{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T12:10:05Z","timestamp":1772107805919,"version":"3.50.1"},"reference-count":29,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T00:00:00Z","timestamp":1772064000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Shanghai Pujiang Program","award":["21PJD026"],"award-info":[{"award-number":["21PJD026"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>As Large Language Models (LLMs) become increasingly integrated into web environments, they introduce complex microarchitectural noise that challenges existing hardware security mechanisms. This paper investigates the impact of concurrent web-based LLM workloads on the detection accuracy of Spectre attacks. Firstly, we constructed a representative dataset by executing multiple web-accessible LLMs (e.g., DeepSeek, Kimi, Doubao and Qwen) alongside Spectre attacks, capturing the specific interference patterns introduced by these AI workloads. Experimental analysis reveals that traditional Hardware Performance Counter (HPC)-based detectors, relying primarily on branch prediction and Last-Level Cache (LLC) events, suffer significant accuracy degradation due to the masking effects of LLM-induced noise. To address this limitation, we then propose a novel Spectre attack detector Spec-LAMP via augmenting conventional HPC feature sets with the L1D Miss Pending event. This new metric specifically captures unresolved speculative memory dependencies, a distinctive characteristic of Spectre attacks that remains discernible even under web-accessible LLM interference. Comparative statistical analysis demonstrates that incorporating this event significantly enhances the separability between malicious and benign executions. Finally, experimental results show that our proposed feature augmentation effectively restores detection performance, increasing average accuracy from 85.15% to 98.43% and demonstrating superior robustness compared to traditional approaches in realistic web-based LLM scenarios.<\/jats:p>","DOI":"10.3390\/e28030254","type":"journal-article","created":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T11:23:45Z","timestamp":1772105025000},"page":"254","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Spec-LAMP: Robust Spectre Attack Detection Under Web-Based LLM Workload via L1D Miss Pending Event"],"prefix":"10.3390","volume":"28","author":[{"given":"Jiajia","family":"Jiao","sequence":"first","affiliation":[{"name":"College of Information Engineering, Shanghai Maritime University, No. 1550 Haigang Avenue, Shanghai 201306, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Quan","family":"Zhou","sequence":"additional","affiliation":[{"name":"College of Information Engineering, Shanghai Maritime University, No. 1550 Haigang Avenue, Shanghai 201306, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7314-6399","authenticated-orcid":false,"given":"Yulian","family":"Li","sequence":"additional","affiliation":[{"name":"College of Information Engineering, Shanghai Maritime University, No. 1550 Haigang Avenue, Shanghai 201306, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,2,26]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Liang, Z., Xu, Y., Hong, Y., Shang, P., Wang, Q., Fu, Q., and Liu, K. (2024). A Survey of Multimodel Large Language Models. Proceedings of the 3rd International Conference on Computer, Artificial Intelligence and Control Engineering, ACM.","DOI":"10.1145\/3672758.3672824"},{"key":"ref_2","unstructured":"Liu, A., Feng, B., Xue, B., Wang, B., Wu, B., Lu, C., Zhao, C., Deng, C., Zhang, C., and Ruan, C. (2024). DeepSeek-V3 Technical Report. arXiv."},{"key":"ref_3","unstructured":"Team, K., Bai, Y., Bao, Y., Chen, G., Chen, J., Chen, N., Chen, R., Chen, Y., Chen, Y., and Chen, Y. (2025). Kimi K2: Open Agentic Intelligence. arXiv."},{"key":"ref_4","unstructured":"Gong, L., Hou, X., Li, F., Li, L., Lian, X., Liu, F., Liu, L., Liu, W., Lu, W., and Shi, Y. (2025). Seedream 2.0: A Native Chinese\u2013English Bilingual Image Generation Foundation Model. arXiv."},{"key":"ref_5","unstructured":"Bai, J., Bai, S., Chu, Y., Cui, Z., Dang, K., Deng, X., Fan, Y., Ge, W., Han, Y., and Huang, F. (2023). Qwen Technical Report. arXiv."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Sayadi, H., He, Z., Makrani, H.M., and Homayoun, H. (2024). Intelligent Malware Detection Based on Hardware Performance Counters: A Comprehensive Survey. Proceedings of the 25th International Symposium on Quality Electronic Design (ISQED), IEEE.","DOI":"10.1109\/ISQED60706.2024.10528369"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1145\/3399742","article-title":"Spectre Attacks: Exploiting Speculative Execution","volume":"63","author":"Kocher","year":"2020","journal-title":"Commun. ACM"},{"key":"ref_8","first-page":"1320","article-title":"Detecting Spectre Attacks Using Hardware Performance Counters","volume":"71","author":"Li","year":"2022","journal-title":"IEEE Trans. Comput."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Jiao, J., Wen, R., and Li, Y. (2024). T-Smade: A Two-Stage Smart Detector for Evasive Spectre Attacks under Various Workloads. Electronics, 13.","DOI":"10.3390\/electronics13204090"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Polychronou, N.F., Thevenon, P.