{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:01:37Z","timestamp":1785952897979,"version":"3.56.0"},"reference-count":67,"publisher":"Association for Computing Machinery (ACM)","issue":"5s","funder":[{"name":"French Research Agency","award":["ANR-21-CE-39-0017"],"award-info":[{"award-number":["ANR-21-CE-39-0017"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,11,30]]},"abstract":"<jats:p>Numerous attacks compromising processor security have been developed over decades, including some targeting the microarchitecture, such as side-channel or transient attacks, or control-flow hijacking attacks. As these attacks target processor microarchitectural features and bypass software-level mitigation techniques, they are considered a serious threat. In order to mitigate these attacks while limiting the impact on performance, various detection methods have been proposed. Indeed, detection techniques offer solutions to limit the execution of costly countermeasures, only after attacks detection, limiting the induced performance overhead. However, detection techniques in the literature suffer from several drawbacks, including non-real-time detection, significant increase in execution time, or make the hypothesis of a trusted Operating System (OS). In this work, we introduce DynHaMo that addresses these issues by detecting attacks targeting the microarchitecture, such as Cache-based Side-Channel Attacks (CSCAs) and Return-Oriented Programming (ROP) attacks, at run-time by taking advantage of dynamic instruction insertion at the hardware level. DynHaMo, is a light-weight hardware micro-decoding unit capable of monitoring microarchitectural events on the fly. For evaluation purposes, DynHaMo has been integrated into a RISC-V core, assessed through multiple benchmarks and attack codes, and implemented on an FPGA platform. We evaluated our solution under high workloads to demonstrate the efficiency of the approach and its robustness to noise. The evaluation results show a detection accuracy of 99.3% on average, with 0.7% false negative and 1.2% false positive on average.<\/jats:p>","DOI":"10.1145\/3762646","type":"journal-article","created":{"date-parts":[[2025,8,28]],"date-time":"2025-08-28T11:32:18Z","timestamp":1756380738000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["DynHaMo: Dynamic Hardware-Based Monitoring Dedicated to Attacks Detection"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0521-8311","authenticated-orcid":false,"given":"Juliette","family":"Pottier","sequence":"first","affiliation":[{"name":"IETR, UMR 6164, Nantes Universit\u00e9","place":["Nantes, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9336-9936","authenticated-orcid":false,"given":"Maria","family":"M\u00e9ndez Real","sequence":"additional","affiliation":[{"name":"Lab-STICC, UMR 6285, Universit\u00e9 Bretagne-Sud","place":["Lorient, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2269-8756","authenticated-orcid":false,"given":"Bertrand","family":"Le Gal","sequence":"additional","affiliation":[{"name":"INRIA, IRISA, UMR 6074, Universit\u00e9 de Rennes","place":["Lannion, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9160-2896","authenticated-orcid":false,"given":"Sebastien","family":"Pillement","sequence":"additional","affiliation":[{"name":"IETR, UMR 6164, Nantes Universit\u00e9","place":["Nantes, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,9,26]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"crossref","unstructured":"G. Agosta A. Barenghi and G. Pelosi. 2019. Compiler-based techniques to secure cryptographic embedded software against side-channel attacks. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems 39 8 (2019) 1550\u20131554.","DOI":"10.1109\/TCAD.2019.2912924"},{"key":"e_1_3_2_3_2","doi-asserted-by":"crossref","unstructured":"A. Akram M. Mushtaq M. K. Bhatti V. Lapotre and G. Gogniat. 2020. Meet the Sherlock Holmes\u2019 of side channel leakage: A survey of cache SCA detection techniques. IEEE Access 8 (2020) 70836\u201370860.","DOI":"10.1109\/ACCESS.2020.2980522"},{"key":"e_1_3_2_4_2","unstructured":"S. Andersen. 2004. Changes to functionality in Microsoft Windows XP service pack 2. Microsoft technical document August."