Lune

S&P2026Top-tier venue

RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache Incoherence

Fabian Thomas, Michael Schwarz

2026Year
1Citations

Abstract

Caches have long been known to leak information across isolation boundaries, with classic attacks relying on timing to distinguish cache hits and misses. However, modern CPUs and operating systems increasingly limit timer resolution or restrict access to cycle counters, making such attacks less reliable in practice. As an alternative, architectural side channels replace timing with instruction sequences whose architectural outcome depends on cache state, offering higher robustness.

In this paper, we introduce I 2 SC, a generic timer-free architectural cache side channel that exploits instruction/data-cache incoherence on RISC-V, ARM, and LoongArch. I 2 SC leverages a widespread RISC property: stores through the data path are invisible to instruction fetch when the instruction cache holds stale lines, yielding architecturally distinct outcomes that reveal cache state. Unlike prior work that targets only instruction caches, I 2 SC generalizes this behavior into a timerfree oracle for both instruction and data caches via a transientexecution-based cache-state transfer gadget. We evaluate I 2 SC on 18 microarchitectures, finding that 12 microarchitectures are affected. To demonstrate the security impact of I 2 SC, we mount three end-to-end attacks: a timer-free AES keyrecovery, a Spectre variant with architectural leakage across all three architectures, achieving reliability on par with or exceeding prior timing-based methods, and a classical sidechannel attack on Android shared libraries recovering finegrained touch-event timing. Finally, we discuss both software and hardware mitigations, noting that full prevention likely requires hardware changes.

• We propose I 2 SC, an unprivileged timer-free architectural cache side channel that exploits instruction/data cache incoherence on RISC-V, ARM, and LoongArch.

• We identify two main building blocks for I 2 SC and evaluate their prevalence on 18 microarchitectures, finding that 12 microarchitectures are affected by I 2 SC, including recent high-performance cores deployed in smartphones, servers, and domestic ISAs.

• We present Spectral attacks and architectural sidechannel attacks on AES T-tables on all three ISAs. Further, we show an architectural side-channel attack on shared Android libraries recovering touch-event timing, such as taps and swipes, on the Google Pixel 9 running Android 16.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 039b9e1d-82ec-42ef-a982-b98233adb2fb

Builds on36

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines