IdleLeak: Exploiting Idle State Side Effects for Information Leakage
Fabian Rauscher, Andreas Kogler, Jonas Juffinger, Daniel Gruss
Abstract
—Modern processors are equipped with numerous features to regulate energy consumption according to the work-load. For this purpose, software brings processor cores into idle states via dedicated instructions such as hlt . Recently, Intel introduced the C0.1 and C0.2 idle states. While idle states previously could only be reached via privileged operations, these new idle states can also be reached by an unprivileged attacker. However, the attack surface these idle states open is still unclear. In this paper, we present IdleLeak, a novel side-channel attack exploiting the new C0.1 and C0.2 idle states in two distinct ways. Specifically, we exploit the processor idle state C0.2 to monitor system activity and for novel means of data exfiltration, and the idle state C0.1 to monitor system activity on logical sibling cores. IdleLeak still works regardless of where the victim workload is scheduled, i.e. , cross-core, due to the low-level x86 design. We demonstrate that IdleLeak leaks significant information in a native keystroke-timing attack, achieving an F1 score of 90 . 5 % and a standard error on the timing prediction of only 12 µs. We also demonstrate website-and video-fingerprinting attacks using IdleLeak traces, pre-processed with short-time Fourier transforms, and classified with convolutional neural networks. These attacks are highly practical with F1 scores of 85 . 2 % (open-world website fingerprinting) and 81 . 5 % (open-world video fingerprinting). We evaluate the throughput of IdleLeak side channels in both directions in covert channel scenarios, i.e. , using interrupts and performance-increasing effects. With the performance-increasing effect, IdleLeak achieves a true capacity of 7 . 1 Mbit/s in a native and 46 . 3 kbit/s in a cross-VM scenario
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6e665e97-9768-4bef-9e8d-032e176d85edCited by top-tier papers9
- Cross-Core Interrupt Detection: Exploiting User and Virtualized IPIsFabian Rauscher, Daniel GrussCCS 2024 · 4 citations
- SnailLoad: Exploiting Remote Network Latency Measurements without JavaScriptStefan Gast, Roland Czerny, Jonas Juffinger, Fabian Rauscher et al.USENIX Security 2024 · 4 citations
- GateBleed: Exploiting On-Core Accelerator Power Gating for High Performance and Stealthy Attacks on AIJoshua Kalyanapu, Farshad Dizani, Darsh Asher, Azam Ghanbari et al.MICRO 2025 · 3 citations
- Eviction Notice: Reviving and Advancing Page Cache AttacksSudheendra Raghav Neela, Jonas Juffinger, Lukas Maar, Daniel GrussNDSS 2026 · 2 citations
- Towards Practical Interrupt Side-Channel Attacks on macOS for Apple SiliconXin Zhang, Chang Liu, Jiajun Zou, Yi Yang et al.ISCA 2026 · 1 citation
Builds on16
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
Related papers
- BrokenSleep: Remote Power Timing Attack Exploiting Processor Idle StatesHyosang Kim, Ki-Dong Kang, Gyeongseo Park, Seungkyu Lee et al.HPCA 2025 · 2 citations
- TimeGaps Channels: Exploiting CPU Halted Time for Fun and ProfitYusi Feng, Xin Zhang, Sioli O'Connell, Liangwei Qiu et al.ISCA 2026 · 1 citation
- Cross-VM and Cross-Processor Covert Channels Exploiting Processor Idle Power ManagementPaizhuo Chen, Lei Li, Zhice YangUSENIX Security 2021 · 7 citations
- PREFETCHX: Cross-Core Cache-Agnostic Prefetcher-based Side-Channel AttacksYun Chen, Ali Hajiabadi, Lingfeng Pei, Trevor E. CarlsonHPCA 2024 · 15 citations
- ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUsFabian Thomas, Michael Torres, Daniel Moghimi, Michael SchwarzCCS 2025