},{"key":"e_1_3_2_5_2","doi-asserted-by":"crossref","unstructured":"K. Arikan A. Palumbo L. Cassano P. Reviriego S. Pontarelli G. Bianchi O. Ergin and M. Ottavi. 2022. Processor security: Detecting microarchitectural attacks via count-min sketches. IEEE Transactions on Very Large Scale Integration (VLSI) Systems 30 7 (2022) 938\u2013951.","DOI":"10.1109\/TVLSI.2022.3171810"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00031"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3663673"},{"key":"e_1_3_2_8_2","doi-asserted-by":"crossref","unstructured":"T. Biton O. Gilles D. Gracia P\u00e9rez N. Kosmatov and S. Pillement. 2025. Call rewinding: Efficient backward edge protection. IACR Transactions on Cryptographic Hardware and Embedded Systems 2025 1 (2025) 227\u2013250.","DOI":"10.46586\/tches.v2025.i1.227-250"},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","unstructured":"T. Bletsch X. Jiang V. W. Freeh and Z. Liang. 2011. Jump-oriented programming: A new class of code-reuse attack. In Proceedings of the 6th ACM Symposium on Information Computer and Communications Security (2011).","DOI":"10.1145\/1966913.1966919"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3519601"},{"key":"e_1_3_2_11_2","unstructured":"C. Celio J. Zhao A. Gonzalez and B. Korpan. 2019. Riscv-boom documentation. (2019) (visited on 20250916). https:\/\/media.readthedocs.org\/pdf\/riscv-boom\/latest\/riscv-boom.pdf"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00061"},{"key":"e_1_3_2_13_2","volume-title":"Proceedings of the Information Systems Security","author":"Chen P.","unstructured":"P. Chen, H. Xiao, X. Shen, X. Yin, B. Mao, and L. Xie. DROP: Detecting return-oriented programming malicious code. In Proceedings of the Information Systems Security."},{"key":"e_1_3_2_14_2","unstructured":"R. de Clercq and I. Verbauwhede. 2017. A survey of Hardware-based Control Flow Integrity (CFI). arXiv preprint arXiv:1706.07257 (2017)."},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23264"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/HST.2018.8383910"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00021"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/HOST55342.2024.10545414"},{"key":"e_1_3_2_19_2","volume-title":"Proceedings of the 26th USENIX Security Symposium (USENIX Security)","author":"Disselkoen C.","year":"2017","unstructured":"C. Disselkoen, D. Kohlbrenner, L. Porter, and D. Tullsen. 2017. Prime+ abort: A timer-free high-precision l3 cache attack using intel TSX. In Proceedings of the 26th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_20_2","article-title":"Using PAPI for hardware performance monitoring on Linux systems","author":"Dongarra J.","year":"2001","unstructured":"J. Dongarra, K. London, S. Moore, P. Mucci, and D. Terpstra. 2001. Using PAPI for hardware performance monitoring on Linux systems. Conference on Linux Clusters: The HPC Revolution 5 (2001).","journal-title":"Conference on Linux Clusters: The HPC Revolution"},{"key":"e_1_3_2_21_2","unstructured":"lowRISC ETH Zurich University of Bologna. [n. d.]. IBEX core. ([n. d.]) (visited on 2025-09-16). https:\/\/ibexcore.readthedocs.io\/en\/latest\/index.html"},{"key":"e_1_3_2_22_2","volume-title":"Proceedings of the 2024 IEEE Computer Society Annual Symposium on VLSI (ISVLSI).","author":"Gaudin N.","unstructured":"N. Gaudin, P. Cotret, G. Gogniat, and V. Lapotre. A fine-grained dynamic partitioning against cache-based timing attacks via cache locking. In Proceedings of the 2024 IEEE Computer Society Annual Symposium on VLSI (ISVLSI)."},{"key":"e_1_3_2_23_2","doi-asserted-by":"crossref","unstructured":"L. Gerlach D. Weber R. Zhang and M. Schwarz. 2023. A security RISC: Microarchitectural attacks on hardware RISC-V CPUs. In IEEE Symposium on Security and Privacy (SP). 2321\u20132338.","DOI":"10.1109\/SP46215.2023.10179399"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179440"},{"key":"e_1_3_2_25_2","volume-title":"Proceedings of the Third Workshop on Computer Architecture Research with RISC-V (CARRV)","author":"Gonzalez A.","year":"2019","unstructured":"A. Gonzalez, B. Korpan, J. Zhao, E. Younis, and K. Asanovic. 2019. Replicating and mitigating spectre attacks on an open source RISC-V microarchitecture. In Proceedings of the Third Workshop on Computer Architecture Research with RISC-V (CARRV)."