022.9833802","volume-title":"Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP\u201922)","author":"Tobah Youssef","year":"2022","unstructured":"Youssef Tobah, Andrew Kwong, Ingab Kang, Daniel Genkin, and Kang G. Shin. 2022. SpecHammer: Combining spectre and Rowhammer for new speculative attacks. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP\u201922). IEEE, 681\u2013698."},{"key":"e_1_3_1_137_2","first-page":"919","volume-title":"Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom\u201920)","author":"Tong Zhongkai","year":"2020","unstructured":"Zhongkai Tong, Ziyuan Zhu, Zhanpeng Wang, Limin Wang, Yusha Zhang, and Yuxin Liu. 2020. Cache side-channel attacks detection based on machine learning. In Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom\u201920). IEEE, 919\u2013926."},{"key":"e_1_3_1_138_2","doi-asserted-by":"crossref","first-page":"947","DOI":"10.1109\/MICRO.2018.00081","volume-title":"Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918)","author":"Trippel Caroline","year":"2018","unstructured":"Caroline Trippel, Daniel Lustig, and Margaret Martonosi. 2018. Checkmate: Automated synthesis of hardware exploits and security litmus tests. In Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918). IEEE, 947\u2013960. Retrieved from https:\/\/github.com\/ctrippel\/checkmate"},{"key":"e_1_3_1_139_2","unstructured":"Caroline Trippel Daniel Lustig and Margaret Martonosi. 2018. MeltdownPrime and SpectrePrime: Automatically-synthesized attacks exploiting invalidation-based coherence protocols. arXiv:1802.03802. Retrieved from https:\/\/arxiv.org\/abs\/1802.03802"},{"key":"e_1_3_1_140_2","doi-asserted-by":"publisher","DOI":"10.1145\/3152701.3152706"},{"key":"e_1_3_1_141_2","doi-asserted-by":"crossref","first-page":"466","DOI":"10.1109\/HPCA.2019.00058","volume-title":"Proceedings of the 2019 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201919)","author":"Vougioukas Ilias","year":"2019","unstructured":"Ilias Vougioukas, Nikos Nikoleris, Andreas Sandberg, Stephan Diestelhorst, Bashir M. Al-Hashimi, and Geoff V. Merrett. 2019. BRB: Mitigating branch predictor side-channels. In Proceedings of the 2019 IEEE International Symposium on High Performance Computer Architecture (HPCA\u201919). IEEE, 466\u2013477."},{"key":"e_1_3_1_142_2","volume-title":"Proceedings of the NDSS","author":"Wampler Jack","year":"2019","unstructured":"Jack Wampler, Ian Martiny, and Eric Wustrow. 2019. ExSpectre: Hiding malware in speculative execution.. In Proceedings of the NDSS. Retrieved from https:\/\/github.com\/ewust\/speculake"},{"issue":"11","key":"e_1_3_1_143_2","doi-asserted-by":"crossref","first-page":"2504","DOI":"10.1109\/TSE.2019.2953709","article-title":"oo7: Low-overhead defense against spectre attacks via program analysis","volume":"47","author":"Wang Guanhua","year":"2019","unstructured":"Guanhua Wang, Sudipta Chattopadhyay, Ivan Gotovchits, Tulika Mitra, and Abhik Roychoudhury. 2019. oo7: Low-overhead defense against spectre attacks via program analysis. IEEE Transactions on Software Engineering 47, 11 (2019), 2504\u20132519.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_1_144_2","first-page":"1","volume-title":"Proceedings of the 53rd Annual Design Automation Conference","author":"Wang Yao","year":"2016","unstructured":"Yao Wang, Andrew Ferraiuolo, Danfeng Zhang, Andrew C. Myers, and G. Edward Suh. 2016. SecDCP: Secure dynamic cache partitioning for efficient timing channel protection. In Proceedings of the 53rd Annual Design Automation Conference. 1\u20136."},{"key":"e_1_3_1_145_2","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1109\/MICRO.2008.4771781","volume-title":"Proceedings of the 2008 41st IEEE\/ACM International Symposium on Microarchitecture","author":"Wang Zhenghong","year":"2008","unstructured":"Zhenghong Wang and Ruby B. Lee. 2008. A novel cache architecture with enhanced performance and security. In Proceedings of the 2008 41st IEEE\/ACM International Symposium on Microarchitecture. IEEE, 83\u201393."},{"key":"e_1_3_1_146_2","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358306"},{"key":"e_1_3_1_147_2","first-page":"675","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919)","author":"Werner Mario","year":"2019","unstructured":"Mario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz, Daniel Gruss, and Stefan Mangard. 2019. \\(\\lbrace\\) ScatterCache \\(\\rbrace\\) : Thwarting cache attacks via cache set randomization. In Proceedings of the 28th USENIX Security Symposium (USENIX Security\u201919). 675\u2013692."},{"key":"e_1_3_1_148_2","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1145\/3274694.3274741","volume-title":"Proceedings of the 34th Annual Computer Security Applications Conference","author":"Wichelmann Jan","year":"2018","unstructured":"Jan Wichelmann, Ahmad Moghimi, Thomas Eisenbarth, and Berk Sunar. 2018. Microwalk: A framework for finding side channels in binaries. In Proceedings of the 34th Annual Computer Security Applications Conference. 161\u2013173. Retrieved from https:\/\/github.com\/microwalk-project\/Microwalk"},{"key":"e_1_3_1_149_2","first-page":"3","volume-title":"Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Wichelmann Jan","year":"2023","unstructured":"Jan Wichelmann, Christopher Peredy, Florian Sieck, Anna P\u00e4tschke, and Thomas Eisenbarth. 2023. MAMBO\u2013V: Dynamic side-channel leakage analysis on RISC\u2013V. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 3\u201323. Retrieved from https:\/\/github.com\/UzL-ITS\/MAMBO-V"},{"key":"e_1_3_1_150_2","first-page":"3825","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922)","author":"Wikner Johannes","year":"2022","unstructured":"Johannes Wikner and Kaveh Razavi. 2022. \\(\\lbrace\\) RETBLEED \\(\\rbrace\\) : Arbitrary speculative code execution with return instructions. In Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922). 3825\u20133842. Retrieved from https:\/\/comsec.ethz.ch\/research\/microarch\/retbleed"},{"key":"e_1_3_1_151_2","doi-asserted-by":"publisher","DOI":"10.1145\/3213846.3213851"},{"key":"e_1_3_1_152_2","unstructured":"You Wu and Xuehai Qian. 2020. RCP: A low-overhead reversible coherence protocol. arXiv:2006.16535. Retrieved from https:\/\/arxiv.org\/abs\/2006.16535"},{"key":"e_1_3_1_153_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442479"},{"key":"e_1_3_1_154_2","first-page":"01","volume-title":"Proceedings of the 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST\u201924)","author":"Xu Tianhong","year":"2024","unstructured":"Tianhong Xu, Aidong Adam Ding, and Yunsi Fei. 2024. TrustZoneTunnel: A cross-world pattern history table-based microarchitectural side-channel attack. In Proceedings of the 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST\u201924). IEEE, 01\u201311."},{"key":"e_1_3_1_155_2","first-page":"428","volume-title":"Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918)","author":"Yan Mengjia","year":"2018","unstructured":"Mengjia Yan, Jiho Choi, Dimitrios Skarlatos, Adam Morrison, Christopher Fletcher, and Josep Torrellas. 2018. Invisispec: Making speculative execution invisible in the cache hierarchy. In Proceedings of the 2018 51st Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO\u201918). IEEE, 428\u2013441. Retrieved from https:\/\/github.com\/mjyan0720\/InvisiSpec-1.0"},{"issue":"2","key":"e_1_3_1_156_2","doi-asserted-by":"crossref","first-page":"347","DOI":"10.1145\/3140659.3080222","article-title":"Secure hierarchy-aware cache replacement policy (SHARP) defending against cache-based side channel atacks","volume":"45","author":"Yan Mengjia","year":"2017","unstructured":"Mengjia Yan, Bhargava Gopireddy, Thomas Shull, and Josep Torrellas. 2017. Secure hierarchy-aware cache replacement policy (SHARP) defending against cache-based side channel atacks. ACM SIGARCH Computer Architecture News 45, 2 (2017), 347\u2013360.","journal-title":"ACM SIGARCH Computer Architecture News"},{"key":"e_1_3_1_157_2","first-page":"719","volume-title":"Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914)","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner. 2014. \\(\\lbrace\\) FLUSH+ RELOAD \\(\\rbrace\\) : A high resolution, low noise, l3 cache \\(\\lbrace\\) Side-Channel \\(\\rbrace\\) attack. In Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914). 719\u2013732."},{"key":"e_1_3_1_158_2","doi-asserted-by":"publisher","DOI":"10.1145\/3620666.3651382"},{"key":"e_1_3_1_159_2","doi-asserted-by":"crossref","first-page":"1220","DOI":"10.1109\/SP46215.2023.10179415","volume-title":"Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP\u201923)","author":"Yavarzadeh Hosein","year":"2023","unstructured":"Hosein Yavarzadeh, Mohammadkazem Taram, Shravan Narayan, Deian Stefan, and Dean Tullsen. 