-H., Puys, M., and Beroulle, V. (2021). MaDMAN: Detection of Software Attacks Targeting Hardware Vulnerabilities. Proceedings of the 24th Euromicro Conference on Digital System Design (DSD), IEEE.","DOI":"10.1109\/DSD53832.2021.00060"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1145\/3688843","article-title":"Anatomizing Deep Learning Inference in Web Browsers","volume":"34","author":"Wang","year":"2025","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Gulmezoglu, B., Zankl, A., Eisenbarth, T., and Sunar, B. (2017). PerfWeb: How to Violate Web Privacy with Hardware Performance Events. Proceedings of the European Symposium on Research in Computer Security (ESORICS), Springer.","DOI":"10.1007\/978-3-319-66399-9_5"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Jiao, J., Jiang, L., Zhou, Q., and Wen, R. (2025). Evaluating Large Language Model Application Impacts on Evasive Spectre Attack Detection. Electronics, 14.","DOI":"10.3390\/electronics14071384"},{"key":"ref_14","unstructured":"Wikner, J., Giuffrida, C., Bos, H., and Razavi, K. (2022). Spring: Spectre Returning in the Browser with Speculative Load Queuing and Deep Stacks. Proceedings of the 16th IEEE Workshop on Offensive Technologies (WOOT 2022), San Francisco, CA, USA, 26 May 2022, IEEE."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"178","DOI":"10.1145\/3645109","article-title":"Timing Side-Channel Attacks and Countermeasures in CPU Microarchitectures","volume":"56","author":"Zhang","year":"2024","journal-title":"ACM Comput. Surv."},{"key":"ref_16","unstructured":"Canella, C., Van Bulck, J., Schwarz, M., Lipp, M., Von Berg, B., Ortner, P., Piessens, F., Evtyushkin, D., and Gruss, D. (2019). A Systematic Evaluation of Transient Execution Attacks and Defenses. Proceedings of the 28th USENIX Security Symposium (USENIX Security 19), ACM."},{"key":"ref_17","unstructured":"Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Mangard, S., Kocher, P., Genkin, D., Yarom, Y., and Hamburg, M. (2018). Meltdown. arXiv."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Das, S., Werner, J., Antonakakis, M., Polychronakis, M., and Monrose, F. (2019). SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for Security. Proceedings of the IEEE Symposium on Security and Privacy (S&P), IEEE.","DOI":"10.1109\/SP.2019.00021"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/LCA.2020.2976069","article-title":"Challenges in Detecting an \u201cEvasive Spectre\u201d","volume":"19","author":"Li","year":"2020","journal-title":"IEEE Comput. Archit. Lett."},{"key":"ref_20","unstructured":"Intel Corporation (2023). Intel\u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual, Combined Volumes 1, 2A, 2B, 2C, 2D, 3A, 3B, 3C, 3D, and 4, Intel Corporation. Available online: https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-sdm.html."},{"key":"ref_21","first-page":"21","article-title":"A Feature Selection Method Based on the Kolmogorov\u2013Smirnov Test and Neighborhood Rough Sets","volume":"47","author":"Liu","year":"2019","journal-title":"J. Henan Norm. Univ. (Nat. Sci. Ed.)"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1504\/IJESDF.2025.143475","article-title":"IoT Security: A Systematic Literature Review of Feature Selection Methods for Machine Learning-Based Attack Classification","volume":"17","author":"Li","year":"2025","journal-title":"Int. J. Electron. Secur. Digit. Forensics"},{"key":"ref_23","unstructured":"Tong, Z., Zhu, Z., Zhang, Y., Liu, Y., and Meng, D. (2022). Attack Detection Based on Machine Learning Algorithms for Different Variants of Spectre Attacks and Different Meltdown Attack Implementations. arXiv."},{"key":"ref_24","unstructured":"Ahmad, B.A. (2020). Real Time Detection of Spectre and Meltdown Attacks Using Machine Learning. arXiv."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Li, C., and Gaudiot, J.-L. (2018). Online Detection of Spectre Attacks Using Microarchitectural Traces from Performance Counters. Proceedings of the 30th International Symposium on Computer Architecture and High Performance Computing (SBAC-PAD), IEEE.","DOI":"10.1109\/CAHPC.2018.8645918"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Wang, W., Chen, G., Cheng, Y., Zhang, Y., and Lin, Z. (2021). Specularizer: Detecting speculative execution attacks via performance tracing. Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), Springer.","DOI":"10.1007\/978-3-030-80825-9_8"},{"key":"ref_27","unstructured":"Hassan, M., Mushtaq, M., Raik, J., and Ghasempouri, T. (2025). DRsam: Detection of Fault-Based Microarchitectural Side-Channel Attacks in RISC-V Using Statistical Preprocessing and Association Rule Mining. arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Lou, X., Chen, K., Xu, G., Qiu, H., Guo, S., and Zhang, T. (2024). Protecting Confidential Virtual Machines from Hardware Performance Counter Side Channels. Proceedings of the 54th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), IEEE.","DOI":"10.1109\/DSN58291.2024.00031"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Volos, S., Fournet, C., Hofmann, J., K\u00f6pf, B., and Oleksenko, O. (2024). Principled Microarchitectural Isolation on Cloud CPUs. Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS \u201924), ACM.","DOI":"10.1145\/3658644.3690183"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/254\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T11:26:30Z","timestamp":1772105190000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/254"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,26]]},"references-count":29,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2026,3]]}},"alternative-id":["e28030254"],"URL":"https:\/\/doi.org\/10.3390\/e28030254","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,26]]}}}