},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_2_27_2","unstructured":"B. Gulmezoglu A. Moghimi T. Eisenbarth and B. Sunar. 2019. FortuneTeller: Predicting microarchitectural attacks via unsupervised deep learning. arXiv:1907.03651. Retrieved from https:\/\/arxiv.org\/abs\/1907.03651"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/WWC.2001.990739"},{"key":"e_1_3_2_29_2","unstructured":"Z. He T. Ao M. Wan K. Dai and X. Zou. 2016. ERIST: An efficient randomized instruction insertion technique to counter side-channel attacks.International Journal of Computer Science (IAENG) 43 1 (2016)."},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.23919\/DATE51398.2021.9473919"},{"key":"e_1_3_2_31_2","volume-title":"Proceedings of the 15th ACM Asia Conference on Computer and Communications Security","author":"Jaloyan G.-A.","unstructured":"G.-A. Jaloyan, K. Markantonakis, R. N. Akram, D. Robin, K. Mayes, and D. Naccache. 2020. Return-oriented programming on RISC-V. In Proceedings of the 15th ACM Asia Conference on Computer and Communications Security (2020). ACM."},{"key":"e_1_3_2_32_2","doi-asserted-by":"crossref","unstructured":"M. Kayaalp T. Schmitt J. Nomani D. Ponomarev and N. Abu-Ghazaleh. 2013. SCRAP: Architecture for signaturebased protection from code reuse attacks. In 2013 IEEE 19th International Symposium on High Performance Computer Architecture (HPCA\u201913).","DOI":"10.1109\/HPCA.2013.6522324"},{"key":"e_1_3_2_33_2","doi-asserted-by":"crossref","unstructured":"P. Kocher J. Horn A. Fogh D. Genkin D. Gruss W. Haas M. Hamburg M. Lipp S. Mangard T. Prescher M. Schwarz and Y. Yarom. 2019. Spectre attacks: Exploiting speculative execution. In IEEE Symposium on Security and Privacy (SP) (2019).","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3637649"},{"key":"e_1_3_2_35_2","article-title":"Softcore processor optimization according to real-application requirements","author":"Gal B. Le","year":"2012","unstructured":"B. Le Gal and C. Jego. 2012. Softcore processor optimization according to real-application requirements. IEEE Embedded Systems Letters 5, 1 (2012), 4\u20137.","journal-title":"IEEE Embedded Systems Letters"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/HOST54066.2022.9840060"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3357033"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2016.85"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/1064978.1065034"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00101"},{"key":"e_1_3_2_41_2","doi-asserted-by":"crossref","unstructured":"Y. Mao V. Migliore and V. Nicomette. 2022. MATANA: A reconfigurable framework for runtime attack detection based on the analysis of microarchitectural signals. Applied Sciences MDPI 12 3 (2022) 1452.","DOI":"10.3390\/app12031452"},{"key":"e_1_3_2_42_2","doi-asserted-by":"crossref","unstructured":"V. Martinoli E. Tourneur Y. Teglia and R. Leveugle. 2022. CCALK: (When) CVA6 cache associativity leaks the key. Journal of Low Power Electronics and Applications (JLPEA) 13 1 (2022) 1.","DOI":"10.3390\/jlpea13010001"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISQED51717.2021.9424252"},{"key":"e_1_3_2_44_2","unstructured":"V. Meraji and H. Soleimany. 2021. Evict+ time attack on intel CPUs without explicit knowledge of address offsets.ISeCure 13 1 (2021)."},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/GIIS.2018.8635767"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2988370"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_2_48_2","article-title":"Cache missing for fun and profit","author":"Percival C.","year":"2005","unstructured":"C. Percival. 2005. Cache missing for fun and profit. BSDCan (2005).","journal-title":"BSDCan"},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","unstructured":"S. Pillement M. M\u00e9ndez Real J. Pottier T. Nieddu B. Le Gal S. Faucou J. L. B\u00e9chennec M. Briday S. Girbal J. Le Rhun O. Gilles D. Gracia P\u00e9rez A. Sintzoff and J. R. Coulon. 