2023. Half&Half: Demystifying intel\u2019s directional branch predictors for fast, secure partitioned execution. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP\u201923). IEEE Computer Society, 1220\u20131237."},{"key":"e_1_3_1_160_2","unstructured":"Jiyong Yu Lucas Hsiung Mohamad El Hajj and Christopher W. Fletcher. 2019. Data oblivious ISA extensions for side channel-resistant and high performance computing. In Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS\u201919)."},{"key":"e_1_3_1_161_2","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589100"},{"key":"e_1_3_1_162_2","first-page":"707","volume-title":"Proceedings of the 2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA\u201920)","author":"Yu Jiyong","year":"2020","unstructured":"Jiyong Yu, Namrata Mantri, Josep Torrellas, Adam Morrison, and Christopher W. Fletcher. 2020. Speculative data-oblivious execution: Mobilizing safe prediction for safe and efficient speculative execution. In Proceedings of the 2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA\u201920). IEEE, 707\u2013720. Retrieved from https:\/\/github.com\/cwfletcher\/sdo"},{"key":"e_1_3_1_163_2","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358274"},{"key":"e_1_3_1_164_2","first-page":"667","volume-title":"Proceedings of the 25th International Conference on Architectural Support for Programming Languages and Operating Systems","author":"Zhang Tao","year":"2020","unstructured":"Tao Zhang, Kenneth Koltermann, and Dmitry Evtyushkin. 2020. Exploring branch predictors for constructing transient execution trojans. In Proceedings of the 25th International Conference on Architectural Support for Programming Languages and Operating Systems. 667\u2013682."},{"key":"e_1_3_1_165_2","doi-asserted-by":"crossref","unstructured":"Tao Zhang Timothy Lesch Kenneth Koltermann and Dmitry Evtyushkin. 2022. STBPU: A reasonably secure branch prediction unit. In Proceedings of the 52nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN\u201922). IEEE 109\u2013123.","DOI":"10.1109\/DSN53405.2022.00023"},{"key":"e_1_3_1_166_2","first-page":"1492","volume-title":"Proceedings of the 2020 IEEE 5th Information Technology and Mechatronics Engineering Conference (ITOEC\u201920)","author":"Zhang Yahui","year":"2020","unstructured":"Yahui Zhang, Min Zhao, Tingquan Li, and Huan Han. 2020. Survey of attacks and defenses against SGX. In Proceedings of the 2020 IEEE 5th Information Technology and Mechatronics Engineering Conference (ITOEC\u201920). IEEE, 1492\u20131496."},{"key":"e_1_3_1_167_2","unstructured":"Zhi Zhang Yueqiang Cheng and Surya Nepal. 2020. Ghostknight: Breaching data integrity via speculative execution. arXiv:2002.00524. Retrieved from https:\/\/arxiv.org\/abs\/2002.00524"},{"key":"e_1_3_1_168_2","first-page":"7321","volume-title":"Proceedings of the 32nd USENIX Security Symposium (USENIX Security\u201923)","author":"Zhang Zhiyuan","year":"2023","unstructured":"Zhiyuan Zhang, Mingtian Tao, Sioli O\u2019Connell, Chitchanok Chuengsatiansup, Daniel Genkin, and Yuval Yarom. 2023. \\(\\lbrace\\) BunnyHop \\(\\rbrace\\) : Exploiting the instruction prefetcher. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security\u201923). 7321\u20137337. Retrieved from https:\/\/github.com\/0xADE1A1DE\/BunnyHop"},{"key":"e_1_3_1_169_2","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586178"},{"key":"e_1_3_1_170_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978324"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3734218","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,14]],"date-time":"2025-06-14T12:22:20Z","timestamp":1749903740000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3734218"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,14]]},"references-count":169,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2025,11,30]]}},"alternative-id":["10.1145\/3734218"],"URL":"https:\/\/doi.org\/10.1145\/3734218","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,14]]},"assertion":[{"value":"2024-07-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-27","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-06-14","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}