RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache Incoherence
Fabian Thomas, Michael Schwarz
Abstract
Caches have long been known to leak information across isolation boundaries, with classic attacks relying on timing to distinguish cache hits and misses. However, modern CPUs and operating systems increasingly limit timer resolution or restrict access to cycle counters, making such attacks less reliable in practice. As an alternative, architectural side channels replace timing with instruction sequences whose architectural outcome depends on cache state, offering higher robustness.
In this paper, we introduce I 2 SC, a generic timer-free architectural cache side channel that exploits instruction/data-cache incoherence on RISC-V, ARM, and LoongArch. I 2 SC leverages a widespread RISC property: stores through the data path are invisible to instruction fetch when the instruction cache holds stale lines, yielding architecturally distinct outcomes that reveal cache state. Unlike prior work that targets only instruction caches, I 2 SC generalizes this behavior into a timerfree oracle for both instruction and data caches via a transientexecution-based cache-state transfer gadget. We evaluate I 2 SC on 18 microarchitectures, finding that 12 microarchitectures are affected. To demonstrate the security impact of I 2 SC, we mount three end-to-end attacks: a timer-free AES keyrecovery, a Spectre variant with architectural leakage across all three architectures, achieving reliability on par with or exceeding prior timing-based methods, and a classical sidechannel attack on Android shared libraries recovering finegrained touch-event timing. Finally, we discuss both software and hardware mitigations, noting that full prevention likely requires hardware changes.
• We propose I 2 SC, an unprivileged timer-free architectural cache side channel that exploits instruction/data cache incoherence on RISC-V, ARM, and LoongArch.
• We identify two main building blocks for I 2 SC and evaluate their prevalence on 18 microarchitectures, finding that 12 microarchitectures are affected by I 2 SC, including recent high-performance cores deployed in smartphones, servers, and domestic ISAs.
• We present Spectral attacks and architectural sidechannel attacks on AES T-tables on all three ISAs. Further, we show an architectural side-channel attack on shared Android libraries recovering touch-event timing, such as taps and swipes, on the Google Pixel 9 running Android 16.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 039b9e1d-82ec-42ef-a982-b98233adb2fbBuilds on36
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
Related papers
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu et al.CCS 2025
- ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUsFabian Thomas, Michael Torres, Daniel Moghimi, Michael SchwarzCCS 2025
- Synchronization Storage Channels (S2C): Timer-less Cache Side-Channel Attacks on the Apple M1 via Hardware Synchronization InstructionsJiyong Yu, Aishani Dutta, Trent Jaeger, David Kohlbrenner et al.USENIX Security 2023
- Loongleak: Architectural Cross-Privilege-Boundary Data Leakage on LoongArch CPUsLorenz Hetterich, Tristan Hornetz, Fabian Thomas, Michael SchwarzUSENIX Security 2026
- TimeCache: Using Time to Eliminate Cache Side Channels when Sharing SoftwareDivya Ojha, Sandhya DwarkadasISCA 2021 · 14 citations