2023. Securing a RISC-V architecture: A dynamic approach. In Design Automation & Test in Europe Conference & Exhibition (DATE).","DOI":"10.23919\/DATE56975.2023.10136972"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSD53832.2021.00060"},{"key":"e_1_3_2_51_2","article-title":"RISC-V processor enhanced with a dynamic micro-decoder unit","author":"Pottier J.","year":"2024","unstructured":"J. Pottier, T. Nieddu, B. Le Gal, S. Pillement, and M. M. Real. 2024. RISC-V processor enhanced with a dynamic micro-decoder unit. In Proceedings of the IEEE International Conference on Electronics Circuits and Systems (ICECS).","journal-title":"In Proceedings of the IEEE International Conference on Electronics Circuits and Systems (ICECS)."},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2018.00068"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/MWSCAS48704.2020.9184539"},{"key":"e_1_3_2_54_2","volume-title":"Proceedings of the 14th ACM Conference on Computer and Communications Security","author":"Shacham H.","unstructured":"H. Shacham. The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In Proceedings of the 14th ACM Conference on Computer and Communications Security (2007)."},{"key":"e_1_3_2_55_2","doi-asserted-by":"crossref","unstructured":"B. Sprunt. 2002. The basics of performance-monitoring hardware. IEEE Micro 22 4 (2002) 64\u201371.","DOI":"10.1109\/MM.2002.1028477"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/5559552"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2022.3152633"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/2046660.2046671"},{"key":"e_1_3_2_59_2","unstructured":"X. Wang and J. Backer. 2016. SIGDROP: Signature-based ROP Detection using Hardware Performance Counters. arXiv preprint arXiv:1609.02667 (2016)."},{"key":"e_1_3_2_60_2","doi-asserted-by":"crossref","unstructured":"A. Waterman Y. Lee D. A Patterson and K. Asanovic. 2014. The RISC-V Instruction Set Manual Volume I: User-level ISA Version 2.0. EECS Department University of California Berkeley Tech. Rep. UCB\/EECS-2014-54.","DOI":"10.21236\/ADA605735"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.23919\/DATE51398.2021.9474214"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/SEED55351.2022.00010"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.45"},{"key":"e_1_3_2_64_2","article-title":"FLUSH+RELOAD: A high resolution, low noise, L3 cache side-channel attack","author":"Yarom Y.","year":"2014","unstructured":"Y. Yarom and K. Falkner. 2014. FLUSH+RELOAD: A high resolution, low noise, L3 cache side-channel attack. In Proceedings of the 23rd USENIX Security Symposium (USENIX Security 14).","journal-title":"In Proceedings of the 23rd USENIX Security Symposium (USENIX Security 14)."},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2019.2926114"},{"key":"e_1_3_2_66_2","article-title":"CBA-detector: A self-feedback detector against cache-based attacks","author":"Zheng B.","year":"2021","unstructured":"B. Zheng, J. Gu, J. Wang, and C. Weng. 2021. CBA-detector: A self-feedback detector against cache-based attacks. IEEE Transactions on Dependable and Secure Computing 19, 5 (2021), 3231\u20133243.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_67_2","volume-title":"Proceedings of the Information Security Practice and Experience","author":"Zhou H.","unstructured":"H. Zhou, X. Wu, W. Shi, J. Yuan, and B. Liang. HDROP: Detecting ROP attacks using performance monitoring counters. In Proceedings of the Information Security Practice and Experience."},{"key":"e_1_3_2_68_2","article-title":"ISA extensions of shuffling against side-channel attacks","author":"Zhou J.","year":"2023","unstructured":"J. Zhou, G. Qin, L. Li, C. Guo, and W. Wang. 2023. ISA extensions of shuffling against side-channel attacks. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems 43, 3 (2023), 761\u2013773.","journal-title":"IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3762646","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,3]],"date-time":"2025-10-03T14:05:38Z","timestamp":1759500338000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3762646"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,26]]},"references-count":67,"journal-issue":{"issue":"5s","published-print":{"date-parts":[[2025,11,30]]}},"alternative-id":["10.1145\/3762646"],"URL":"https:\/\/doi.org\/10.1145\/3762646","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,26]]},"assertion":[{"value":"2025-08-10","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-11","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}