MDPeek: Breaking Balanced Branches in SGX with Memory Disambiguation Unit Side Channels
Chang Liu, Shuaihu Feng, Yuan Li, Dongsheng Wang, Wenjian He, Yongqiang Lyu, Trevor E. Carlson
Abstract
In recent years, control flow attacks targeting Intel SGX have attracted significant attention from the security community due to their potent capacity for information leakage. Although numerous software-based defenses have been developed to counter these attacks, many remain inadequate in fully addressing other, yet-to-be-discovered side channels.
In this paper, we introduce MDPeek, a novel control flow attack targeting secret-dependent branches in SGX. To circumvent existing defenses, such as microarchitectural state flushing and branch balancing, we exploit a new leakage source, the Memory Disambiguation Unit (MDU). We present the first comprehensive reverse engineering on the MDU's enable and update logic. Based on our detailed analysis, we develop a methodology to identify vulnerable workloads in real-world applications. We demonstrate the effectiveness of MDPeek with end-to-end attacks on the latest versions of three SGX-secured applications, including Libjpeg, MbedTLS and WolfSSL. In addition, we propose a low-overhead mitigation technique, store-to-load coupling, which provides a 7× latency reduction compared to naive techniques like serialization and load aligning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Towards Practical Interrupt Side-Channel Attacks on macOS for Apple SiliconXin Zhang, Chang Liu, Jiajun Zou, Yi Yang et al.ISCA 2026 · 1 citation
- SSBench: Automated Characterization of Memory Dependence Predictors on Modern CPUsChang Liu, Yu Jin, Yuchen Fan, Tianrui Xiao et al.ISCA 2026 · 1 citation
- OCCUPY+PROBE: Cross-Privilege Branch Target Buffer Side-Channel Attacks at Instruction GranularityKaiyuan Rong, Junqi Fang, Haixia Wang, Dapeng Ju et al.NDSS 2026
- UncoreBleed: AEX-Free, High-Resolution, and Low-Noise Side-Channel Attacks on SGX Enclaved ExecutionDecheng Chen, Zhi Zhang, Zhenkai Zhang, Xin Zhang et al.USENIX Security 2026
Builds on27
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
Related papers
- Leaky MDU: ARM Memory Disambiguation Unit Uncovered and Vulnerabilities ExposedChang Liu, Yongqiang Lyu, Haixia Wang, Pengfei Qiu et al.DAC 2023 · 5 citations
- LVI: Hijacking Transient Execution through Microarchitectural Load Value InjectionJo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp et al.S&P 2020 · 275 citations
- HoBBy: Hardening Unbalanced Branches against Control Flow Attacks on Intel SGX and AMD SEVChang Liu, Shuaihu Feng, Yuan Li, Dongsheng Wang et al.DAC 2025 · 2 citations
- Frontal Attack: Leaking Control-Flow in SGX via the CPU FrontendIvan Puddu, Moritz Schneider, Miro Haller, Srdjan CapkunUSENIX Security 2021 · 63 citations
- MetaLeak: Uncovering Side Channels in Secure Processor Architectures Exploiting MetadataMd Hafizul Islam Chowdhuryy, Hao Zheng, Fan YaoISCA 2024 · 3 citations
