BLACKSMITH: Scalable Rowhammering in the Frequency Domain
Patrick Jattke, Victor van der Veen, Pietro Frigo, Stijn Gunter, Kaveh Razavi
Abstract
We present the new class of non-uniform Rowhammer access patterns that bypass undocumented, proprietary in-DRAM Target Row Refresh (TRR) while operating in a production setting. We show that these patterns trigger bit flips on all 40 DDR4 DRAM devices in our test pool. We make a key observation that all published Rowhammer access patterns always hammer “aggressor” rows uniformly. While uniform accesses maximize the number of aggressor activations, we find that in-DRAM TRR exploits this behavior to catch aggressor rows and refresh neighboring “victims” before they fail. There is no reason, however, to limit Rowhammer attacks to uniform access patterns: smaller technology nodes make underlying DRAM technologies more vulnerable, and significantly fewer accesses are nowadays required to trigger bit flips, making it interesting to investigate less predictable access patterns. The search space for non-uniform access patterns, however, is tremendous. We design experiments to explore this space with respect to the deployed mitigations, highlighting the importance of the order, regularity, and intensity of accessing aggressor rows in non-uniform access patterns. We show how randomizing parameters in the frequency domain captures these aspects and use this insight in the design of Blacksmith, a scalable Rowhammer fuzzer that generates access patterns that hammer aggressor rows with different phases, frequencies, and amplitudes. Blacksmith finds complex patterns that trigger Rowhammer bit flips on all 40 of our recently purchased DDR4 DIMMs, more than state of the art, and generating on average more bit flips. We also demonstrate the effectiveness of these patterns on Low Power DDR4X devices. Our extensive analysis using Blacksmith further provides new insights on the properties of currently deployed TRR mitigations. We conclude that after almost a decade of research and deployed in-DRAM mitigations, we are perhaps in a worse situation than when Rowhammer was first discovered.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers52
- ProTRR: Principled yet Optimal In-DRAM Target Row RefreshMichele Marazzi, Patrick Jattke, Flavien Solt, Kaveh RazaviS&P 2022 · 101 citations
- RowPress: Amplifying Read Disturbance in Modern DRAM ChipsHaocong Luo, Ataberk Olgun, Abdullah Giray Yaglikçi, Yahya Can Tugrul et al.ISCA 2023 · 71 citations
- ZenHammer: Rowhammer Attacks on AMD Zen-based PlatformsPatrick Jattke, Max Wipfli, Flavien Solt, Michele Marazzi et al.USENIX Security 2024 · 63 citations
- SoftTRR: Protect Page Tables against Rowhammer Attacks using Software-only Target Row RefreshZhi Zhang, Yueqiang Cheng, Minghua Wang, Wei He et al.USENIX ATC 2022 · 62 citations
- When Frodo Flips: End-to-End Key Recovery on FrodoKEM via RowhammerMichael Fahr, Hunter Kippen, Andrew Kwong, Thinh Dang et al.CCS 2022 · 34 citations
Builds on18
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss et al.CCS 2016 · 381 citations
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel et al.USENIX Security 2016 · 306 citations
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin et al.S&P 2018 · 288 citations
- TRRespass: Exploiting the Many Sides of Target Row RefreshPietro Frigo, Emanuele Vannacci, Hasan Hassan, Victor van der Veen et al.S&P 2020 · 274 citations
Related papers
- Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting SynchronizationDiego Meyer, Patrick Jattke, Michele Marazzi, Salman Qazi et al.S&P 2026 · 25 citations
- Understanding RowHammer Under Reduced Refresh Latency: Experimental Analysis of Real DRAM Chips and Implications on Future SolutionsYahya Can Tugrul, A. Giray Yaglikçi, Ismail Emir Yüksel, Ataberk Olgun et al.HPCA 2025 · 10 citations
- SMASH: Synchronized Many-sided Rowhammer Attacks from JavaScriptFinn de Ridder, Pietro Frigo, Emanuele Vannacci, Herbert Bos et al.USENIX Security 2021 · 124 citations
- BlockHammer: Preventing RowHammer at Low Cost by Blacklisting Rapidly-Accessed DRAM RowsAbdullah Giray Yaglikçi, Minesh Patel, Jeremie S. Kim, Roknoddin Azizi et al.HPCA 2021 · 124 citations
- PrIDE: Achieving Secure Rowhammer Mitigation with Low-Cost In-DRAM TrackersAamer Jaleel, Gururaj Saileshwar, Stephen W. Keckler, Moinuddin K. QureshiISCA 2024 · 22 citations
