TAROT: A CXL SmartNIC-Based Defense Against Multi-bit Errors by Row-Hammer Attacks
Chihun Song, Michael Jaemin Kim, Tianchen Wang, Houxiang Ji, Jinghan Huang, Ipoom Jeong, Jaehyun Park, Hwayong Nam, Minbok Wi, Jung Ho Ahn, Nam Sung Kim
Abstract
Row Hammer (RH) has been demonstrated as a security vulnerability in modern systems. Although commodity CPUs can handle RH-induced single-bit errors in DRAM through ECC, RH can still give rise to multi-bit uncorrectable errors (UEs) and crash the systems. Meanwhile, recent work has indicated that the DRAM cells vulnerable to RH are determined by manufacturing imperfections and resulting defects. Taking one step further from the recent work, we first conduct RH experiments on contemporary DRAM modules for 3 weeks. This demonstrates that RH-induced UEs occur only at specific DRAM addresses (RH-UE-vulnerable addresses) and the percentage of such addresses is small in these DRAM modules. Second, to protect the systems from RH-induced UEs, we propose two RH defense solutions: H- and S-TAROT (TArgeted ROw-Hammer Therapy). H-TAROT is a software-based solution running on the host CPU. It obtains RH-UE-vulnerable addresses during the system boot and then periodically accesses such addresses before UEs may occur. Since it accesses only a small percentage of addresses, it does not incur a notable performance penalty for throughput applications (e.g., a 1.5% increase in execution time of the SPECrate 2017 benchmark suite running on a system even with 128GB of DRAM). Yet, it imposes a significant performance penalty on latency-sensitive applications (e.g., a 28.2% increase in tail latency of Redis). To minimize the performance penalty, for a system with a SmartNIC (SNIC), S-TAROT offloads H-TAROT from the host CPU to the SNIC CPU. Our experiment shows that S-TAROT increases the execution time and tail latency of the SPECrate 2017 benchmark suite and Redis by only 0.1% and 1.0%, respectively.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4f427f17-9760-4cf4-b290-8301ee6023a1Cited by top-tier papers9
- HiDPU: A DPU-Oriented Hybrid Indexing Scheme for Disaggregated Storage SystemsWenbin Zhu, Zhaoyan Shen, Qian Wei, Renhai Chen et al.FAST 2025 · 11 citations
- HAL: Hardware-assisted Load Balancing for Energy-efficient SNIC-Host Cooperative ComputingJinghan Huang, Jiaqi Lou, Srikar Vanavasam, Xinhao Kong et al.ISCA 2024 · 7 citations
- SoK: Systematizing a Decade of Architectural Rowhammer Defenses Through the Lens of Streaming AlgorithmsMichael Jaemin Kim, Seungmin Baek, Jumin Kim, Hwayong Nam et al.S&P 2026 · 6 citations
- SwCC: Software-Programmable and Per-Packet Congestion Control in RDMA EngineHongjing Huang, Jie Zhang, Xuzheng Chen, Ziyu Song et al.USENIX ATC 2025 · 4 citations
- Unified Memory Protection with Multi-granular MAC and Integrity Tree for Heterogeneous ProcessorsSunho Lee, Seonjin Na, Jeongwon Choi, Jinwon Pyo et al.ISCA 2025 · 2 citations
Related papers
- BreakHammer: Enhancing RowHammer Mitigations by Carefully Throttling Suspect ThreadsOguzhan Canpolat, A. Giray Yaglikçi, Ataberk Olgun, Ismail Emir Yuksel et al.MICRO 2024 · 19 citations
- SafeGuard: Reducing the Security Risk from Row-Hammer via Low-Cost Integrity ProtectionAli Fakhrzadehgan, Yale N. Patt, Prashant J. Nair, Moinuddin K. QureshiHPCA 2022 · 51 citations
- Memory Band-Aid: A Principled Rowhammer Defense-in-DepthCarina Fiedler, Jonas Juffinger, Sudheendra Raghav Neela, Martin Heckel et al.NDSS 2026 · 5 citations
- SoftTRR: Protect Page Tables against Rowhammer Attacks using Software-only Target Row RefreshZhi Zhang, Yueqiang Cheng, Minghua Wang, Wei He et al.USENIX ATC 2022 · 62 citations
- Marionette: A RowHammer Attack via Row CouplingSeungmin Baek, Minbok Wi, Seonyong Park, Hwayong Nam et al.ASPLOS 2025 · 11 citations
